Big Halloween Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

HP HPE7-A01 Aruba Certified Campus Access Professional Exam Exam Practice Test

Page: 1 / 14
Total 139 questions

Aruba Certified Campus Access Professional Exam Questions and Answers

Question 1

You are helping an onsite network technician bring up an Aruba 9004 gateway with ZTP for a branch office The technician was to plug in any port for the ZTP process to start Thirty minutes after the gateway was plugged in new users started to complain they were no longer able to get to the internet. One user who reported the issue stated their IP address is 172.16 0.81 However, the branch office network is supposed to be on 10.231 81.0/24.

What should the technician do to alleviate the issue and get the ZTP process started correctly?

Options:

A.

Turn off the DHCP scope on the gateway, and set DNS correctly on the gateway to reach Aruba Activate

B.

Move the cable on the gateway from port G0/0V1 tc port G0 0.0

C.

Move the cable on the gateway to G0/0/1. and add the device's MAC and Serial number in Central

D.

Factory default and reboot the gateway to restart the process.

Question 2

Refer to the exhibit.

Question # 2

A company has deployed 200 AP-635 access points. To but is not working as expected

What would be the correct action to fix the issue?

Options:

A.

Change the SSID to WPA3-Enhanced Open

B.

Change the SSID to WPA3-Enterprise (CCM).

C.

Change the SSID to WPA3-Personal

D.

Change the SSID to WPA3-Enterpnse (CNSA).

Question 3

A customer wants to deploy a Gateway and take advantage of all the SD-WAN features. Which persona role option should be selected?

Options:

A.

ArubaOS 10 Branch

B.

ArubaOS 10 VPN Concentrator

C.

ArubaOS 10 Wireless

D.

ArubaOS 10 Mobility

Question 4

Your Aruba CX 6300 VSF stack has OSPF adjacency over SVI 10 with LAG 1 to a neighboring device The following configuration was created on the switch:

Question # 4

A)

Question # 4

B)

Question # 4

C)

Question # 4

D)

Question # 4

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 5

A client is connecting to 802.1X SSID that has been configured in tunnel mode with the default AP-group settings.

After receiving Access-Accept from the RADIUS server, the Aruba Gateway will send Access-Accept to the AP through which tunnel?

Options:

A.

IPsec tunnel

B.

Split tunnel

C.

GRE tunnel

D.

PAR tunnel

Question 6

Refer to the output from a CX 6100 switch:

Question # 6

What is the correct detail that can be observed from the output above?

Options:

A.

The dBm values for Tx are too high and affect Rx signals.

B.

The dBm values for Rx are too low, indicating that the link is down.

C.

The dBm values for Rx are within acceptable values, and the link is up.

D.

The dbm values for T are too far away from 0, and the link is down.

Question 7

Your customer has asked you to assign a switch management role for a new user The customer requires the user role to only have Web Ul access to the System > Log page and only have access to the GET method for REST API for the /logs/event resource

Which default AOS-CX user role meets these requirements?

Options:

A.

administrators

B.

auditors

C.

sysops

D.

operators

Question 8

What is a primary benefit of BSS coloring?

Options:

A.

BSS color tags improve performance by allowing APS on the same channel to be farther apart

B.

BSS color tags improve security by identifying rogue APS and tagging them as threats.

C.

BSS color tags are applied on the wireless controllers and can reduce the threshold for interference_

D.

BSS color tags are applied to WI-Fi channels and can reduce the threshold tor interference

Question 9

A company recently deployed new Aruba Access Points at different branch offices Wireless 802.1X authentication will be against a RADIUS server in the cloud. The security team is concerned that the traffic between the AP and the RADIUS server will be exposed.

What is the appropriate solution for this scenario?

Options:

A.

Enable EAP-TLS on all wireless devices

B.

Configure RadSec on the AP and Aruba Central.

C.

Enable EAP-TTLS on all wireless devices.

D.

Configure RadSec on the AP and the RADIUS server

Question 10

What is used to retrieve data stored in a Management Information Base (MIS)?

Options:

A.

SNMPv3

B.

DSCP

C.

TLV

D.

CDP

Question 11

Your Director of Security asks you to assign AOS-CX switch management roles to new employees based on their specific job requirements. After the configuration was complete, it was noted that a user assigned with the auditors role did not have the appropriate level of access on the switch.

