Black Friday Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

HP HPE7-A01 Aruba Certified Campus Access Professional Exam Exam Practice Test

Page: 1 / 12
Total 119 questions

Aruba Certified Campus Access Professional Exam Questions and Answers

Question 1

On AOS10 Gateways, which device persona is only available when configuring a Gateway-only group'?

Options:

A.

Edge

B.

Mobility

C.

Branch

D.

VPN Concentrator

Question 2

Your Director of Security asks you to assign AOS-CX switch management roles to new employees based on their specific job requirements. After the configuration was complete, it was noted that a user assigned with the auditors role did not have the appropriate level of access on the switch.

The user was not allowed to perform firmware upgrades and a privilege level of 15 was not assigned to their role. Which default management role should have been assigned for the user?

Options:

A.

sysadmin

B.

sysops

C.

administrators

D.

config

Question 3

What is the order of operations tor Key Management service for a wireless client roaming from AP1 to AP2?

Question # 3

Options:

Question 4

Match each PoE power class to Its corresponding 802.3 standard. (Options may he used more than once or not at all)

Question # 4

Options:

Question 5

What are the requirements to ensure that WMM is working effectively'? (Select two)

Options:

A.

The APs and the controller are Wi-Fi CERTIFIED for WMM which is enabled

B.

All APs need to be from the AP-5xx series and AP-6xx series which are Wi-Fi CERTIFIED 6.

C.

The Client must be Wi-Fi CERTIFIED for WMM and configured for WMM marking.

D.

The Aruba AOS10 APs installed have to be converted to controlled mode

E.

The AP needs to be connected via a tagged VLAN to the wired port

Question 6

Which statements are true about VSX LAG? (Select two.)

Options:

A.

The total number of configured links may not exceed 8 for the pair or 4 per switch

B.

Outgoing traffic is switched to a port based on a hashing algorithm which may be either switch in the pair

C.

LAG traffic is passed over VSX ISL links only while upgrading firmware on the switch pair

D.

Outgoing traffic is preferentially switched to local members of the LAG.

E.

Up to 255 VSX lags can be configured on all 83xx and 84xx model switches.

Question 7

A customer just upgraded aggregation layer switches and noticed traffic dropping for 120 seconds after the aggregation layer came online again. What is the best way to avoid having this traffic dropped given the topology below?

Question # 7

Options:

A.

Configure the linkup delay timer to 240 seconds to double the amount of lime for the initial phase to sync

B.

Configure the linkup delay timer to exclude LAGS 101 and 102, which will allow time for routing adjacencies to form and to learn upstream routes

C.

Configure the linkup delay timer to include LAGs 101 and 102, which will allow time for routing adjacencies lo form and to learn upstream routes

D.

Configure the linkup delay timer to 120 seconds, which will allow the right amount of time for the initial phase to sync

Question 8

In an ArubaOS 10 architecture using an AP and a gateway, what happens when a client attempts to join the network and the WLAN is configured with OWE?

Options:

A.

Authentication information is not exchanged

B.

The Gateway will not respond.

C.

No encryption is applied.

D.

RADIUS protocol is utilized.

Question 9

For the Aruba CX 6400 switch, what does virtual output queueing (VOQ) implement that is different from most typical campus switches?

Options:

A.

large ingress packet buffers

B.

large egress packet buffers

C.

per port ASICs

D.

VSX

Question 10

Using Aruba best practices what should be enabled for visitor networks where encryption is needed but authentication is not required?

Options:

A.

Wi-Fi Protected Access 3 Enterprise

B.

Opportunistic Wireless Encryption

C.

Wired Equivalent Privacy

D.

Open Network Access

Question 11

A company deployed Dynamic Segmentation with their CX switches and Gateways After performing a security audit on their network, they discovered that the tunnels built between the CX switch and the Aruba Gateway are not encrypted. The company is concerned that bad actors could try to insert spoofed messages on the Gateway to disrupt communications or obtain information about the network.

Which action must the administrator perform to address this situation?

Options:

A.

Enable Secure Mode Enhanced

B.

Enable Enhanced security

C.

Enable Enhanced PAPI security

D.

Enable GRE security

Question 12

Your Director of Security asks you to assign AOS-CX switch management roles to new employees based on their specific job requirements After the configuration was complete, it was noted that a user assigned with the administrators role did not have the appropriate level of access on the switch.

The user was not limited to viewing nonsensitive configuration information and a level of 1 was not assigned to their role Which default management role should have been assigned for the user?

Options:

A.

sysadmin

B.

operators

C.

helpdesk

D.

config

Question 13

You need to create a keepalive network between two Aruba CX 8325 switches for VSX configuration How should you establish the keepalive connection?

Options:

A.

SVI, VLAN trunk allowed all on ISL in default VRF

B.

routed port in custom VRF

C.

loopback 0 and OSPF area 0 in default VRF

D.

SVI, VLAN trunk allowed all on ISL in custom VRF

Question 14

What is true regarding 802.11k?

