Practice Free HPE7-A10 Exam Online Questions
You are configuring gateway IDS/IPS settings in HPE Aruba Networking Central.
For which reason would you set the Fail Strategy to Bypass?
- A . To tell gateways to stop enforcing IDS/IPS policies if they lose connectivity to the Internet
- B . To enable the gateway to honor the allowlist settings configured in IDS/IPS policies
- C . To permit traffic if the IPS engine fails to inspect it
- D . To avoid wasting IPS engine resources on filtering traffic for unauthenticated clients
Refer to the exhibit.

HPE Aruba Networking ClearPass Policy Manager (CPPM) is using the settings shown in the exhibit. You reference the tag shown in the exhibit in enforcement policies related to NASes of several types, including HPE Aruba Networking APs, HPE Aruba Networking gateways, and AOS-CX switches.
What should you do to ensure that clients are reclassified and receive the correct treatment based on the tag?
- A . Set the Tags Update Action to No Action. Then instead enable the RADIUS CoAs using enforcement profiles in the rules that match clients with the tag shown in the exhibit.
- B . Change the RADIUS action to [Aruba Wireless – Bounce Switch Port] which is supported by all the NASes in question.
- C . Enable profiling in each service using one of these enforcement profiles. Set the profiling action to the correct one for the NASes using that service.
- D . Change the RADIUS action to [Aruba Wireless – Terminate Session] which is supported by all the NASes in question.
A customer has an HPE Aruba Networking ClearPass cluster. The customer has AOS-CX switches that implement 802.1X authentication to HPE Aruba Networking ClearPass Policy Manager (CPPM). Switches are using local port-access policies.
The customer wants to start tunneling wired clients that pass user authentication only to an HPE Aruba Networking gateway cluster. The gateway cluster should assign these clients to the "eth-internet" role. The gateway should also handle assigning clients to their VLAN, which is VLAN 20.
The plan for the enforcement policy and profiles is shown below:


The gateway cluster has two gateways with these IP addresses:
• Gateway 1
o VLAN 4085 (system IP) = 10.20.4.21
o VLAN 20 (users) = 10.20.20.1
o VLAN 4094 (WAN) = 198.51.100.14
• Gateway 2
o VLAN 4085 (system IP) = 10.20.4.22
o VLAN 20 (users) = 10.20.20.2
o VLAN 4094 (WAN) = 198.51.100.12
• VRRP on VLAN 20 = 10.20.20.254
The customer requires high availability for the tunnels between the switches and the gateway cluster. If one gateway fails, the other gateway should take over its tunnels. Also, the switch should be able to discover the gateway cluster regardless of whether one of the gateways is in the cluster.
Refer to the scenario.
What is one change that you should make to the solution?
- A . Remove VLAN assignments from role configurations on the gateways.
- B . Configure edge ports in VLAN trunk mode.
- C . Configure the UBT solution to use VLAN extend mode.
- D . Change the ubt-client-vlan to VLAN 13.
A customer needs you to configure Aruba ClearPass Policy Manager (CPPM) to authenticate domain users on domain computers. Domain users, domain computers, and domain controllers receive certificates from a Windows CA. CPPM should validate these certificates and verify that the users and computers have accounts in Windows AD. The customer requires encryption for all communications between CPPM and the domain controllers.
You have imported the root certificate for the Windows CA to the ClearPass CA Trust list.
Based on these requirements, which usages should you add to it?
- A . Radsec and HPE Aruba Networking infrastructure
- B . EAP and AD/LDAP Server
- C . LDAP and HPE Aruba Networking infrastructure
- D . EAP and Radsec
A customer has an HPE Aruba Networking ClearPass cluster. The customer has AOS-CX switches that implement 802.1X authentication to HPE Aruba Networking ClearPass Policy Manager (CPPM). Switches are using local port-access policies.
The customer wants to start tunneling wired clients that pass user authentication only to an HPE Aruba Networking gateway cluster. The gateway cluster should assign these clients to the "eth-internet" role. The gateway should also handle assigning clients to their VLAN, which is VLAN 20.
The plan for the enforcement policy and profiles is shown below:


