Big Halloween Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

HP HPE7-A01 Dumps

Page: 1 / 14
Total 139 questions

Aruba Certified Campus Access Professional Exam Questions and Answers

Question 1

Your manufacturing client is deploying twenty headless scanners in their warehouse. These new devices do not support 802.1X authentication.

How does the gateway determine the device's role and VLAN derivation-rules when using MPSK Local?

Options:

A.

From the Type-Length-Value based on the Aruba-MPSK-Key-Name.

B.

It pulls the device roles from HPE Aruba Networking Central during deployment.

C.

From the device's Calling-Station-ID in the RADIUS Access-Request.

D.

From the MPSK roles defined in HPE Aruba Networking Central's security dashboard.

Question 2

Match the appropriate QoS concept with its definition. (Options may be used more than once or not at all.)

as

Options:

Question 3

Which statement best describes QoS?

Options:

A.

Determining which traffic passes specified quality metrics

B.

Scoring traffic based on the quality of the contents

C.

Identifying specific traffic for special treatment

D.

Identifying the quality of the connection

Question 4

With Aruba CX 6300. how do you configure ip address 10 10 10 1 for the interface in default state for interface 1/1/1?

Options:

A.

int 1/1/1. switching, ip address 10 10 10 1/24

B.

int 1/1/1. no switching, ip address 10 10 10.1/24

C.

int 1/1/1. ip address 10.10.10.1/24

D.

int 1/1/1. routing, ip address 10.10.10 1/24

Question 5

A customer is using stacked Aruba CX 6200 and CX 6300 switches for access and a VSX pair of Aruba CX 8325 as a collapsed core 802 1X is implemented for authentication. Due to the lack of cabling, some unmanaged switches are still in use Sometimes devices behind these switches cause network outages The switch should send a warning to the helpdesk when the problem occurs You have been asked to implement an effective solution to the problem

What is the solution for this?

Options:

A.

Configure spanning tree on the Aruba CX 8325 switches Set the trap-option

B.

Configure loop protection on all edge ports of the Aruba CX 6200 and CX 6300 switches No trap option is needed

C.

Configure loop protection on all edge ports of the Aruba CX 6200 and CX 6300 switches Set up the trap-option

D.

Configure spanning tree on the Aruba CX 6200 and CX 6300 switches No trap option is needed

Question 6

For the Aruba CX 6400 switch, what does virtual output queueing (VOQ) implement that is different from most typical campus switches?

Options:

A.

large ingress packet buffers

B.

large egress packet buffers

C.

per port ASICs

D.

VSX

Question 7

Two AOS-CX switches are configured with VSX at the the Access-Aggregation layer where servers attach to them An SVI interface is configured for VLAN 10 and serves as the default gateway for VLAN 10. The ISL link between the switches fails, but the keepalive interface functions. Active gateway has been configured on the VSX switches.

as

What is correct about access from the servers to the Core? (Select two.)

Options:

A.

Server 1 can access the core layer via the keepalrve link

B.

Server 2 can access the core layer via the keepalive link

C.

Server 2 cannot access the core layer.

D.

Server 1 can access the core layer via both uplinks

E.

Server 1 and Server 2 can communicate with each other via the core layer

F.

Server 1 can access the core layer on only one uplink

Question 8

You are proposing new CX 8360 VSX switches to replace a customers existing core switches. The customer Is concerned about the possibility of a split-brain scenario between the VSX pair. How Is the VSX pair affected when the ISL is down 3nd keepalive is down?

Options:

A.

The VSX node with lower system-id continues forwarding.

B.

Both VSX nodes will automatically reboot and keep LAG interfaces shutdown.

C.

Both VSX nodes still forward tame

D.

The VSX node with higher uptime continues forwarding.

Question 9

Match the topics with the underlying technologies (Options may be used more than once or not at all.)

as

Options:

Question 10

A network engineer recently identified that a wired device connected to a CX Switch is misbehaving on the network To address this issue, a new ClearPass policy has been put in place to prevent this device from connecting to the network again.