The user was not allowed to perform firmware upgrades and a privilege level of 15 was not assigned to their role. Which default management role should have been assigned for the user?

Options:

A.

sysadmin

B.

sysops

C.

administrators

D.

config

Question 12

Which statements regarding Aruba NAE agents are true? (Select two )

Options:

A.

A single NAE script can be used by multiple NAE agents

B.

NAE agents are active at all times

C.

NAE agents will never consume more than 10% of switch processor resources

D.

NAE scripts must be reviewed and signed by Aruba before being used

E.

A single NAE agent can be used by multiple NAE scripts.

Question 13

Which standard supported by some Aruba APs can enable a customer to accurately locate wireless client devices within a few meters?

Options:

A.

802.11mc

B.

802.11W

C.

802.11k

D.

802.11r

Question 14

By default, Best Effort is higher priority than which priority traffic type?

Options:

A.

All queues

B.

Background

C.

Internet Control

D.

Network Control

Question 15

For an Aruba AOS10 AP in mixed mode, which factors can be used to determine the forwarding role assigned to a client? (Select two.)

Options:

A.

Client IP address

B.

802.1X authentication result

C.

Client MAC address

D.

Client SSID

E.

Client VLAN

Question 16

Which statement best describes QoS?

Options:

A.

Determining which traffic passes specified quality metrics

B.

Scoring traffic based on the quality of the contents

C.

Identifying specific traffic for special treatment

D.

Identifying the quality of the connection

Question 17

Your Director of Security asks you to assign AOS-CX switch management roles to new employees based on their specific job requirements After the configuration was complete, it was noted that a user assigned with the administrators role did not have the appropriate level of access on the switch.

The user was not limited to viewing nonsensitive configuration information and a level of 1 was not assigned to their role Which default management role should have been assigned for the user?

Options:

A.

sysadmin

B.

operators

C.

helpdesk

D.

config

Question 18

Your customer currently has two (2) 5406 modular switches with MSTP configured as their core switches. You are proposing a new solution. What would you explain regarding the AOS-CX VSX switch pair when the Spanning-tree needs to be set up?

Options:

A.

Use vsx-sync in the MSTP region configuration to get synced.

B.

Enable vsx-sync stp-global in vsx mode to sync the configuration.

C.

Spanning-tree configuration is synced by default with VSX.

D.

Enable vsx-peer stp-global in vsx mode to sync the configuration.

Question 19

Which statements regarding 0SPFv2 route redistribution are true for Aruba OS CX switches? (Select two.)

Options:

A.

The "redistribute connected" command will redistribute all connected routes for the switch including local loopback addresses

B.

The "redistribute ospf" command will redistribute routes from all OSPF V2 and V3 processes

C.

The "redistribute static route-map connected-routes" command will redistribute all static routes without a matching deny in the route map "connected-routes".

D.

The "redistribute connected" command will redistribute all connected routes for the switch except local loopback addresses.

E.

The "redistribute static route-map connected-routes" command will redistribute all static routes with a matching permit in the route map "connected-routes-

Question 20

Your manufacturing client is deploying two hundred wireless IP cameras and fifty headless scanners in their warehouse. These new devices do not support 802.1X authentication.

How can HPE Aruba enhance security for these new IP cameras in this environment?

Options:

A.

Use MPSK Local to automatically provide unique pre-shared Keys for devices.

B.

Aruba ClearPass performs the 802.1X authentication and installs a certificate.

C.

MPSK provides for each device in the WLAN to have its own unique pre-shared Key.

D.

MPSK Local will allow the cameras to share a rey and the scanners to share a different

Question 21

Due to a shipping error, five (5) Aruba AP-515S and one (1) Aruba CX 6300 were sent directly to your new branch office You have configured a new group persona for the new branch office devices in Central, but you do not know their MAC addresses or serial numbers The office manager is instructed via text message on their smartphone to onboard all the new hardware into Aruba Central

What application must the office manager use on their phone to complete this task?

Options:

A.

Aruba Onboard App

B.

Aruba Central App

C.

Aruba CX Mobile App

D.