The gateway cluster has two gateways with these IP addresses:
• Gateway 1
o VLAN 4085 (system IP) = 10.20.4.21
o VLAN 20 (users) = 10.20.20.1
o VLAN 4094 (WAN) = 198.51.100.14
• Gateway 2
o VLAN 4085 (system IP) = 10.20.4.22
o VLAN 20 (users) = 10.20.20.2
o VLAN 4094 (WAN) = 198.51.100.12
• VRRP on VLAN 20 = 10.20.20.254
The customer requires high availability for the tunnels between the switches and the gateway cluster. If one gateway fails, the other gateway should take over its tunnels. Also, the switch should be able to discover the gateway cluster regardless of whether one of the gateways is in the cluster.
Refer to the scenario.
Assume that you have configured the correct UBT zone and port-access role settings. However, the solution is not working.
What else should you make sure to do?
- A . Assign VLAN 20 as the access VLAN on any edge ports to which tunneled clients might connect.
- B . Assign sufficient VIA licenses to the gateways based on the number of wired clients that will connect.
- C . Create a new VLAN on the AOS-CX switch and configure that VLAN as the UBT client VLAN.
- D . Change the port-access auth-mode mode to client-mode on any edge ports to which tunneled clients might connect.
Your company has HPE Aruba Networking AOS-10 APs and gateways, as well as AOS-CX switches, all managed by HPE Aruba Networking Central. Within HPE Aruba Networking Central, you need to collect a packet capture on a client connected to an AP.
What is a prerequisite?
- A . The AP tunnels the client’s SSID to a gateway with application visibility enabled.
- B . The AP tunnels the client’s SSID to a gateway with DPI enabled.
- C . The AP has one radio configured in monitor mode.
- D . The AP is assigned to an HPE Aruba Networking Central site.
A customer has an AOS-10 architecture that is managed by HPE Aruba Networking Central. HPE Aruba Networking infrastructure devices authenticate clients to an HPE Aruba Networking ClearPass cluster.
In HPE Aruba Networking Central, you are examining network traffic flows on a wireless IoT device that is categorized as "Raspberry Pi" clients. You see SSH traffic. You then check several more wireless IoT clients and see that they are sending SSH also.
Which element helps to lay the foundation for solid network security forensics?
- A . Enabling debug-level information for network infrastructure device logs
- B . Enable BPDU protection and loop protection on edge switch ports
- C . Implementing 802.1X authentication on switch ports that connect to APs
- D . Ensuring that all network devices use a correct, consistent clock
A customer has an AOS-10 architecture that is managed by HPE Aruba Networking Central. HPE Aruba Networking infrastructure devices authenticate clients to an HPE Aruba Networking ClearPass cluster.
In HPE Aruba Networking Central, you are examining network traffic flows on a wireless IoT device that is categorized as "Raspberry Pi" clients. You see SSH traffic. You then check several more wireless IoT clients and see that they are sending SSH also.
Which element helps to lay the foundation for solid network security forensics?
- A . Enabling debug-level information for network infrastructure device logs
- B . Enable BPDU protection and loop protection on edge switch ports
- C . Implementing 802.1X authentication on switch ports that connect to APs
- D . Ensuring that all network devices use a correct, consistent clock
You want to use HPE Aruba Networking ClearPass Device Insight tags as conditions within CPPM role mapping or enforcement policy rules.
What guidelines should you follow?
- A . Create an HTTP authentication source to the HPE Aruba Networking Central API that queries for the tags. To use that source as the type for rule conditions, add it an authorization source for the service in question.
- B . Use the Application type for the rule conditions; no extra authorization source is required for services that use policies with these rules.
- C . Use the Endpoints Repository type for the rule conditions; Add Endpoints Repository as a secondary authentication source for services that use policies with these rules.
- D . Use the Endpoint type for the rule conditions; no extra authorization source is required for services that use policies with these rules.
You are entering this command on an AOS-CX switch: radius-server host clearpass.example.com tls clearpass-username clearpass-password plaintext.
Which credentials do you enter for "clearpass-usemame" and "clearpass-password"?
- A . the credentials for a CPPM admin with HPE Aruba Networking Role Download privileges
- B . the RADIUS secret configured in the corresponding network device entry on CPPM
- C . the username in the certificate that the switch uses for Radsec and the password for the certificate’s private key
- D . the credentials of a user account used for RADIUS server tracking