Which steps need to be implemented to allow ClearPass to perform a CoA and change the access for this wired device? (Select two.)

Options:

A.

Confirm that NTP is configured on the switch and ClearPass

B.

Configure dynamic authorization on the switch.

C.

Bounce the switchport

D.

Use Dynamic Segmentation.

E.

Configure dynamic authorization on the switchport

Question 11

What is true regarding 802.11k?

Options:

A.

It extends radio measurements to define mechanisms for wireless network management of stations

B.

It reduces roaming delay by pre-authenticating clients with multiple target APs before a client roams to an AP

C.

It provides mechanisms for APs and clients to dynamically measure the available radio resources.

D.

It considers several metrics before it determines if a client should be steered to the 5GHz band, including client RSSI

Question 12

A company deployed Dynamic Segmentation with their CX switches and Gateways After performing a security audit on their network, they discovered that the tunnels built between the CX switch and the Aruba Gateway are not encrypted. The company is concerned that bad actors could try to insert spoofed messages on the Gateway to disrupt communications or obtain information about the network.

Which action must the administrator perform to address this situation?

Options:

A.

Enable Secure Mode Enhanced

B.

Enable Enhanced security

C.

Enable Enhanced PAPI security

D.

Enable GRE security

Question 13

You are configuring an SVI on an Aruba CX switch that needs to have the following characteristics:

• VLANID = 25

. IPv4 address 10 105 43 1 with mask 255 255 255.0

• IPv6 address fd00:5708::f02d:4df6 with a 64 bit prefix length

• member of VRF eng

• VRF eng and VLAN 25 have not yet been created

Which command lists will satisfy the requirements with the least number of commands?

A)

as

B)

as

C)

as

D)

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 14

For an Aruba AOS10 AP in mixed mode, which factors can be used to determine the forwarding role assigned to a client? (Select two.)

Options:

A.

Client IP address

B.

802.1X authentication result

C.

Client MAC address

D.

Client SSID

E.

Client VLAN

Question 15

A large retail client is looking to generate a rich set of contextual data based on the location information of wireless clients in their stores Which standard uses Round Trip Time (RTT) and Fine Time Measurements (FTM) to calculate the distance a client is from an AP?

Options:

A.

802.11ah

B.

802.11mc

C.

802.11be

D.

802.11V

Question 16

Which statements are true about VSX LAG? (Select two.)

Options:

A.

The total number of configured links may not exceed 8 for the pair or 4 per switch

B.

Outgoing traffic is switched to a port based on a hashing algorithm which may be either switch in the pair

C.

LAG traffic is passed over VSX ISL links only while upgrading firmware on the switch pair

D.

Outgoing traffic is preferentially switched to local members of the LAG.

E.

Up to 255 VSX lags can be configured on all 83xx and 84xx model switches.

Question 17

Refer to Exhibit:

as

With Access-1, What needs to be identically configured With MSTP to load-balance VLANS?

Options:

A.

Spanning-tree bpdu-guard setting

B.

Spanning-tree instance vlan mapppjng

C.

spanning-tree Cist mapping

D.

Spanning-tree root-guard setting

Question 18

Match the solution components of NetConductor (Options may be used more than once or not at all.)

as

Options:

Question 19

A company recently deployed new Aruba Access Points at different branch offices Wireless 802.1X authentication will be against a RADIUS server in the cloud. The security team is concerned that the traffic between the AP and the RADIUS server will be exposed.

What is the appropriate solution for this scenario?

Options:

A.

Enable EAP-TLS on all wireless devices

B.

Configure RadSec on the AP and Aruba Central.

C.

Enable EAP-TTLS on all wireless devices.

D.

Configure RadSec on the AP and the RADIUS server

Question 20

Which method is used to onboard a new UXI in an existing environment with 802 1X authentication? (The sensor has no cellular connection)

Options:

A.

Use the UXI app on your smartphone and connect the UXI via Bluetooth

B.

Use the Aruba installer app on your smartphone to scan the barcode

C.

