Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free HP HPE6-A78 Practice Exam with Questions & Answers

Questions 1

You are configuring ArubaOS-CX switches to tunnel client traffic to an Aruba Mobility Controller (MC). What should you do to enhance security for control channel communications between the switches and the MC?

Options:
A.

Create one UBT zone for control traffic and a second UBT zone for clients.

B.

Configure a long, random PAPI security key that matches on the switches and the MC.

C.

install certificates on the switches, and make sure that CPsec is enabled on the MC

D.

Make sure that the UBT client vlan is assigned to the interface on which the switches reach the MC and only that interface.

HP HPE6-A78 Premium Access
Questions 2

What is one of the roles of the network access server (NAS) in the AAA framework?

Options:
A.

It negotiates with each user’s device to determine which EAP method is used for authentication.

B.

It determines which resources authenticated users are allowed to access and monitors each user’s session.

C.

It enforces access to network services and sends accounting information to the AAA server.

D.

It authenticates legitimate users and uses policies to determine which resources each user is allowed to access.

Questions 3

Which scenario requires the Aruba Mobility Controller to use a Server Certificate?

Options:
A.

Obtain downloadable user roles (DURs) from ClearPass.

B.

Synchronize its clock with an NTP server that requires authentication.

C.

Use RadSec for enforcing 802.1X authentication to ClearPass.

D.

Use RADIUS for enforcing 802.1X authentication to ClearPass.

Questions 4

What is a reason to set up a packet capture on an HPE Aruba Networking Mobility Controller (MC)?

Options:
A.

The security team believes that a wireless endpoint connected to the MC is launching an attack and wants to examine the traffic more closely.

B.

The company wants to use HPE Aruba Networking ClearPass Policy Manager (CPPM) to profile devices and needs to receive HTTP User-Agent strings from the MC.

C.

You want the MC to analyze wireless clients' traffic at a lower level, so that the AOS firewall can control Web traffic based on the destination URL.

D.

You want the MC to analyze wireless clients' traffic at a lower level, so that the AOS firewall can control the traffic based on application.

Questions 5

What is an Authorized client, as defined by AOS Wireless Intrusion Prevention System (WIP)?

Options:
A.

A client that is on the WIP whitelist

B.

A client that has a certificate issued by a trusted Certification Authority (CA)

C.

A client that is NOT on the WIP blacklist

D.

A client that has successfully authenticated to an authorized AP and passed encrypted traffic

Questions 6

What is a guideline for deploying Aruba ClearPass Device Insight?

Options:
A.

Deploy a Device Insight Collector at every site in the corporate WAN to reduce the impact on WAN links.

B.

Make sure that Aruba devices trust the root CA certificate for the ClearPass Device Insight Analyzer's HTTPS certificate.

C.

Configure remote mirroring on access layer Aruba switches, using Device Insight Analyzer as the destination IP.

D.

For companies with multiple sites, deploy a pair of Device Insight Collectors at the HQ or the central data center.

Questions 7

How should admins deal with vulnerabilities that they find in their systems?

Options:
A.

They should apply fixes, such as patches, to close the vulnerability before a hacker exploits it.

B.

They should add the vulnerability to their Common Vulnerabilities and Exposures (CVE).

C.

They should classify the vulnerability as malware. a DoS attack or a phishing attack.

D.

They should notify the security team as soon as possible that the network has already been breached.

Questions 8

What correctly describes the Pairwise Master Key (PMK) in thee specified wireless security protocol?

Options:
A.

In WPA3-Enterprise, the PMK is unique per session and derived using Simultaneous Authentication of Equals.

B.

In WPA3-Personal, the PMK is unique per session and derived using Simultaneous Authentication of Equals.

C.

In WPA3-Personal, the PMK is derived directly from the passphrase and is the same tor every session.

D.

In WPA3-Personal, the PMK is the same for each session and is communicated to clients that authenticate

Questions 9

How does the AOS firewall determine which rules to apply to a specific client's traffic?

Options:
A.

The firewall applies the rules in policies associated with the client's user role.

B.

The firewall applies every rule that includes the client's IP address as the source.

C.

The firewall applies the rules in policies associated with the client's WLAN.

D.

The firewall applies every rule that includes the client's IP address as the source or destination.

Questions 10

You are deploying a new wireless solution with an Aruba Mobility Master (MM). Aruba Mobility Controllers (MCs), and campus APs (CAPs). The solution will include a WLAN that uses Tunnel for the forwarding mode and WPA3-Enterprise for the security option.

You have decided to assign the WLAN to VLAN 301, a new VLAN. A pair of core routing switches will act as the default router for wireless user traffic.

Which links need to carry VLAN 301?

Options:
A.

only links in the campus LAN to ensure seamless roaming

B.

only links between MC ports and the core routing switches

C.

only links on the path between APs and the core routing switches

D.

only links on the path between APs and the MC