HP HPE6-A15 Exam Practice Questions (P. 5)
- Full Access (105 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #21
A hotel chain deployed ClearPass Guest. When hotel guests connect to the Guest SSID, launch a web browser and enter the address www.google.com, they are unable to immediately see the web login page.
What are the likely causes of this? (Select two.)
What are the likely causes of this? (Select two.)
- AThe ClearPass server has a trusted server certificate issued by Verisign.
- BThe ClearPass server has an untrusted server certificate issued by the internal Microsoft Certificate server.
- CThe ClearPass server does not recognize the client’s certificate.
- DThe DNS server is not replying with an IP address for www.google.com.
Correct Answer:
BD
You would need a publicly signed certificate.
References: http://community.arubanetworks.com/t5/Security/Clearpass-Guest-certificate-error-for-guest-visitors/td-p/221992
BD
You would need a publicly signed certificate.
References: http://community.arubanetworks.com/t5/Security/Clearpass-Guest-certificate-error-for-guest-visitors/td-p/221992
send
light_mode
delete
Question #22
Refer to the exhibit.

An Enforcement Profile has been created in the Policy Manager as shown.
Which action will ClearPass take based on the Enforcement Profile?

An Enforcement Profile has been created in the Policy Manager as shown.
Which action will ClearPass take based on the Enforcement Profile?
- Ait will count down 600 seconds and send a RADIUS CoA message to the NAD to end the user’s session after this time is up
- Bit will send the Session-Timeout attribute in the RADIUS Access-Request packet to the NAD and the NAD will end the user’s session after 600 seconds
- Cit will count down 600 seconds and send a RADIUS CoA message to the user to end the user’s session after this time is up
- Dit will send the Session-Timeout attribute in the RADIUS Access-Request packet to the user and the user’s session will be terminated after 600 seconds
Correct Answer:
D
Session Timeout (in seconds) - Configure the agent session timeout interval to re-evaluate the system health again. OnGuard triggers auto-remediation using this value to enable or disable AV-RTP status check on endpoint. Agent re-authentication is determined based on session-time out value. You can specify the session timeout interval from 60 600 seconds. Setting the lower value for session timeout interval results numerous authentication requests in Access Tracker page. The default value is 0.
References: http://www.arubanetworks.com/techdocs/ClearPass/Aruba_CPPMOnlineHelp/Content/CPPM_UserGuide/Enforce/EPAgent_Enforcement.htm
D
Session Timeout (in seconds) - Configure the agent session timeout interval to re-evaluate the system health again. OnGuard triggers auto-remediation using this value to enable or disable AV-RTP status check on endpoint. Agent re-authentication is determined based on session-time out value. You can specify the session timeout interval from 60 600 seconds. Setting the lower value for session timeout interval results numerous authentication requests in Access Tracker page. The default value is 0.
References: http://www.arubanetworks.com/techdocs/ClearPass/Aruba_CPPMOnlineHelp/Content/CPPM_UserGuide/Enforce/EPAgent_Enforcement.htm
send
light_mode
delete
Question #23
Refer to the exhibit.

Based on the information shown, what is the purpose of using [Time Source] for authorization?

Based on the information shown, what is the purpose of using [Time Source] for authorization?
- Ato check whether the MAC address status is unknown in the endpoints table
- Bto check whether the MAC address is in the MAC Caching repository
- Cto check how long it has been since the last web login authentication
- Dto check whether the MAC address status is known in the endpoint table.
Correct Answer:
D
D
send
light_mode
delete
Question #24
A customer with an Aruba Controller wants it to work with ClearPass Guest.
How should the customer configure ClearPass as an authentication server in the controller so that guests are able to authenticate successfully?
How should the customer configure ClearPass as an authentication server in the controller so that guests are able to authenticate successfully?
- AAdd ClearPass as a RADIUS CoA server.
- BAdd ClearPass as a RADIUS authentication server.
- CAdd ClearPass as a TACACS+ authentication server.
- DAdd ClearPass as an HTTPS authentication server.
Correct Answer:
B
5. Configuring the Aruba Controller
5.1 Add Clearpass as RADIUS Server
Navigate to Configuration > SECURITY > Authentication > Servers
Click on RADIUS Server and enter the Name of your Clearpass Server: myClearpass
Click Add -
Click on myClearpass in the Server List
Etc.
References: https://community.arubanetworks.com/t5/Security/Step-by-Step-Controller-CPPM-6-5-Captive-Portal-authentication/td-p/229740
B
5. Configuring the Aruba Controller
5.1 Add Clearpass as RADIUS Server
Navigate to Configuration > SECURITY > Authentication > Servers
Click on RADIUS Server and enter the Name of your Clearpass Server: myClearpass
Click Add -
Click on myClearpass in the Server List
Etc.
References: https://community.arubanetworks.com/t5/Security/Step-by-Step-Controller-CPPM-6-5-Captive-Portal-authentication/td-p/229740
send
light_mode
delete
Question #25
Refer to the exhibit.

Based on the Enforcement Policy configuration shown, when a user with Role Remote Worker connects to the network and the posture token assigned is quarantine, which Enforcement Profile will be applied?

Based on the Enforcement Policy configuration shown, when a user with Role Remote Worker connects to the network and the posture token assigned is quarantine, which Enforcement Profile will be applied?
- ARestrictedACL
- BRemote Employee ACL
- C[Deny Access Profile]
- DEMPLOYEE_VLAN
- EHR VLAN
Correct Answer:
B
The first rule will match, and the Remote Employee ACL will be used.
B
The first rule will match, and the Remote Employee ACL will be used.
send
light_mode
delete
All Pages