Connect the new UXI from an already installed one and adjust the initial configuration.

D.

Use the CLI via the serial cable and adjust the initial configuration.

Question 21

You are setting up a customer's 150 headless loT devices that do not support 802.1 X. What should you use?

Options:

A.

Multiple Pre-Shared Keys (MPSK) Local

B.

Multiple Pre-Shared Keys (MPSK) with WPA3-AES

C.

HPE Aruba Networking ClearPass profiling with MAC-AUTH

D.

HPE Aruba Networking ClearPass profiling with WPA-PSK

Question 22

You are deploying Aruba CX 6300's with the customers requirement to only allow one (1) VoIP phone and one (1) device.

The following local role gets assigned to the phone

port-access rote VoIP device-traffic-class voice

What set of commands best fits this requirement?

Options:

A.

interface 1/1/1

aaa authentication port-access client-limit 2

aaa authentication port-access auth-mode client-mode

B.

interface 1/1/1

aaa authentication port-access auth-mode multi-domain

C.

interface 1/1/1

aaa authentication port-access client-limit multi-domain 2 aaa authentication port-access auth-mode multi-domain

D.

interface 1/1/1

aaa authentication port-access client-limit 1

aaa authentication port-access auth-mode device-mode

Question 23

Your customer is having issues with Wi-Fi 6 clients staying connected to poor-performing APs when a higher throughput APs are closer. Which technology should you implement?

Options:

A.

Clearpass

B.

ClientMatch

C.

Airmatch

D.

ARM

Question 24

The administrator notices that wired guest users that have exceeded their bandwidth limit are not being disconnected Access Tracker in ClearPass indicates a disconnect CoA message is being sent to the AOS-CX switch.

An administrator has performed the following configuration

as

What is the most likely cause of this issue?

Options:

A.

Change of Authorization has not been globally enabled on the switch

B.

The SSL certificate for CPPM has not been added as a trust point on the switch

C.

There is a mismatch between the RADIUS secret on the switch and CPPM.

D.

There is a time difference between the switch and the ClearPass Policy Manager

Question 25

Which statements regarding Aruba NAE agents are true? (Select two )

Options:

A.

A single NAE script can be used by multiple NAE agents

B.

NAE agents are active at all times

C.

NAE agents will never consume more than 10% of switch processor resources

D.

NAE scripts must be reviewed and signed by Aruba before being used

E.

A single NAE agent can be used by multiple NAE scripts.

Question 26

You are doing tests in your lab and with the following equipment specifications:

• AP1 has a radio that generates a 20 dBm signal

• AP2 has a radio that generates a 8 dBm signal

• AP1 has an antenna with a gain of 7 dBI.

• AP2 has an antenna with a gain of 12 dBI.

• The antenna cable for AP1 has a 3 dB loss

• The antenna cable forAP2 has a 3 OB loss.

What would be the calculated Equivalent Isotropic Radiated Power (EIRP) for AP1?

Options:

A.

2dBm

B.

8 dBm

C.

22 dBm

D.

24 dBm

Question 27

A customer has several hundred wireless loT devices and is looking for an authentication solution that meets the following requirements:

as

Which solutions will address the customer's requirements? (Select two.)

Options:

A.

Local User Derivation Rules

B.

MPSK Local with MAC Authentication

C.

MPSK and an internal RADIUS server

D.

MPSK Local with EAP-TLS

E.

HPE Aruba Networking ClearPass Policy Manager

Question 28

your customer has asked you to assign a switch management role for a new user The customer requires the user role to View switch configuration information and have access to the PUT and POST meth0ds for REST API.

Which default AOS-CX user role meets these requirements?

Options:

A.

administrators

B.

auditors

C.

sysops

D.

helpdesk

Question 29

What is an OSPF transit network?

Options:

A.

a network that uses tunnels to connect two areas

B.

a special network that connects two different areas

C.

a network on which a router discovers at least one neighbor

D.

a network that connects to a different routing protocol

Question 30

Refer to the exhibit.

as

In the Core-2 configuration of spanning-tree instance 2 priority 0, what needs to be configured to enable the root for VLAN 20 while VLAN 10 remains root on Core-1?