Aruba installer App

Question 22

List the firewall role derivation flow in the correct order

Question # 22

Options:

Question 23

Your manufacturing client is having installers deploy seventy headless scanners and fifty IP cameras in their warehouse These new devices do not support 802 1X authentication.

How can HPE Aruba reduce the IT administration overhead associated with this deployment while maintaining a secure environment using MPSK?

Options:

A.

Have the installers generate keys with ClearPass Self Service Registration.

B.

Have the MPSK gateway derive the unique pre-shared keys based on the MAC OUI.

C.

Use MPSK Local to automatically provide unique pre-shared keys for devices.

D.

MPSK Local will allow the cameras to share a key and the scanners to share a different key

Question 24

A customer wants to enable wired authentication across all their CX switches One of the requirements is that the switch must be able to authenticate a single computer connected through a VoIP phone.

Which feature should be enabled to support this requirement?

Options:

A.

Multi-Domain Authentication

B.

Device-Based Mode

C.

MAC Authentication

D.

Multi-Auth Mode

Question 25

When configuring UBT on a switch what will happen when a gateway role is not specified?

Options:

A.

The switch will put the client on the access VLAN

B.

The gateway will assign a default role to the client

C.

The switch will assign the default deny role to the client.

D.

The gateway will send back the deny role to the client.

Question 26

You are are doing tests in your lab and with the following equipment specifications:

• AP1 has a radio that generates a 16 dBm signal.

• AP2 has a radio that generates a 13 dBm signal.

• AP1 has an antenna with a gain of 8 dBi.

• AP2 has an antenna with a gain of 12 dBi. The antenna cable for AP1 has a 4 dB loss. The antenna cable for AP2 has a 3 dB loss.

What would be the calculated Equivalent Isotropic Radiated Power (EIRP) for AP1?

Options:

A.

-9 dBm

B.

20 dBm

C.

40 dBm

D.

15 dBm

Question 27

Your customer is interested in hearing more about how roles can help keep consistent policy enforcement in a distributed overlay fabric How would you explain this concept to them''

Options:

A.

Group Based Policy ID is applied on egress VTEP after device authentication and policy is enforced on ingress VTEP

B.

Role-based policies are tied to IP addresses which have an advantage over IP-based policies and role names are sent between VTEPs

C.

Group Based Policy ID is applied on ingress VTEP after device authentication and policy is enforced on egress VTEP

D.

Role-based policies enhance User Based Tunneling across the campus network and the policy traffic is protected with iPsec

Question 28

You are setting up a customer's 15 headless loT devices that do not support 802.1X. What should you use?

Options:

A.

Multiple Pre-Shared Keys (MPSK) Local

B.

Clearpass with WPA3-PSK

C.

Clearpass with WPA3-AES

D.

Multiple Pre-Shared Keys (MPSK) with WPA3-AES

Question 29

Which statements are true regarding a VXLAN Implementation on HPE Aruba Networking switches? (Select two.)

Options:

A.

They are only available for datacenter switches (CX 8k, 9k, 10k).

B.

VNIs encapsulate and decapsulate VXLAN traffic.

C.

MTU size must be increased beyond the default.

D.

All AOS-CX switches support VXLAN.

E.

VTEPs encapsulate and decapsulate VXLAN traffic.

Question 30

you need to have different routing-table requirements With Aruba CX 6300 VSF configuration.

Assuming the correct layer-2 VLAN already exists, how would you create a new SVI for a separate routing table?

Options:

A.

create a new VLAN, and attach the VRF to it.

B.

Create a new routing table, and attach VLANS to it

C.

Create a new SVI and use attach command.

D.

Create a new VLAN. and attach the routing table to it

Question 31

A company recently upgraded its campus switching infrastructure with Aruba 6300 CX switches. They have implemented 802.1X authentication on edge ports where laptop and loT devices typically connect An administrator has noticed that for PoE devices the pons are delivering the maximum wattage instead of what the device actually needs Upon connecting the loT devices, the devices request their specific required wattage through information exchange

Options:

A.

Concerned about this waste of electricity, what should the administrator implement to solve this problem?

B.

Enable AAA authentication to exempt LLDP and/or CDP information

C.

Globally enable the QoS trust setting for LLDP and/or CDP

D.