Options:

A.

It extends radio measurements to define mechanisms for wireless network management of stations

B.

It reduces roaming delay by pre-authenticating clients with multiple target APs before a client roams to an AP

C.

It provides mechanisms for APs and clients to dynamically measure the available radio resources.

D.

It considers several metrics before it determines if a client should be steered to the 5GHz band, including client RSSI

Question 15

With the Aruba CX switch configuration, what is the first-hop protocol feature that is used for VSX L3 gateway as per Aruba recommendation?

Options:

A.

Active Gateway

B.

Active-Active VRRP

C.

SVI with vsx-sync

D.

VRRP

Question 16

You are working on a network where the customer has a dedicated router with redundant Internet connections Tor outbound high-importance real-time audio streams from their datacenter All of this traffic.

• originates from a single subnet

• uses a unique range of UDP ports

• is required to be routed to the dedicated router

All other traffic should route normally The SVI for the subnet containing the servers originating the traffic is located on the core routing switch in the datacenter What should be configured?

Options:

A.

Configure a new OSPF area including both the core routing switch and the dedicated router

B.

Configure a BGP link between the core routing switch and the dedicated router and route filtering.

C.

Configure Policy Based Routing (PBR) on the core routing switch for the VRF with the servers’ SVI

D.

Configure a dedicated VRF on the core routing switch and make the dedicated router the default route.

Question 17

A company recently upgraded its campus switching infrastructure with Aruba 6300 CX switches. They have implemented 802.1X authentication on edge ports where laptop and loT devices typically connect An administrator has noticed that for PoE devices the pons are delivering the maximum wattage instead of what the device actually needs Upon connecting the loT devices, the devices request their specific required wattage through information exchange

Options:

A.

Concerned about this waste of electricity, what should the administrator implement to solve this problem?

B.

Enable AAA authentication to exempt LLDP and/or CDP information

C.

Globally enable the QoS trust setting for LLDP and/or CDP

D.

Create device profiles with the correct power definitions.

E.

implement a classifier policy with the correct power definitions.

Question 18

You are building a configuration in Central that will be used for a standardized network design for small sites for your company, you want to use GUI configuration for gateways and Aps, while template configuration for switches. You need to align with Aruba best practices.

Which set of actions will satisfy these requirements?

Options:

A.

Create one group in Central for switches a second group for APs. and a third group for gateways Create a unique site for each location, and assign devices to the appropriate site.

B.

Create one group in Central for switches and a second group for APs and gateways. Create a unique site for each location, and assign devices to the appropriate site.

C.

Create a single group in Central. Create a unique site for each location, and assign devices to the appropriate site.

D.

Create a single group in Central. Create a unique site for each type of device, and assign devices to the appropriate site.

Question 19

You are configuring an SVI on an Aruba CX switch that needs to have the following characteristics:

• VLANID = 25

. IPv4 address 10 105 43 1 with mask 255 255 255.0

• IPv6 address fd00:5708::f02d:4df6 with a 64 bit prefix length

• member of VRF eng

• VRF eng and VLAN 25 have not yet been created

Which command lists will satisfy the requirements with the least number of commands?

A)

Question # 19

B)

Question # 19

C)

Question # 19

D)

Question # 19

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 20

What is the best practice for handling voice traffic with dynamic segmentation on AOS-CX switches?

Options:

A.

Switch authentication and local forwarding of the voice traffic

B.

Switch authentication and user-based tunneling of the voice traffic.

C.

Central authentication and port-based tunneling of the voice traffic.

D.

Controller authentication and port-based tunneling of all traffic

Question 21

You are are doing tests in your lab and with the following equipment specifications:

• AP1 has a radio that generates a 16 dBm signal.

• AP2 has a radio that generates a 13 dBm signal.

• AP1 has an antenna with a gain of 8 dBi.

• AP2 has an antenna with a gain of 12 dBi. The antenna cable for AP1 has a 4 dB loss. The antenna cable for AP2 has a 3 dB loss.

What would be the calculated Equivalent Isotropic Radiated Power (EIRP) for AP1?

Options:

A.

-9 dBm

B.

20 dBm

C.

40 dBm

D.

15 dBm

Question 22

Match the appropriate QoS concept with its definition. (Options may be used more than once or not at all.)

Question # 22

Options:

Question 23

Match the topics of an AOS10 Tunneled mode setup between an AP and a Gateway. (Options may be used more than once or not at all.)

Question # 23

Options:

Question 24

Your Aruba CX 6300 VSF stack has OSPF adjacency over SVI 10 with LAG 1 to a neighboring device The following configuration was created on the switch:

Question # 24

A)

Question # 24

B)

Question # 24

C)

Question # 24

D)

Question # 24

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 25

A customer is concerned about me unprotected traffic between an AOS-CX switch and a gateway, running on AOStO. What is a feasible option to protect this traffic?

Options:

A.

