Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

HP HPE6-A82 - Aruba Certified ClearPass Associate Exam

Page: 1 / 2
Total 60 questions

When using Guest Authentication with MAC Caching service template, which statements are true? (Select two.)

A.

The guest authentication is provided better security than without using MAC caching

B.

The guest authentication is provided better security than without using MAC caching

C.

The endpoint status of the client will be treated as "known" the first time the client associates to the network

D.

Which wireless SSID and wireless controller must be indicated when configuring the template

E.

The client will be required to re-enter their credentials even if still within the MAC-Auth Expiry term

What is RADIUS Change of Authorization (CoA)?

A.

It allows ClearPass to transmit messages to the Network Attached Device/Network Attached Server (NAD/NAS) to modify a user’s session status

B.

It allows clients to issue a privilege escalation request to ClearPass using RADIUS to switch to TACACS+

C.

It is a mechanism that enables ClearPass to assigned a User-Based Tunnel (UBT) between a switch and controller for Dynamic Segmentation

D.

It forces the client to re-authenticate upon roaming to an access point controlled by a foreign mobility controller.

What happens when a client successfully authenticates but does not match any Enforcement Policy rules?

A.

A RADIUS Accept is returned and the default Enforcement Profile is applied.

B.

A RADIUS reject is returned for the client.

C.

A RADIUS Accept is retuned, and the default rule is applied to the device.

D.

A RADIUS Accept is returned with no Enforcement Profile applied

What services are recommended to be allowed by the pre-authenticated role assigned to the Client during the Captive Portal process? (Choose three.)

A.

DHCP options 43 and 150

B.

RADIUS to ClearPass

C.

HTTPS to ClearPass

D.

HTTPS to the Internet

E.

DHCP address assignment

F.

DNS resolution

Refer to the exhibit.

A client is attempting to authenticate using their Windows account with a bad password if the Remote Lab AD server is down for maintenance, what win be the expected result?

A.

ClearPass receives a timeout attempt when trying the Remote Lab AD server first. It will then try the server Backup 1 and receive a result of Active Directory Authentication failed. No further processing will occur.

B.

ClearPass try either server Backup 1 or Backup 2 depending on which has responded the fastest in prior attempts to authenticate ClearPass will then receive a result of Active Directory Authentication failed.

No further processing will occur.

C.

ClearPass receives a timeout attempt when trying the Remote Lab AD server first. It will then try the server Backup 1 and Backup 2; both will send a result authentication failed.

D.

ClearPass receive a timeout attempt when trying the Remote Lab AD server first. No further processing will occur until the Remote Lab AD server is marked as "Down" by the Administrator.

What is the benefit to installing a wild card certificate for captive portal authentication?

A.

Guests no longer are required to validate certificates during captive portal.

B.

Allows different certificates for each controller for increased security

C.

Wild card certificates are provide greater security than normal certificates

D.

Allows the single wild card certificate to be installed on all controllers in the environment

When ClearPass is communicating with external context servers, which connection protocol is typically used?

A.

YAML

B.

SOAP and XML

C.

REST APIs over HTTPS

D.

FTP over SSH

What is a good collector type used for ClearPass to discover devices with static IP addresses?

A.

DHCP Collectors

B.

Network Functions

C.

Active Collectors

D.

ClearPass Air Monitors

Refer to the exhibit.

What does a bold field indicate?

A.

The field is currently enabled.

B.

The field is a non-system field

C.

The field has been customized

D.

The field Is required

Which option supports DHCP profiling for devices in a network?

A.

configuring ClearPass as a DHCP relay for the client

B.

DHCP profiling is enabled on ClearPass by default; configuration of the network access devices is not

necessary

C.

enabling the DHCP server to profile endpoints and forward meta-data to ClearPass

D.

enabling DHCP relay on our network access devices so DHCP requests are forwarded to ClearPass