Create device profiles with the correct power definitions.

E.

implement a classifier policy with the correct power definitions.

Question 32

The administrator notices that wired guest users that have exceeded their bandwidth limit are not being disconnected Access Tracker in ClearPass indicates a disconnect CoA message is being sent to the AOS-CX switch.

An administrator has performed the following configuration

Question # 32

What is the most likely cause of this issue?

Options:

A.

Change of Authorization has not been globally enabled on the switch

B.

The SSL certificate for CPPM has not been added as a trust point on the switch

C.

There is a mismatch between the RADIUS secret on the switch and CPPM.

D.

There is a time difference between the switch and the ClearPass Policy Manager

Question 33

AppRF 2.0 allows you to:

Options:

A.

configure ACL and bandwidth control for applications

B.

classify web content based on reputation

C.

customize application signatures

D.

monitor applications and radio frequencies

Question 34

A network administrator is attempting to troubleshoot a connectivity issue between a group of users and a particular server The administrator needs to examine the packets over a period of time from their desktop; however, the administrator is not directly connected to the AOS-CX switch involved with the traffic flow.

What statements are correct regarding the ERSPAN session that needs to be established on an AOS-CX switch'? (Select two )

Options:

A.

On the source AOS-CX switch, the destination specified is the switch to which the administrator's desktop is connected

B.

The encapsulation protocol used is GRE.

C.

The encapsulation protocol used is VXLAN.

D.

The encapsulation protocol is UDP.

E.

On the source AOS-CX switch, the destination specified is the administrators desktop

Question 35

Match the topics with the underlying technologies (Options may be used more than once or not at all.)

Question # 35

Options:

Question 36

You are doing tests in your lab and with the following equipment specifications

• AP1 has a radio that generates a 10 dBm signal

• AP2 has a radio that generates a 11 dBm signal

• AP1 has an antenna with a gain of 9 dBi

• AP2 has an antenna with a gain of 12 dBi.

• The antenna cable for AP1 has a 2 dB loss

• The antenna cable for AP2 has a 3 dB loss

What would be the calculated Equivalent Isotropic Radiated Power (EIRP) for APT?

Options:

A.

26 dBm

B.

30 dBm

C.

17 dBm

D.

-12 dBm

Question 37

You are configuring an SVI on an Aruba CX switch that needs to have the following characteristics:

• VLANID = 25

. IPv4 address 10 105 43 1 with mask 255 255 255.0

• IPv6 address fd00:5708::f02d:4df6 with a 64 bit prefix length

• member of VRF eng

• VRF eng and VLAN 25 have not yet been created

Which command lists will satisfy the requirements with the least number of commands?

A)

Question # 37

B)

Question # 37

C)

Question # 37

D)

Question # 37

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 38

What is one advantage of using OCSP vs CRLs for certificate validation?

Options:

A.

reduces latency between the time a certificate is revoked and validation reflects this status

B.

less complex to implement

C.

higher availability for certificate validation

D.

supports longer certificate validity periods

Question 39

your customer has asked you to assign a switch management role for a new user The customer requires the user role to View switch configuration information and have access to the PUT and POST meth0ds for REST API.

Which default AOS-CX user role meets these requirements?

Options:

A.

administrators

B.

auditors

C.

sysops

D.

helpdesk

Question 40

Describe the difference between Class of Service (CoS) and Differentiated Services Code Point (DSCP).

Options:

A.

CoS has much finer granularity than DSCP

B.

CoS is only contained in VLAN Tag fields DSCP is in the IP Header and preserved throughout the IP packet flow

C.

They are similar and can be used interchangeably.

D.

CoS is only used to determine CLASS of traffic DSCP is only used to differentiate between different Classes.

Question 41

A customer is using a legacy application that communicates at layer-2. The customer would like to keep this application working to a remote site connected via layer-3 All legacy devices are connected to a dedicated Aruba CX 6200 switch at each site.

What technology on the Aruba CX 6200 could be used to meet this requirement?

Options:

A.

Inclusive Multicast Ethernet Tag (IMET)

B.

Ethernet over IP (EolP)

C.

Generic Routing Encapsulation (GRE)

D.

Static VXLAN

Page: 1 / 14
Total 139 questions