Pre-Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

HP HPE7-A02 - Aruba Certified Network Security Professional Exam

Page: 1 / 5
Total 156 questions

A company has HPE Aruba Networking APs running AOS-10 and managed by HPE Aruba Networking Central. The company also has AOS-CX switches. The

security team wants you to capture traffic from a particular wireless client. You should capture this client ' s traffic over a 15 minute time period and then send the

traffic to them in a PCAP file.

What should you do?

A.

Go to the client ' s AP in HPE Aruba Networking Central. Use the " Security " page to run a packet capture.

B.

Access the CLI for the client ' s AP. Set up a mirroring session between its radio and a management station running Wireshark.

C.

Access the CLI for the client ' s AP ' s switch. Set up a mirroring session between the AP ' s port and a management station running Wireshark.

D.

Go to that client in HPE Aruba Networking Central. Use the " Live Events " page to run a packet capture.

A company issues user certificates to domain computers using its Windows CA and the default user certificate template. You have set up HPE Aruba Networking

ClearPass Policy Manager (CPPM) to authenticate 802.1X clients with those certificates. However, during tests, you receive an error that authorization has failed

because the usernames do not exist in the authentication source.

What is one way to fix this issue and enable clients to successfully authenticate with certificates?

A.

Configure rules to strip the domain name from the username.

B.

Change the authentication method list to include both PEAP MSCHAPv2 and EAP-TLS.

C.

Add the ClearPass Onboard local repository to the authentication source list.

D.

Remove EAP-TLS from the authentication method list and add TEAP there instead.

You have created a Web-based Health Check Service that references a posture policy. You want the service to trigger a RADIUS change of authorization (CoA) when a client receives a Healthy or Quarantine posture. Where do you configure those rules?

A.

In a RADIUS enforcement policy

B.

In the Agents and Software Updates > OnGuard Settings

C.

In the posture policy

D.

In a WEBAUTH enforcement policy

A company has AOS-CX switches, which authenticate clients to HPE Aruba Networking ClearPass Policy Manager (CPPM). CPPM is set up to receive a variety of information about clients ' profile and posture. New information can mean that CPPM should change a client ' s enforcement profile. What should you set up on the switches to help the solution function correctly?

A.

Enable RADIUS accounting to CPPM, including interim RADIUS accounting.

B.

Configure a RADIUS track that references CPPM ' s FQDN or IP address.

C.

Enable dynamic authorization, and specify CPPM as a dynamic authorization client.

D.

Re-configure the authentication server on the switch specifying CPPM as a TACACS server.

A company is using HPE Aruba Networking Central SD-WAN Orchestrator to establish a hub-spoke VPN between branch gateways (BGWs) at 1444 site and

VPNCs at multiple data centers.

What is part of the configuration that admins need to complete?

A.

At the global level, create default IPsec policies for the SD-WAN Orchestrator to use.

B.

In BGWs ' groups, select the VPNCs to which to connect in a DC preference list.

C.

In VPNCs ' groups, establish VPN pools to control which branches connect to which VPNCs.

D.

In BGWs ' and VPNCs ' groups, create default IKE policies for the SD-WAN Orchestrator to use.

An admin has configured an AOS-CX switch with these settings:

port-access role employees

vlan access name employees

This switch is also configured with CPPM as its RADIUS server.

Which enforcement profile should you configure on CPPM to work with this configuration?

A.

RADIUS Enforcement type with HPE-User-Role VSA set to " employees "

B.

HPE Aruba Networking Downloadable Role Enforcement type with role name set to " employees "

C.

HPE Aruba Networking Downloadable Role Enforcement type with gateway role name set to " employees "

D.

RADIUS Enforcement type with Aruba-User-Role VSA set to " employees "

You manage AOS-10 APs with HPE Aruba Networking Central. A role is configured on these APs with these rules (in order):

Allow UDP on port 67 to any destination

Allow any to network 10.1.4.0/23

Deny any to network 10.1.0.0/18 + log

Deny any to network 10.0.0.0/8

Allow any to any destination

You add this new rule immediately before rule 4:

Deny SSH to network 10.1.0.0/21 + denylist

After this change, what happens when a client assigned to this role sends SSH traffic to 10.1.7.12?

A.

The traffic is permitted

B.

The traffic is dropped and logged

C.

The traffic is dropped, and the client is denylisted

D.

The traffic is dropped (without any logging or further action against the client)

A company is using HPE Aruba Networking ClearPass Device Insight (CPDI) (the standalone application). In the CPDI security settings, Security Analysis is On,

the Data Source is ClearPass Devices Insight, and Enable Posture Assessment is On. You see that device has a Risk Score of 90.

What can you know from this information?

A.

The posture is unhealthy, and CPDI has also detected at least one vulnerability on the device.

B.

The posture is unhealthy, but CPDI has not detected any vulnerabilities on the device.

C.

The posture is healthy, but CPDI has detected multiple vulnerabilities on the device.

D.

The posture is unknown, and CPDI has detected exactly four vulnerabilities on the device.

HPE Aruba Networking Central displays an alert about an Infrastructure Attack that was detected. You go to the Security > RAPIDS events and see that the attack

was " Detect adhoc using Valid SSID. "

What is one possible next step?

A.

Use HPE Aruba Networking Central floorplans or the detecting AP identities to locate the general area for the threat.

B.

Look for the IP address associated with the offender and then check for that IP address among HPE Aruba Networking Central clients.

C.

Make sure that you have tuned the threshold for that check, as false positives are common for it.

D.

Make sure that clients have updated drivers, as faulty drivers are a common explanation for this attack type.

You are configuring an HPE Aruba Networking VIA solution for a customer. The customer wants this behavior for remote clients that connect to the VPN:

    They forward internet traffic locally.

    They forward traffic destined to the data center over the VPN.

How can you configure this behavior?

A.

Use the firewall role to which users are assigned after VIA Web authentication to configure the forwarding rules.

B.

Use the firewall role to which users are assigned after IKE authentication to configure the forwarding rules.

C.

Enable split tunneling in the VIA Connection Profile and add the data center networks to the tunneled networks list.

D.

Specify the data center networks in a VPN pool; associate that pool to the role to which users are assigned after IKE authentication.