Pre-Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

A company uses HPE Aruba Networking ClearPass Policy Manager (CPPM) and HPE Aruba Networking ClearPass Device Insight (CPDI) and has integrated the

two. CPDI admins have created a tag. CPPM admins have created rules that use that tag in the wired 802.1X and wireless 802.1X services ' enforcement policies.

The company requires CPPM to apply the tag-based rules to a client directly after it learns that the client has that tag.

What is one of the settings that you should verify on CPPM?

A.

The " Device Sync " setting is set to 1 in the ClearPass Device Insight Integration settings.

B.

Both 802.1X services have the " Profile Endpoints " option enabled and an appropriate CoA profile selected in the Profiler tab.

C.

Both 802.1X services have the " Use cached Role and Posture attributes from the previous sessions " setting.

D.

The " Polling Interval " is set to 1 in the ClearPass Device Insight Integration settings.

A company wants HPE Aruba Networking ClearPass Policy Manager (CPPM) to respond to Syslog messages from its Palo Alto Next Generation Firewall (NGFW)

by quarantining clients involved in security incidents.

Which step must you complete to enable CPPM to process the Syslogs properly?

A.

Configure the Palo Alto as a context server on CPPM.

B.

Install a Palo Alto Extension through ClearPass Guest.

C.

Enable Insight and ingress event processing on the CPPM server.

D.

Configure CPPM to trust the root CA certificate for the NGFW.

Refer to the exhibits.

HPE Aruba Networking ClearPass Policy Manager (CPPM) is authenticating 802.1X clients using Active Directory as the source. CPPM has a custom attribute for AD that uses AccountStatus as userAccountControl .

Which enforcement profile does CPPM apply to a client that:

    Succeeds in authenticating to an active AD user account: userAccountControl = 512

    Does not succeed at authenticating as a computer

A.

profile3

B.

profile1

C.

Deny Access Profile

D.

profile2

A port-access role for AOS-CX switches has this policy applied to it:

plaintext

Copy code

port-access policy mypolicy

10 class ip zoneC action drop

20 class ip zoneA action drop

100 class ip zoneB

The classes have this configuration:

plaintext

Copy code

class ip zoneC

10 match tcp 10.2.0.0/16 eq https

class ip zoneA

10 match ip any 10.1.0.0/16

class ip zoneB

10 match ip any 10.0.0.0/8

The company wants to permit clients in this role to access 10.2.12.0/24 with HTTPS. What should you do?

A.

Add this rule to zoneC: 5 match any 10.2.12.0/24 eq https

B.

Add this rule to zoneA: 5 ignore tcp any 10.2.12.0/24 eq https

C.

Add this rule to zoneB: 5 match tcp any 10.2.12.0/24 eq https

D.

Add this rule to zoneC: 5 ignore tcp any 10.2.12.0/24 eq https

What information can admins view in an AOS-CX switch’s Analytics Dashboard?

A.

A view of clients’ authentication status, role, and UBT state

B.

Alerts triggered by NAE agents deployed on the switch

C.

A list of all TACACS+, RADIUS, and other authentication events

D.

All debugging information collected since the last switch reboot

You need to create a certificate signing request (CSR) for HPE Aruba Networking ClearPass’s RADIUS/EAP certificate.

What is one guideline you should follow?

A.

Specify a valid IP address for the Subject Alternative Name.

B.

Select RSA instead of EC to obtain a shorter key length.

C.

Avoid submitting the CSR to a private CA.

D.

Use an FQDN for the subject CN without a wildcard.

You are using OpenSSL to obtain a certificate signed by a Certification Authority (CA). You have entered this command:

openssl req -new -out file1.pem -newkey rsa:3072 -keyout file2.pem

Enter PEM pass phrase: **********

Verifying - Enter PEM pass phrase: **********

Country Name (2 letter code) [AU]:US

State or Province Name (full name) [Some-State]:California

Locality Name (eg, city) []:Sunnyvale

Organization Name (eg, company) [Internet Widgits Pty Ltd]:example.com

Organizational Unit Name (eg, section) []:Infrastructure

Common Name (e.g. server FQDN or YOUR name) []:radius.example.com

What is one guideline for continuing to obtain a certificate?

A.

You should use a third-party tool to encrypt file2.pem before sending it and file1.pem to the CA.

B.

You should concatenate file1.pem and file2.pem into a single file, and submit that to the desired CA to sign.

C.

You should submit file1.pem, but not file2.pem, to the desired CA to sign.

D.

You should submit file2.pem, but not file1.pem, to the desired CA to sign.

What is one use case that companies can fulfill using HPE Aruba Networking ClearPass Policy Manager’s (CPPM’s) Device Profiler?

A.

Applying the correct enforcement profiles to specialized clients such as security cameras

B.

Identifying OS, browser, and application vulnerabilities by CVE ID

C.

Authenticating clients to Active Directory computer accounts

D.

Quarantining and remediating devices that have disabled firewalls

You have created this rule in an HPE Aruba Networking ClearPass Policy Manager (CPPM) service’s enforcement policy:

IF Authorization [Endpoints Repository] Conflict EQUALS true

THEN apply " quarantine_profile "

What information can help you determine whether you need to configure cluster-wide profiler parameters to ignore some conflicts?

A.

Whether some devices are running legacy operating systems

B.

Whether the company has rare Internet of Things (IoT) devices

C.

Whether some devices are incapable of captive portal or 802.1X authentication

D.

Whether the company has devices that use PXE boot

Which statement describes Zero Trust Security?

A.

Companies must apply the same access controls to all users, regardless of identity.

B.

Companies that support remote workers cannot achieve zero trust security and must determine if the benefits outweigh the cost.

C.

Companies should focus on protecting their resources rather than on protecting the boundaries of their internal network.

D.

Companies can achieve zero trust security by strengthening their perimeter security to detect a wider range of threats.