Pre-Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

HP HPE7-A02 - Aruba Certified Network Security Professional Exam

Page: 2 / 5
Total 156 questions

How can HPE Aruba Networking User-Based Tunneling (UBT) help companies implement a Zero Trust Security strategy?

A.

By extending internal security zones through integration with cloud-based security solutions

B.

By controlling wired and wireless clients with consistent identity- and context-based access policies

C.

By applying best-practice data center security technologies, such as VXLAN, all the way to the internal edge

D.

By applying strong encryption to all traffic that flows through the corporate LAN

What is a use case for running periodic subnet scans on devices from HPE Aruba Networking ClearPass Policy Manager (CPPM)?

A.

Using DHCP fingerprints to determine a client ' s device category and OS

B.

Detecting devices that fail to comply with rules defined in CPPM posture policies

C.

Identifying issues with authenticating and authorizing clients

D.

Using WMI to collect additional information about Windows domain clients

You need to set up HPE Aruba Networking ClearPass Policy Manager (CPPM) to provide certificate-based authentication of 802.1X supplicants.

How should you upload the root CA certificate for the supplicants ' certificates?

A.

As a ClearPass Server certificate with the RADIUS/EAP usage

B.

As a Trusted CA with the AD/LDAP usage

C.

As a Trusted CA with the EAP usage

D.

As a ClearPass Server certificate with the Database usage

A company has HPE Aruba Networking APs and AOS-CX switches, as well as HPE Aruba Networking ClearPass. The company wants CPPM to have HTTP User-

Agent strings to use in profiling devices.

What can you do to support these requirements?

A.

Add the CPPM server ' s IP address to the IP helper list in all client VLANs on routing switches.

B.

Schedule periodic subnet scans of all client subnets on CPPM.

C.

Configure mirror sessions on the APs and switches to copy client HTTP traffic to CPPM.

D.

On the APs and switches, configure a redirect to ClearPass Guest in the role for devices being profiled.

Refer to the exhibits.

You are setting up HPE Aruba Networking ClearPass Policy Manager (CPPM) to authenticate wireless clients with EAP-TLS and 802.1X. CPPM should assign clients to an AOS firewall role named contractors-fullaccess if the clients meet these requirements:

    AD account is enabled: AccountStatus 512

    Security group name is Contractors

What should you do to make these policies meet these requirements?

A.

In the role mapping policy rule 2, change “role2” to a role named “contractors-fullaccess.”

B.

Add this rule to the enforcement policy: IF Tips:Role EQUALS role2 , THEN profile = RADIUS enforcement profile with the Aruba-User-Role attribute set to contractors-fullaccess .

C.

In the enforcement policy rule 1, remove the second condition; also change the profile to one named “contractors-fullaccess.”

D.

In the enforcement policy rule 1, change the profile to a RADIUS enforcement profile with the Aruba-User-Role attribute set to contractors-fullaccess .

You need to create a rule in an HPE Aruba Networking ClearPass Policy Manager (CPPM) role mapping policy that references a ClearPass Device Insight Tag. Which Type (namespace) should you specify for the rule?

A.

Endpoint

B.

TIPS

C.

Device

D.

Application

You are helping an organization deploy HPE Aruba Networking SSE. What is one reason to recommend that the company install agents on remote users ' devices?

A.

To run posture checks and apply different permissions based on those checks.

B.

To permit admins to manage the HPE Aruba Networking SSE policy rules.

C.

To permit users to access private servers using SSH.

D.

To run threat inspection on clients in a local sandbox rather than in the cloud.

You need to create a rule in an HPE Aruba Networking ClearPass Policy Manager (CPPM) role mapping policy that references a ClearPass Device Insight Tag.

Which Type (namespace) should you specify for the rule?

A.

Application

B.

Tips

C.

Device

D.

Endpoint

You need to set up an HPE Aruba Networking VIA solution for a customer who needs to support 2100 remote employees. The customer wants employees to

download their VIA connection profile from the VPNC. Only employees who authenticate with their domain credentials to HPE Aruba Networking ClearPass Policy

Manager (CPPM) should be able to download the profile. (A RADIUS server group for CPPM is already set up on the VPNC.)

How do you configure the VPNC to enforce that requirement?

A.

Set up a VIA Authentication Profile that uses CPPM ' s server group; reference that profile in the VIA Web Authentication Profile.

B.

Reference CPPM ' s server group in an AAA profile; then, apply that profile to the VPNC ' s Internet-facing ports.

C.

Create a new VPN Authentication Profile and then reference CPPM ' s default server group in that profile.

D.

Set up a VIA Authentication Profile that uses CPPM ' s server group; reference that profile in the VIA Connection Profile.

A company has HPE Aruba Networking infrastructure devices. The devices authenticate clients to HPE Aruba Networking ClearPass Policy Manager (CPPM). You want CPPM to track information about clients, such as their IP addresses and their network bandwidth utilization. What should you set up on the network infrastructure devices to help that happen?

A.

Logging with CPPM configured as a Syslog server.

B.

Dynamic authorization enabled in the RADIUS settings for CPPM.

C.

RADIUS accounting to CPPM, including interim updates.

D.

An IF-MAP interface with CPPM as the destination.