Introduction to the customer: You are helping a company add HPE Aruba Networking ClearPass to their network, which uses HPE Aruba Networking network infrastructure devices. The company currently has a Windows domain and Windows CA. The Window CA issues certificates to domain computers, domain users, and servers such as domain controllers. An example of a certificate issued by the Windows CA is shown here.ClearPass cluster IP addressing and hostnames:A customer's ClearPass cluster has these IP addresses: • Publisher = 10.47.47.5 • Subscriber 1 = 10.47.47.6 • Subscriber 2 = 10.47.47.7 • Virtual IP with Subscriber 1 and Subscriber 2 = 10.47.47.8 The customer's DNS server has these entries • cp.acnsxtest.com = 10.47.47.5 • cps1.acnsxtest.com = 10.47.47.6 • cps2.acnsxtest.com = 10.47.47.7 • radius.acnsxtest.com = 10.47.47.8 • onboard.acnsxtest.com = 10.47.47.8 Refer to the scenario. On CPPM, you are creating the authentication source. You have configured the settings shown in the tab and have not altered any other settings.What else do you need to do to help authentication proceed correctly?
Answer(s): C
Introduction to the customer: You are helping a company add HPE Aruba Networking ClearPass to their network, which uses HPE Aruba Networking network infrastructure devices. The company currently has a Windows domain and Windows CA. The Window CA issues certificates to domain computers, domain users, and servers such as domain controllers. An example of a certificate issued by the Windows CA is shown here.ClearPass cluster IP addressing and hostnames:A customer's ClearPass cluster has these IP addresses: • Publisher = 10.47.47.5 • Subscriber 1 = 10.47.47.6 • Subscriber 2 = 10.47.47.7 • Virtual IP with Subscriber 1 and Subscriber 2 = 10.47.47.8 The customer's DNS server has these entries • cp.acnsxtest.com = 10.47.47.5 • cps1.acnsxtest.com = 10.47.47.6 • cps2.acnsxtest.com = 10.47.47.7 • radius.acnsxtest.com = 10.47.47.8 • onboard.acnsxtest.com = 10.47.47.8 Refer to the scenario. A customer has AOS-CX switches with this configuration on their edge ports: port-access onboarding-method concurrent enable aaa authentication port-access mac-auth enable quiet-period 60 aaa authentication port-access dotx1 authenticator enable The switch authenticates clients to HPE Aruba Networking ClearPass Policy Manager (CPPM) which has these services: 1. An 802.1 X service that uses an EAP-TLS method for most clients 2. A MAC-Auth service that uses the [MAC-Auth] method for devices such as printers imported from an inventory manager The customer now wants to provide limited access to wired guest devices and new devices that need to be enrolled with certificates. You have set up these rights in an AOS-CX role named "guest-login." How should you apply the "guest-login" role on the switches?
Answer(s): B
Introduction to the customer: You are helping a company add HPE Aruba Networking ClearPass to their network, which uses HPE Aruba Networking network infrastructure devices. The company currently has a Windows domain and Windows CA. The Window CA issues certificates to domain computers, domain users, and servers such as domain controllers. An example of a certificate issued by the Windows CA is shown here.ClearPass cluster IP addressing and hostnames:A customer's ClearPass cluster has these IP addresses: • Publisher = 10.47.47.5 • Subscriber 1 = 10.47.47.6 • Subscriber 2 = 10.47.47.7 • Virtual IP with Subscriber 1 and Subscriber 2 = 10.47.47.8 The customer's DNS server has these entries • cp.acnsxtest.com = 10.47.47.5 • cps1.acnsxtest.com = 10.47.47.6 • cps2.acnsxtest.com = 10.47.47.7 • radius.acnsxtest.com = 10.47.47.8 • onboard.acnsxtest.com = 10.47.47.8 Refer to the scenario. You need to configure HPE Aruba Networking ClearPass Onboard to issue client certificates for Azure AD joined devices. Which step is required to achieve this objective?
Answer(s): D
Introduction to the customer: You are helping a company add HPE Aruba Networking ClearPass to their network, which uses HPE Aruba Networking network infrastructure devices. The company currently has a Windows domain and Windows CA. The Window CA issues certificates to domain computers, domain users, and servers such as domain controllers. An example of a certificate issued by the Windows CA is shown here.ClearPass cluster IP addressing and hostnames:A customer's ClearPass cluster has these IP addresses: • Publisher = 10.47.47.5 • Subscriber 1 = 10.47.47.6 • Subscriber 2 = 10.47.47.7 • Virtual IP with Subscriber 1 and Subscriber 2 = 10.47.47.8 The customer's DNS server has these entries • cp.acnsxtest.com = 10.47.47.5 • cps1.acnsxtest.com = 10.47.47.6 • cps2.acnsxtest.com = 10.47.47.7 • radius.acnsxtest.com = 10.47.47.8 • onboard.acnsxtest.com = 10.47.47.8 Refer to the scenario. The Onboard CA is using the settings shown in the exhibits below.Microsoft Entra ID (Azure AD) admins need help setting up the app registration for integrating with ClearPass Onboard. Which URL should you tell them to use?
A hospital has an AOS-10 architecture that is managed by HPE Aruba Networking Central. The customer has deployed a pair of HPE Aruba Networking 9000 Series gateways with Security licenses at each clinic. The gateways implement IDS/IPS in IDS mode. The Security Dashboard shows these several recent events with the same signature, as shown below:Refer to the scenario. You have learned that the source of the events is nurse call stations. What can you conclude?
Answer(s): A
A hospital has an AOS-10 architecture that is managed by HPE Aruba Networking Central. The customer has deployed a pair of HPE Aruba Networking 9000 Series gateways with Security licenses at each clinic. The gateways implement IDS/IPS in IDS mode. The Security Dashboard shows these several recent events with the same signature, as shown below:Refer to the scenario. Which step could give you valuable context about the incident?
A hospital has an AOS-10 architecture that is managed by HPE Aruba Networking Central. The customer has deployed a pair of HPE Aruba Networking 9000 Series gateways with Security licenses at each clinic. The gateways implement IDS/IPS in IDS mode. The Security Dashboard shows these several recent events with the same signature, as shown below:Refer to the scenario. You would like a record of the specific traffic that triggered the threat event. What should you do?
When would you implement BPDU protection on an AOS-CX switch port versus BPDU filtering?
Share your comments for HP HPE7-A10 exam with other users:
Question 6:Correct answer: A — Move rule 1 to the bottom of the list. I can’t see the role-mapping exhibit itself, but the key concept is ClearPass role-mapping rule order. Rules are evaluated from top to bottom, and a broad rule placed first can match a certificate before a more specific rule gets a chance to assign the intended role. Typically:
Issuer-CN
Subject-CN
Question 4:Correct answer: D — Specify an OCSP responder and set the hostname to localhost. The question describes creating a ClearPass local CA to issue certificates to mobile clients. Those certificates must also be usable for client authentication, which requires a revocation-checking mechanism.
localhost