HP HPE6-A07 Exam Practice Questions (P. 3)
- Full Access (40 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #11
Which most accurately describes the First Applicable rule evaluation algorithm in Enforcement Policies?
- AEach rule is checked and once a match is found, the Enforcement profile assigned to that rule is applied and the rule matching stops.Most Voted
- BAll rules are checked and if there is no match, no Enforcement profile is applied.
- CEach rule is checked and once a match is found, the Enforcement profile assigned to that rule is applied. along with the default Enforcement profile.
- DAll rules are checked for any matching rules and their respective Enforcement profiles are applied.
Correct Answer:
D
D
send
light_mode
delete
Question #12
What is the purpose of using a role mapping policy in an 802.1x service with Active Directory as the authentication source?
- Ato translate and combine AD attributes into ClearPass rolesMost Voted
- Bto send roles from ClearPass to the AD user to update a user’s group membership
- Cto enable attributes as roles directly without needing role mapping rules
- Dto send Aruba firewall roles back to the Aruba Network Access Device
- Eto send details of a user’s connection to the AD user to store in its database
Correct Answer:
B
B
send
light_mode
delete
Question #13
What is the purpose of a guest self-registration page in ClearPass?
- Ato allow employees to get their own devices securely connected to the network
- Bto allow contractors to create their own accounts in Active Directory
- Cto allow employees’ sponsors to create accounts for their guests
- Dto allow employees to easily get their corporate devices on the network
- Eto allow guest users to create a login account for the web login pageMost Voted
Correct Answer:
B
Explanation -
Guest self-registration allows an administrator to customize the process for guests to create their own visitor accounts. Self-registration is also referred to as self- provisioned access
Reference -
http://www.arubanetworks.com/techdocs/ClearPass/6.6/Guest/Content/Configuration/CustomizingSelfProvisionedAccess.htm
B
Explanation -
Guest self-registration allows an administrator to customize the process for guests to create their own visitor accounts. Self-registration is also referred to as self- provisioned access
Reference -
http://www.arubanetworks.com/techdocs/ClearPass/6.6/Guest/Content/Configuration/CustomizingSelfProvisionedAccess.htm
send
light_mode
delete
Question #14
What is the purpose of the pre-auth check during guest authentication?
- Afor the NAD device to do an internal authentication check before sending the credentials to ClearPass
- Bfor the NAD device to check that ClearPass is active before sending it the RADIUS request
- Cfor ClearPass to do an internal authentication check before the NAS login happens
- Dfor the client device to do an internal sanity check before the NAS login occurs
- Efor the client device to check that ClearPass is active before sending it the credentials
Correct Answer:
C
Explanation -
The way NAS devices like wireless controllers do authentication on external captive portals only allows standard reject message handling like "authentication failed". The pre auth check allows CPPM to provide advanced error handling of a reject like "your time limit has been reached" before a user logs in. It is to do an end run around limited error handing of NAS devices on external captive portals.
Reference -
https://community.arubanetworks.com/t5/Security/why-use-pre-auth-check/m-p/93254
C
Explanation -
The way NAS devices like wireless controllers do authentication on external captive portals only allows standard reject message handling like "authentication failed". The pre auth check allows CPPM to provide advanced error handling of a reject like "your time limit has been reached" before a user logs in. It is to do an end run around limited error handing of NAS devices on external captive portals.
Reference -
https://community.arubanetworks.com/t5/Security/why-use-pre-auth-check/m-p/93254
send
light_mode
delete
Question #15
Where is the web login page created in the ClearPass UI?
- AWebAuth Service
- BCaptive Portal Profile
- CClearPass Policy Manager
- DGuest Login Service
- EClearPass Guest
Correct Answer:
E
E
send
light_mode
delete
All Pages