Practice Free HPE7-A02 Exam Online Questions
You have set up a mirroring session between an AOS-CX switch and a management station, running Wireshark. You want to capture just the traffic sent in the mirroring session, not the management station’s other traffic.
What should you do?
- A . Apply this capture filter: ip proto 47
- B . Edit protocol preferences and enable ARUBA_ERM.
- C . Edit protocol preferences and enable HPE_ERM.
- D . Apply this capture filter: udp port 5555
You have set up a mirroring session between an AOS-CX switch and a management station, running Wireshark. You want to capture just the traffic sent in the mirroring session, not the management station’s other traffic.
What should you do?
- A . Apply this capture filter: ip proto 47
- B . Edit protocol preferences and enable ARUBA_ERM.
- C . Edit protocol preferences and enable HPE_ERM.
- D . Apply this capture filter: udp port 5555
A company wants to use HPE Aruba Networking ClearPass Onboard to issue certificates to BYOD devices. These certificates should be valid only for authenticating the company’s ClearPass cluster.
What type of Onboard CA should you set up?
- A . Intermediate CA with EST disabled
- B . Intermediate CA with EST enabled
- C . Root CA
- D . Registration authority
A company uses HPE Aruba Networking ClearPass Policy Manager (CPPM) as a TACACS+ server to authenticate managers on its AOS-CX switches. You want to assign managers to groups on the AOS-CX switch by name.
How do you configure this setting in a CPPM TACACS+ enforcement profile?
- A . Add the Shell service and set autocmd to the group name.
- B . Add the Shell service and set priv-Ivl to the group name.
- C . Add the Aruba: Common service and set Aruba-Admin-Role to the group name.
- D . Add the Aruba: Common service and set Aruba-Priv-Admin-User to the group name.
A company uses HPE Aruba Networking ClearPass Policy Manager (CPPM) as a TACACS+ server to authenticate managers on its AOS-CX switches. You want to assign managers to groups on the AOS-CX switch by name.
How do you configure this setting in a CPPM TACACS+ enforcement profile?
- A . Add the Shell service and set autocmd to the group name.
- B . Add the Shell service and set priv-Ivl to the group name.
- C . Add the Aruba: Common service and set Aruba-Admin-Role to the group name.
- D . Add the Aruba: Common service and set Aruba-Priv-Admin-User to the group name.
A company uses HPE Aruba Networking ClearPass Policy Manager (CPPM) as a TACACS+ server to authenticate managers on its AOS-CX switches. You want to assign managers to groups on the AOS-CX switch by name.
How do you configure this setting in a CPPM TACACS+ enforcement profile?
- A . Add the Shell service and set autocmd to the group name.
- B . Add the Shell service and set priv-Ivl to the group name.
- C . Add the Aruba: Common service and set Aruba-Admin-Role to the group name.
- D . Add the Aruba: Common service and set Aruba-Priv-Admin-User to the group name.
A company uses HPE Aruba Networking ClearPass Policy Manager (CPPM) as a TACACS+ server to authenticate managers on its AOS-CX switches. You want to assign managers to groups on the AOS-CX switch by name.
How do you configure this setting in a CPPM TACACS+ enforcement profile?
- A . Add the Shell service and set autocmd to the group name.
- B . Add the Shell service and set priv-Ivl to the group name.
- C . Add the Aruba: Common service and set Aruba-Admin-Role to the group name.
- D . Add the Aruba: Common service and set Aruba-Priv-Admin-User to the group name.
What is one use case for implementing user-based tunneling (UBT) on AOS-CX switches?
- A . Centralizing the distribution of wired traffic without requiring HPE Aruba Networking gateways
- B . Tunneling traffic directly to a third-party firewall in a client data center
- C . Adding 802.1X while continuing to use the existing VLAN and ACL structure in the Ethernet network
- D . Applying enhanced security features such as deep packet inspection (DPI) to wired traffic
What is one use case for implementing user-based tunneling (UBT) on AOS-CX switches?
- A . Centralizing the distribution of wired traffic without requiring HPE Aruba Networking gateways
- B . Tunneling traffic directly to a third-party firewall in a client data center
- C . Adding 802.1X while continuing to use the existing VLAN and ACL structure in the Ethernet network
- D . Applying enhanced security features such as deep packet inspection (DPI) to wired traffic
Your company wants to implement Tunneled EAP (TEAP).
How can you set up HPE Aruba Networking ClearPass Policy Manager (CPPM) to enforce certificated-based authentication for clients using TEAP?
- A . For the service using TEAP, set the authentication source to an internal database.
- B . Select a service certificate when you specify TEAP as a service’s authentication method.
- C . Create an authentication method named "TEAP" with the type set to EAP-TLS.
- D . Select an EAP-TLS-type authentication method for the TEAP method’s inner method.
