Practice Free HPE7-A10 Exam Online Questions
A customer has an AOS-10 architecture that is managed by HPE Aruba Networking Central. HPE Aruba Networking infrastructure devices authenticate clients to an HPE Aruba Networking ClearPass cluster.
In HPE Aruba Networking Central, you are examining network traffic flows on a wireless IoT device that is categorized as "Raspberry Pi" clients. You see SSH traffic. You then check several more wireless IoT clients and see that they are sending SSH also. Refer to the scenario.
What possible issue is indicated?
- A . A hacker might have inserted a rogue network device between these clients and the authorized router, creating a man-in-the-middle attack.
- B . The clients are likely responding to port scanning requests by a hacker attempting to conduct network reconnaissance.
- C . Network admins are not using proper management protocols when accessing user devices.
- D . These clients might be controlled by hackers through reverse SSH tunnels.
An organization wants the AOS-CX switch to trigger an alert if its RADIUS server (cp.acnsxtest.local) rejects an unusual number of client authentication requests per hour. After some discussions with other HPE Aruba Networking admins, you are still not sure how many rejections are usual or unusual. You expect that the value could be different on each switch. You are helping the developer understand how to develop an NAE script for this use case.
Refer to the scenario.
You are helping a customer define an NAE script for AOS-CX switches. The script will monitor statistics from a RADIUS server defined on the switch. You want to future proof the script by enabling admins to select a different hostname or IP address for the monitored RADIUS server when they create an agent from the script.
What should you recommend?
- A . Use this variable, %{radius-ip}, when defining the monitor URI in the NAE agent script.
- B . Define a parameter for the RADIUS server; reference that parameter instead of the server name/ip when defining the monitor URI.
- C . Make the script editable so that admins can edit it on demand when they are creating scripts.
- D . Use a callback action to collect the name of any RADIUS servers defined on the switch at the time the agent is created.
A customer’s admins have added RF Protect licenses and enabled WIDS for a customer’s AOS-8-based solution. The customer wants to use the built-in capabilities of APs without deploying dedicated air monitors (AMs). Admins tested rogue AP detection by connecting a unauthorized wireless AP to a switch. The rogue AP was not detected even after several hours.
What is one point about which you should ask?
- A . Whether admins enabled wireless containment
- B . Whether the customer is using non-standard Wi-Fi channels in the deployment
- C . Whether admins set at least one radio on each AP to air monitor mode
- D . Whether APs’ switch ports support all the VLANs that are accessible at the edge
A customer has an AOS-10 architecture, which includes HPE Aruba Networking APs. The customer recently enabled WIDS at the high level on the APs. Admins see a lot of "detect disconnect station" events.
What should you explain?
- A . The WIDS solution is likely malfunctioning, causing APs to disassociate each other’s clients. You will check the configuration immediately.
- B . A hacker is likely targeting the customer s network for a DoS attack. You will locate the source MAC address associated with the event and remove the device.
- C . The WLAN is likely misconfigured with legacy security settings. You will check the WLAN configuration immediately.
- D . Client drivers and interference can cause false positives of this event. You will look out for other stronger signs of attack such as rogue APs and disassociation broadcasts.
# Introduction to the customer
You are helping a company add HPE Aruba Networking ClearPass to their network, which uses HPE Aruba Networking network infrastructure devices.
The company currently has a Windows domain and Windows CA. The Window CA issues certificates to domain computers, domain users, and servers such as domain controllers. An example of a certificate issued by the Windows CA is shown here.


