Practice Free HPE7-A10 Exam Online Questions
Your company has an HPE Aruba Networking infrastructure, including a variety of HPE Aruba Networking APs and gateways. The company has recently added HPE Aruba Networking SSE. The company needs to improve security for branch users behind an HPE Aruba Networking SD-WAN gateway.
You need to control users’ actions on various SaaS applications.
What is part of the setup?
- A . Enable gateway IDS/IPS on the gateway’s group in HPE Aruba Networking Central
- B . Configure an HPE Aruba Networking Central API token on HPE Aruba Networking SSE
- C . Use HPE Aruba Networking Central to establish an IPsec tunnel between the gateway and HPE Aruba Networking SSE
- D . Configure IPsec crypto maps on HPE Aruba Networking SSE
A customer has two AOS-10 HPE Aruba Networking gateways at a site .
The gateways are part of an SD-Branch solution, managed by HPE Aruba Networking Central, and they use WLAN mode (NON-default gateway mode) for their cluster setting. You are setting up a manual HPE Aruba Networking gateway cluster for dynamic authorization.
The gateways have these IP addresses on a subnet accessible by CPPM:
• Gateway 1 = 10.56.20.2
• Gateway 2 = 10.56.20.3
Which are valid choices for the VRRP IP addresses on the gateways. (Assume that all these options for IP addresses are available.)
- A . Gateway 1 = 10.56.20.4 and Gateway 2 = 10.56.20.4
- B . Gateway 1 = 10.56.20.4 and Gateway 2 = 10.56.20.5
- C . Gateway 1 = 10.56.20.3 and Gateway 2 = 10.56.20.3
- D . Gateway 1 = 10.56.20.2 and Gateway 2 = 10.56.20.2
A customer has an AOS-10 architecture that is managed by HPE Aruba Networking Central. HPE Aruba Networking infrastructure devices authenticate clients to an HPE Aruba Networking ClearPass cluster.
In HPE Aruba Networking Central, you are examining network traffic flows on a wireless IoT device that is categorized as "Raspberry Pi" clients. You see SSH traffic. You then check several more wireless IoT clients and see that they are sending SSH also. Refer to the scenario.
You are helping the customer assess ways to mitigate the potential threat you have detected. You have identified one possible option: Adding a rule to the clients’ AOS user role that matches SSH traffic and applies denylisting.
What is one benefit of this option?
- A . It denies the SSH traffic while still allowing the clients to transmit and receive other traffic.
- B . It allows you to leave a degree of access open to blocked clients so that IT admins can remediate them remotely.
- C . It temporarily blocks all traffic from the client. But remediated clients can easily connect again as long as they no longer send SSH traffic.
- D . If allows you direct to clients to a server for scanning and remediation.
