New Year Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

HP HPE6-A73 Aruba Certified Switching Professional Exam Exam Practice Test

Page: 1 / 13
Total 127 questions

Aruba Certified Switching Professional Exam Questions and Answers

Question 1

An administrator will be deploying NetEdit to manage an Aruba solution. What does NetEdit support?

Options:

A.

Manages AOS-CX switches and Aruba gateways

B.

Support for Aruba-supplied security updates

C.

Tracks configuration and hardware information

D.

Can be purchased as a VM and/or hardware appliance

Question 2

Which statement is correct regarding ACLs and TCAM usage?

Options:

A.

Applying an ACL to a group of ports consumes the same resources as specific ACE entries

B.

Using object groups consumes the same resources as specific ACE entries

C.

Compression is automatically enabled for ASIC TCAMs on AOS-CX switches

D.

Applying an ACL to a group of VLANs consumes the same resources as specific ACE entries

Question 3

An administrator wants to track what configuration changes were made on a switch. What should the

administrator implement to see the configuration changes on an AOS-CX switch?

Options:

A.

AAA authorization

B.

Network Analysis Engine (NAE)

C.

AAA authentication

D.

VSX synchronization logging

Question 4

Examine the configuration performed on newly deployed AOS-CX switches:

Question # 4

After performing this configuration, the administrator notices that the switch ports always remain in the EAP start state. What should the administrator do to fix this problem?

Options:

A.

Define the server group cppm

B.

Set the ports to client-mode

C.

Create and assign a local user role to the ports

D.

Enable change of authorization (CoA)

Question 5

Examine the attached diagram

Question # 5

Two AOS-CX switches are configured for VSX at the access layer, where servers attached to them. An SVI interface is configured for VLAN 10 and serves as the default gateway for VLAN 10. The ISL link between the switches fails, but the keepalive interface functions. Active gateway has been configured on the switches.

What is correct about access from the servers to the Core?

Options:

A.

Server 2 can successfully access the core layer via the keepalive link.

B.

Server 1 and Server 2 can communicate with each other via the core layer.

C.

Server 2 cannot access the core layer.

D.

Server 1 can access the core layer via both uplinks.

Question 6

An administrator is implementing a multicast solution in a multi-VLAN network. Which statement is true about the configuration of the switches in the network?

Options:

A.

IGMP snooping must be enabled on all interfaces on a switch to intelligently forward traffic

B.

IGMP requires join and leave messages to graft and prune multicast streams between switches

C.

IGMP must be enabled on all routed interfaces where multicast traffic will traverse

D.

IGMP must be enabled on all interfaces where multicast sources and receivers are connected

Question 7

What would prevent two OSPF routers from forming an adjacency? (Select two.)

Options:

A.

Different priorities

B.

Different area types

C.

Different MTU sizes

D.

Different IP addresses

E.

Different router IDs

Question 8

A network has an ABR that connects area 0 and 1. A network engineer configures a summarized route for area 0. The ABR is a designated router (DR) for the segment it uses to connect to area 1.

Which LSA type is assigned to this route when the summarized route is advertised into area 1 by the ABR?

Options:

A.

LSA1

B.

LSA4

C.

LSA3

D.

LSA2

Question 9

A company is implementing AOS-CX switches at the access layer. The company wants to implement access control for employees and guests.

Which security features will require a ClearPass server to be installed and used by the company?

Options:

A.

Downloadable user roles

B.

Dynamic segmentation

C.

User-based tunneling (UBT)

D.

Change of authorization (CoA)

Question 10

Examine the network exhibit.

Question # 10

A company has a guest implementation for wireless and wired access. Wireless access is implemented

through a third-party vendor. The company is concerned about wired guest traffic traversing the same network as the employee traffic. The network administrator has established a GRE tunnel between AOS-CX switches where guests are connected to a routing switch in the DMZ.

Which feature should the administrator implement to ensure that the guest traffic is tunneled to the DMZ while the employee traffic is forwarded using OSPF?

Options:

A.

OSPF route maps using the “set metric” command

B.

Policy-based routing (PBR)

C.