# ClearPass cluster IP addressing and hostnames
A customer’s ClearPass cluster has these IP addresses:
• Publisher = 10.47.47.5
• Subscriber 1 = 10.47.47.6
• Subscriber 2 = 10.47.47.7
• Virtual IP with Subscriber 1 and Subscriber 2 = 10.47.47.8 The customer’s DNS server has these entries
• cp.acnsxtest.com = 10.47.47.5
• cps1.acnsxtest.com = 10.47.47.6
• cps2.acnsxtest.com = 10.47.47.7
• radius.acnsxtest.com = 10.47.47.8
• onboard.acnsxtest.com = 10.47.47.8
Refer to the scenario.
You need to configure HPE Aruba Networking ClearPass Onboard to issue client certificates for Azure AD joined devices.
Which step is required to achieve this objective?
- A . Create an HTTP authentication source that references an Intune extension.
- B . Recreate the CA as a registration authority under Azure AD.
- C . Create a CPPM policy that authenticates guest users to Azure AD.
- D . Install the Intune SCEP extension on the ClearPass subscribers.
A customer has an AOS-10 architecture that is managed by HPE Aruba Networking Central. HPE Aruba Networking infrastructure devices authenticate clients to an HPE Aruba Networking ClearPass cluster.
In HPE Aruba Networking Central, you are examining network traffic flows on a wireless IoT device that is categorized as "Raspberry Pi" clients. You see SSH traffic. You then check several more wireless IoT clients and see that they are sending SSH also. Refer to the scenario.
You are helping the customer assess ways to mitigate the potential threat you have detected. The customer recommends simply adding a rule that denies SSH traffic to the IoT client’s AOS user role.
What is the security drawback of this option?
- A . It does not prevent the likely compromised clients from taking other harmful actions.
- B . It only applies to Layer 3 traffic, so it will not reliably prevent a man-in-the-middle attack.
- C . It penalizes the wireless IoT client instead of the ultimate source of the threat.
- D . It only prevents SSH traffic initiated from IoT clients, not initiated by a device on the other side of the firewall.
# Introduction to the customer
You are helping a company add HPE Aruba Networking ClearPass to their network, which uses HPE Aruba Networking network infrastructure devices.
The company currently has a Windows domain and Windows CA. The Window CA issues certificates to domain computers, domain users, and servers such as domain controllers. An example of a certificate issued by the Windows CA is shown here.


# ClearPass cluster IP addressing and hostnames
A customer’s ClearPass cluster has these IP addresses:
• Publisher = 10.47.47.5
• Subscriber 1 = 10.47.47.6
• Subscriber 2 = 10.47.47.7
• Virtual IP with Subscriber 1 and Subscriber 2 = 10.47.47.8 The customer’s DNS server has these entries
• cp.acnsxtest.com = 10.47.47.5
• cps1.acnsxtest.com = 10.47.47.6
• cps2.acnsxtest.com = 10.47.47.7
• radius.acnsxtest.com = 10.47.47.8
• onboard.acnsxtest.com = 10.47.47.8
Refer to the scenario.
You have started to create a CA to meet the customer’s requirements for issuing certificates to mobile clients, as shown in the exhibit below.


What change will help to meet those requirements and the requirements for authenticating clients?
- A . Change the EST authentication method to use an external validator.
- B . Change the EST Digest Algorithm to SHA-512.
- C . Recreate the CA as a registration authority under Microsoft Entra ID (Azure AD).
- D . Specify an OCSP responder, setting the hostname to localhost.
What benefit does an organization gain from upgrading wireless security from WPA2-Personal to WPA3-Personal?
- A . Users access the wireless network with individual credentials, making it easier to revoke access.
- B . Users access the wireless network with individual credentials, enabling role-based access controls.
- C . The passphrase used to protect wireless access is more resistant to being cracked.
- D . The passphrase used to protect wireless access is more resistant to being leaked by users.
Your company has an HPE Aruba Networking AOS-10 architecture managed by HPE Aruba Networking Central. A ClearPass Policy Manager (CPPM) cluster provides authentication. The company also has a Palo Alto firewall. You want to set up the HPE Aruba Networking infrastructure to quarantine clients about which the firewall sends Syslog Threat messages to CPPM. Network infrastructure devices already have a “quarantine” role configured on them.
You have checked the CPPM’s event dictionary and found an entry for Palo Alto Syslog Threats that includes:
• Prefix: PANW-Threat
• Attributes such as syslog timestamp and log type
What is a correct part of the configuration on ClearPass server settings?
- A . Insight server enabled
- B . CA that signed the firewall’s certificate installed as trusted
- C . Syslog scanning configured
- D . CoA delay of 5 seconds or greater
A customer has HPE Aruba Networking mobility devices and AOS-CX switches, which implement RADIUS authentication and accounting to HPE Aruba Networking ClearPass Policy Manager (CPPM). The customer uses accounting data for auditing and has noticed that accounting records for clients connected to access switches are missing IP address information.
Which step could you take to fill in this information?
- A . Install an AOS-CX accounting extension through ClearPass Guest.
- B . Enable ARP inspection on the clients’ VLAN on the switches.
- C . Set up a RADIUS accounting proxy to a supported third-party device on CPPM.
- D . Enable DHCP snooping on the clients’ VLANs on the switches.