Options:

A.

Spanning-tree instance 2 VLAN 20

B.

Spanning-tree priority 0 VLAN 20

C.

Spanning-tree priority root VLAN 20

D.

Spanning-tree VLAN 20

Question 31

Refer to the image.

as

Your customer is complaining of weak Wi-Fi coverage in their office. They mention that the office on the other side of the hall has much better signal What is the likely cause of this issue7

Options:

A.

The AP is a remote access point.

B.

The AP is using a directional antenna.

C.

The AP is an outdoor access point.

D.

The AP is configured in Mesh mode

Question 32

Refer to the exhibit.

as

With Core-1. what is the default value for config-revision?

Options:

A.

0

B.

1

C.

1-0

D.

0. 0

Question 33

A customer wants to provide wired security as close to the source as possible The wired security must meet the following requirements:

-allow ping from the IT management VLAN to the user VLAN

-deny ping sourcing from the user VLAN to the IT management VLAN

The customer is using Aruba CX 6300s

What is the correct way to implement these requirements?

Options:

A.

Apply an outbound ACL on the user VLAN allowing temp echo-reply traffic toward the IT management VLAN

B.

Apply an inbound ACL on the user VLAN allowing icmp echo-reply traffic toward the IT management VLAN

C.

Apply an inbound ACL on the user VLAN denying icmp echo traffic toward the IT management VLAN

D.

Apply an outbound ACL on the user VLAN denying icmp echo traffic toward the IT management VLAN

Question 34

You must ensure the HPEAruba network you are configuring for a client is capable of plug-and-play provisioning of access points. What enables this capability?

Options:

A.

UCC Service

B.

LLDP-MED

C.

SRTP

D.

CSMA

Question 35

What steps are part of the Key Management workflow when a wireless device is roaming from AP1 to AP2? (Select two.)

Options:

A.

AP1 will cache the client's information and send it to the Key Management service

B.

The Key Management service receives from AirMatch a list of all AP2's neighbors

C.

The Key Management service receives a list of all AP1 s neighbors from AirMatch.

D.

The Key Management service then generates R1 keys for AP2's neighbors.

E.

A client associates and authenticates with the AP2 after roaming from AP1

Question 36

On AOS10 Gateways, which device persona is only available when configuring a Gateway-only group'?

Options:

A.

Edge

B.

Mobility

C.

Branch

D.

VPN Concentrator

Question 37

Which statements are true regarding a VXLAN implementation on Aruba Switches? (Select two.)

Options:

A.

MTU size must be increased beyond the default

B.

VNIs encapsulate and decapsulate VXLAN traffic

C.

VTEPs encapsulate and decapsulate VXLAN traffic

D.

They are only available for datacenter switches (CX 8k, 9k,10k)

E.

All Aruba CX switches support VXLAN.

Question 38

What is one advantage of using OCSP vs CRLs for certificate validation?

Options:

A.

reduces latency between the time a certificate is revoked and validation reflects this status

B.

less complex to implement

C.

higher availability for certificate validation

D.

supports longer certificate validity periods

Question 39

How is Multicast Transmission Optimization implemented in an HPE Aruba wireless network?

Options:

A.

"The optimal rate for sending multicast frames is based on the highest broadcast rate across all associated clients

B.

When this option is enabled the minimum default rate for multicast traffic is set to 12 Mbps for 5 GHz

C.

The optimal rate for sending multicast frames is based on the lowest broadcast rate across all associated clients.

D.

The optimal rate for sending multicast frames is based on the lowest unicast rate across all associated clients.

Question 40

List the firewall role derivation flow in the correct order

as

Options:

Question 41

Which standard supported by some HPE Aruba Networking APs can enable a customer to accurately locate wireless client devices within a few meters?

Options:

A.

802.1 Imc

B.

807.11ah

C.

802.11be

D.

802.11v

Page: 1 / 14
Total 139 questions