User-based tunneling (UBT)

D.

Classifier policies

Question 11

In AOS-CX switching, what determines when a frame is forwarded by the switch between the ingress and the egress port?

Options:

A.

Egress port

B.

Ingress port

C.

VSX switch tables

D.

Fabric Load Balancer

Question 12

An administrator of a large campus network needs a solution that will provide root cause analytics to quickly identify problems so that they can quickly be fixed.

Which AOS-CX switch feature should the administrator utilize to help with root cause analytics?

Options:

A.

NAE

B.

VoQ

C.

NetEdit

D.

VSX

Question 13

An administrator will be replacing a campus switching infrastructure with AOS-CX switches that support VSX capabilities. The campus involves a core, as well as multiple access layers. Which feature should the

administrator implement to allow both VSX-capable core switches to process traffic sent to the default gateway in the campus VLANs?

Options:

A.

VRF

B.

VRRP

C.

IP helper

D.

Active gateway

Question 14

How is voice traffic prioritized correctly on AOS-CX switches?

Options:

A.

By defining device profiles with QOS settings

B.

By placing it in the strict priority queue

C.

By implementing voice VLANs

D.

By implementing weighted fair queueing (WFQ)

Question 15

A network engineer is using NetEdit to manage AOS-CX switches. The engineer notices that a lot of thirdparty VoIP phones are showing up in the NetEdit topology. The engineer deletes these, but they are

automatically rediscovered by NetEdit and added back in.

What should the administrator do to solve this problem?

Options:

A.

Change the VoIP phone SNMP community string to something unknown by NetEdit

B.

Disable LLDP globally on the AOS-CX switches where phones are connected

C.

Disable SSH access on all the VoIP phones

D.

Disable the RESTful API on all the VoIP phones

Question 16

An administrator has an AOS-CX switch configured with:

router ospf 1

area 0

area 1 stub no-summary

It is the only ABR for area 1. The switch has the appropriate adjacencies to routing switches in areas 0 and 1.

The current routes in each area are:

Area 0: 5 routes (LSA Type 1 and 2)

Area 1: 10 routes (LSA Type 1 and 2)

External routes: 2 (LSA Type 5)

Based on the above configuration, how many OSPF routes will routing switches see in Area 1?

Options:

A.

15

B.

6

C.

11

D.

12

Question 17

A company has recently upgraded their campus switching infrastructure with AOS-CX switches. They have

implemented 802.1X authentication on access ports where laptop and IOT devices typically connect. An

administrator has noticed that for POE devices, the AOS-CX switch ports are delivering the maximum wattage

to the port instead of what the device actually needs.

Concerned about this waste of electricity, what should the administrator implement to solve this problem?

Options:

A.

Implement a classifier policy with the correct power definitions

B.

Create device profiles with the correct power definitions

C.

Enable AAA authentication to exempt LLDP and/or CDP information

D.

Globally enable the QoS trust setting for LLDP and/or CDP

Question 18

Which concept is implemented using Aruba’s dynamic segmentation?

Options:

A.

Root of trust

B.

Device fingerprinting

C.

Zero Touch Provisioning

D.

Colorless port

Question 19

What is a best practice concerning voice traffic and dynamic segmentation on AOS-CX switches?

Options:

A.

Controller authentication and user-based tunneling of the voice traffic

B.

Switch authentication and user-based tunneling of the voice traffic

C.

Controller authentication and port-based tunneling of the voice traffic

D.

Switch authentication and local forwarding of the voice traffic

Question 20

What is correct regarding the operation of VSX and multicasting with PIM-SM routing configured?

Options:

A.

Each VSX peers runs PIM and builds its own group database. One of the VSX peers is elected as the

designated router (DR) to forward multicast streams to a receiver VLAN

B.

Each VSX peers runs PIM and creates a shared group database. Both VSX peers can forward multicast

streams to receivers in a VLAN, achieving load sharing

C.

Each VSX peers runs PIM and builds its own group database. Both VSX peers can forward multicast

streams to receivers in a VLAN, achieving load sharing

D.