Implement an IPSec tunnel to protect PAPI between the AOS-CX switches and the gateway

B.

Implement an MD5 HMAC function lo protect PAPI between the AOS-CX switches and the gateway

C.

Implement a GRE tunnel to protect PAPI between the AOS-CX switches and the gateway

D.

no action is needed, an RSA certificate already encrypts the traffic

Question 26

With the Aruba CX 6100 48G switch with uplinks of 1/1/47 and 1/1/48. how do you automate the process of resuming the port operational state once a loop on a client port is cleared?

Options:

A.

Configure int 1/1/1-1/1/52 loop-protect disable timer.

B.

Configure global loop-protect disable timer.

C.

Configure int 1/1/1-1/1/46 loop-protect re-enable-timer.

D.

Configure global loop-protect re-enable-timer.

Question 27

your customer has asked you to assign a switch management role for a new user The customer requires the user role to View switch configuration information and have access to the PUT and POST meth0ds for REST API.

Which default AOS-CX user role meets these requirements?

Options:

A.

administrators

B.

auditors

C.

sysops

D.

helpdesk

Question 28

Your customer currently has Iwo (2) 5406 modular switches with MSTP configured as their core switches. You are proposing a new solution. What would you explain regarding the Aruba CX VSX switch pair when the Primary VSX node is replaced and the system MAC is replaced?

Options:

A.

VSX will select the MAC address from a node that is the lower ID.

B.

Configure vMAC on the Primary VSX node under VSX to retain MAC after hardware replacement.

C.

VSX will select the MAC address from a node that is a higher ID.

D.

During the initial VSX configuration, the system-mac is assigned with a fixed MAC based on VSX ID.

Question 29

You are doing tests in your lab and with the following equipment specifications

• AP1 has a radio that generates a 10 dBm signal

• AP2 has a radio that generates a 11 dBm signal

• AP1 has an antenna with a gain of 9 dBi

• AP2 has an antenna with a gain of 12 dBi.

• The antenna cable for AP1 has a 2 dB loss

• The antenna cable for AP2 has a 3 dB loss

What would be the calculated Equivalent Isotropic Radiated Power (EIRP) for APT?

Options:

A.

26 dBm

B.

30 dBm

C.

17 dBm

D.

-12 dBm

Question 30

With the Aruba CX 6200 24G switch with uplinks or 1/1/25 and 1/1/26, how do you protect client ports from forming layer-2 loops?

Options:

A.

int 1/1/1-1/1/24, loop-protect

B.

int 1/1/1-1/1/28. loop-protect

C.

int 1/1/1-1/1/28. loop-guard

D.

int 1/1/1-1/1/24. loop-guard

Question 31

You are helping an onsite network technician bring up an Aruba 9004 gateway with ZTP for a branch office The technician was to plug in any port for the ZTP process to start Thirty minutes after the gateway was plugged in new users started to complain they were no longer able to get to the internet. One user who reported the issue stated their IP address is 172.16 0.81 However, the branch office network is supposed to be on 10.231 81.0/24.

What should the technician do to alleviate the issue and get the ZTP process started correctly?

Options:

A.

Turn off the DHCP scope on the gateway, and set DNS correctly on the gateway to reach Aruba Activate

B.

Move the cable on the gateway from port G0/0V1 tc port G0 0.0

C.

Move the cable on the gateway to G0/0/1. and add the device's MAC and Serial number in Central

D.

Factory default and reboot the gateway to restart the process.

Question 32

Describe the difference between Class of Service (CoS) and Differentiated Services Code Point (DSCP).

Options:

A.

CoS has much finer granularity than DSCP

B.

CoS is only contained in VLAN Tag fields DSCP is in the IP Header and preserved throughout the IP packet flow

C.

They are similar and can be used interchangeably.

D.

CoS is only used to determine CLASS of traffic DSCP is only used to differentiate between different Classes.

Question 33

A network administrator is attempting to troubleshoot a connectivity issue between a group of users and a particular server The administrator needs to examine the packets over a period of time from their desktop; however, the administrator is not directly connected to the AOS-CX switch involved with the traffic flow.

What statements are correct regarding the ERSPAN session that needs to be established on an AOS-CX switch'? (Select two )

Options:

A.

On the source AOS-CX switch, the destination specified is the switch to which the administrator's desktop is connected

B.

The encapsulation protocol used is GRE.

C.

The encapsulation protocol used is VXLAN.

D.

The encapsulation protocol is UDP.

E.

On the source AOS-CX switch, the destination specified is the administrators desktop

Question 34

What is one advantage of using OCSP vs CRLs for certificate validation?

Options:

A.

reduces latency between the time a certificate is revoked and validation reflects this status

B.

less complex to implement

C.

higher availability for certificate validation

D.

supports longer certificate validity periods

Question 35

List the WPA 4-Way Handshake functions in the correct order.

Question # 35

Options:

Page: 1 / 12
Total 119 questions