Each VSX peers runs PIM and creates a shared group database. One of the VSX peers is elected as the

designated router (DR) to forward multicast streams to a receiver VLAN

Question 21

An administrate is managing a VSX pair of AOS-CX switches. The administrator configures the following on the secondary switch:

secondary (config)# vlan 100

secondary (conflg. vlan-100) # description BBB

Currently VLAN 100 does not exist on the primary switch. The administrator then accesses the primary switch and configures the following:

Primary(config) vlan 100 primary(config-v1an-100) # description AAA

What Is correct regarding the results of this configuration?

Options:

A.

Each switch will have a different description defined.

B.

Both switches will have a description of "AAA".

C.

Both switches will have a description of "BBS".

D.

An error Is displayed on the primary switch regarding a mismatched parameter.

Question 22

An AOS-CX switch is configured to implement downloadable user roles. Examine the AOS-CX switch output:

Question # 22

Based on this output, what is the state of the user’s access?

Options:

A.

No downloadable user role exists

B.

MAC authentication has passed, but 802.1X authentication is in progress

C.

The RADIUS request timed out to the AAA server

D.

The port should be configured for 802.1X

Question 23

Examine the following AOS-CX configuration:

Question # 23

Based on this configuration, which statement is correct regarding IoT traffic?

Options:

A.

If 10.100.1.2 is not reachable, the IoT traffic will be automatically dropped by the switch

B.

If a specific route is not available in the routing table, the traffic will be routed to 10.100.1.2

C.

The next hop of 10.100.1.2 can be one or more hops away from the AOS-CX switch

D.

All routes are ignored in the routing table for IoT traffic, which is routed to 10.100.1.2

Question 24

What is required when implementing captive portal an AOS-CX switches?

Options:

A.

Certificate installed on the switch

B.

Web server running on the switch

C.

Device fingerprinting

D.

AAA server

Question 25

An administrator is managing a VSX pair of AOS-CX switches An administrator configures the following on the primary AOS-CX switch:

Question # 25

Options:

A.

The primary switch will erase VLAN 200 from the VSX pair

B.

The VLAN is only created on the secondary switch.

C.

The operation is not allowed by the switch and a CLI error is displayed

D.

The VLAN is created on both the primary and secondary switches

Question 26

An administrator is defining a VSX LAG on a pair of AOS-CX switches that are defined as primary and

secondary. The VSX LAG fails to establish successfully with a remote switch; however, after verification, the remote switch is configured correctly. The administrator narrows down the problem to the configuration on the AOS-CX switches.

What would cause this problem?

Options:

A.

Local optimization was not enabled on the VSX LAG

B.

The VSX LAG hash does not match the remote peer

C.

The VSX LAG interfaces are in layer-3 mode

D.

LACP was enabled in active mode on the VSX LAG

Question 27

Examine the output from an AOS-CX switch implementing a dynamic segmentation solution involving

downloadable user roles:

Switch# show port-access role clearpass

Role information:

Name : icxarubadur_employee-3044-2

Type : clearpass

Status: failed, parsing_failed

Reauthentication Period :

Authentication Mode :

Session Timeout :

The downloadable user roles are not being downloaded to the AOS-CX switch. Based on the above output,

what is the problem?

Options:

A.

The certificate that ClearPass uses in invalid

B.

The AOS-CX switch does not have the ClearPass certificate involved

C.

DNS fails to resolve the ClearPass server’s FQDN

D.

There is a date/time issue between the ClearPass server and the switch

Question 28

How does PIM build the IP multicast routing table to route traffic between a multicast source and one or more receivers?

Options:

A.

It uses the unicast routing table and reverse path forwarding (RPF)

B.

It uses IGMP and calculates a shortest path tree (SPT)

C.

It uses the shortest path first (SPF) algorithm derived from link state protocols

D.

It uses the Bellman-Ford algorithm derived from distance vector protocols

Question 29

Examine the partial output of the BGP routing table of an AOS-CX switch:

Question # 29

The switch is learning about four possible path to reach the 1.0.0.0/8 network. Based on this output, which next-hop route will the AOS-CX select to be placed in the IP routing table?

Options:

A.

192.168.1.5

B.

192.168.2.5

C.

192.168.3.5

D.

192 1684 5

Question 30

Examine the commands entered on an AOS-CX switch:

What is true regarding this configuration for traffic received on interface 100?

Options:

A.

The default next-hop address supersedes the two preceding next-hop addresses

B.

The traffic is always dropped is the next-hop addresses are unreachable

C.

The traffic will be routed with the IP routing table entries if the next-hop addresses are unreachable

D.

The next-hop address of 1.1.1.1 is overwritten by the next-hop address of 2.2.2.2

Question 31

When implementing deficit weighted round robin queuing, what importance does the weight value have?

Options:

A.

Prioritizing latency-sensitive traffic

B.

Queue priority in processing traffic

C.

Strict priority queue

D.

Percentage of interface bandwidth

Question 32

A network administrator wants to replace older access layer switches with AOS-CX 6300 switches.

Which virtual switching technology can the administrator implement with this solution?

Options:

A.

Both VSF and VSX

B.

Only Backplane stacking

C.

Only VSF

D.

Only VSX

Question 33

What is correct regarding rate limiting and egress queue shaping on AOS-CX switches?

Options:

A.

Rate limiting and egress queue shaping can be used to restrict inbound traffic

B.

Limits can be defined only for broadcast and multicast traffic

C.

Rate limiting and egress queue shaping can be applied globally

D.

Traffic rate limit is configured on queue level

Question 34

An administrator is managing a network comprised of AOS-CX switches deployed at the aggregation layer. The switches are paired in a VSX stack and run the OSPF routing protocol. The administrator is concerned about how long it takes for OSPF to converge when one of the VSX switches has to reboot.

What should the administrator to do speed up the OSPF convergence of the switch that is rebooting?

Options:

A.

Change the VSXISL link from an OSPF broadcast link point-to-point.

B.

Implement graceful restart on the VSX switches and their neighboring OSPF switches.

C.

Decrease the VSX initial synchronization timer on the two VSX switches.

D.

Define non-backbone areas on the VSX switches as totally stubby areas.

Question 35

MAC authentication is enabled on port 1/1/27 of an AOS-CX switch. The following MAC addresses are defined on the AAA server:

* 88:3a:30:97:b6:00

* 00:50:56:b1:fc:9b

Examine the AOS-CX switch output:

Question # 35

Based on this information, what is true concerning port 1/1/27?

Options:

A.

Device-mode is enabled with a client limit of 1.

B.

Device-mode is enabled with a client limit of 2.

C.

Client-mode is enabled with a client limit of 1.

D.

Client-mode is enabled with a client limit of 2.

Question 36

An administrator is replacing the current access switches with AOS-CX switches. The access layer switches

must authenticate user and networking devices connecting to them. Some devices support no form of

authentication, and some support 802.1X. Some ports have a VoIP phone and a PC connected to the same

port, where the PC is connected to the data port of the phone and the phone’s LAN port is connected to the switch.

Which statement is correct about this situation?

Options:

A.

802.1X must be configured to work in fallback mode

B.

Device fingerprinting is required for authentication

C.

The client-limit setting for port access needs to be changed

D.

Device mode should be implemented

Question 37

A network engineer for a company with 896 users across a multi-building campus wants to gather statistics on an important switch uplink and create actions based on issues that occur on the uplink. How often does an NAE agent gather information from the current state database in regard to the uplink interfaces?

Options:

A.

Once every 60 seconds

B.

Once every 1 second

C.

Once every 30 seconds

D.

Once every 5 seconds

Question 38

Examine the network topology.

Question # 38

Company XYZ has two connections to a service provider (ISP1). Here is the configuration of Router1:

Question # 38

Here is the configuration of Router2:

Question # 38

Based on configuration of Router1 and Router2, which BGP metric is being manipulated?

Options:

A.

Weight

B.

Multiple exit discriminator

C.

Local preference

D.

AS path length

Page: 1 / 13
Total 127 questions