Pre-Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free HP HPE7-A02 Practice Exam with Questions & Answers | Set: 4

Questions 31

A company wants HPE Aruba Networking ClearPass Policy Manager (CPPM) to respond to Syslog messages from its Check Point firewall. You have added the

firewall as an event source and set up an event service. However, test Syslog messages are not triggering the expected actions.

What is one CPPM setting that you should check?

Options:
A.

ClearPass Device Insight integration is disabled.

B.

The Check Point Extension is installed through ClearPass Guest.

C.

The CoA delay value is set to 0 on the server.

D.

Ingress Event Dictionaries for Check Point messages are enabled.

HP HPE7-A02 Premium Access
Questions 32

You want to examine the applications that a device is using and look for any changes in application usage over several different ranges. In which HPE Aruba Networking solution can you view this information in an easy-to-view format?

Options:
A.

HPE Aruba Networking ClearPass OnGuard agent installed on the device

B.

HPE Aruba Networking Central within a device ' s Live Monitoring page

C.

HPE Aruba Networking ClearPass Insight using an Active Endpoint Security report

D.

HPE Aruba Networking ClearPass Device Insight (CPDI) in the device ' s network activity

Questions 33

A company wants to turn on Wireless IDS/IPS infrastructure and client detection at the high level on HPE Aruba Networking APs. The company does not want to

enable any prevention settings.

What should you explain about HPE Aruba Networking recommendations?

Options:
A.

HPE Aruba Networking recommends turning on both wired and wireless prevention whenever you enable detection at high.

B.

HPE Aruba Networking recommends using hybrid AP mode, as opposed to Air Monitors (AMs), when implementing detection without prevention.

C.

HPE Aruba Networking recommends disabling client detection when you configure infrastructure detection at high, as infrastructure detection includes all the client checks and more.

D.

HPE Aruba Networking recommends configuring infrastructure and client detection at a custom level and disabling or tuning some of the settings that are likely to produce false positives.

Questions 34

HPE Aruba Networking ClearPass Device Insight (CPDI) could not classify some endpoints using system and user rules. Using machine learning, it did assign those endpoints to a cluster and discover a recommendation. In which of these circumstances does CPDI automatically classify the endpoints based on that recommendation?

Options:
A.

The recommendation has 96% confidence, and it is based on 13 classified devices.

B.

The recommendation has 98% confidence, and it is based on 5 classified devices.

C.

The recommendation has 93% confidence, and it is based on 36 classified devices.

D.

The recommendation has 100% confidence, and it is based on 4 classified devices.

Questions 35

A company has been running Gateway IDS/IPS on its gateways in IDS mode for several weeks. The company wants to transition to IPS mode.

What is one step you should recommend?

Options:
A.

Disable traffic inspection and reboot before re-enabling traffic inspection with the new mode.

B.

Change the mode on one gateway at a time to establish a smoother transition period.

C.

Consider applying a stricter IPS policy to minimize issues during the transition period.

D.

Check for legitimate traffic that has been flagged as a threat and allow list the associated rules.

Questions 36

You are configuring the Gateway IDS/IPS settings for an HPE Aruba Networking Central group.

What is a reason to set the Inspection Mode to IPS instead of IDS?

Options:
A.

The company has a dedicated security staff that can respond to alerts quickly.

B.

The company’s highest priority is mitigating potential threats immediately.

C.

The company wants to enforce stricter policies associated with lower CVSS scores.

D.

The company is concerned about false positives disrupting connectivity.

Questions 37

A company has AOS-CX switches managed by HPE Aruba Networking Central. The network infrastructure devices authenticate clients to HPE Aruba Networking ClearPass Policy Manager (CPPM), which is integrated with HPE Aruba Networking ClearPass Device Insight (CPDI). You have seen suspicious activity on a client connected to one of the switches. To investigate the client’s activity further, you need to know all of the IP addresses that it has used in the past two weeks.

Where can you find this information collected together?

Options:
A.

In CPPM’s Device Profiler dashboard

B.

In HPE Aruba Networking Central’s Audit Trail for the client’s switch

C.

In the logs stored on the client’s switch

D.

In CPDI’s History tab for the client

Questions 38

Refer to the exhibit.

HPE7-A02 Question 38

You have verified that AOS-CX Switch-1 has constructed an IP-to-MAC binding table in VLANs 10-19. Now you need to enable ARP inspection for the endpoint connected to Switch-1. What must you do first to prevent traffic disruption?

Options:
A.

Configure ARP inspection on VLANs 10-19 on Switch-2.

B.

Configure DHCP snooping on VLANs 10-19 on Switch-2.

C.

Configure Switch-1 uplinks as trusted ARP inspection ports.

D.

Create a static IP-to-MAC binding on Switch-1 for the DHCP server.

Questions 39

Refer to the exhibit.

HPE7-A02 Question 39

The exhibit shows a saved packet capture, which you have opened in Wireshark. You want to focus on the complete conversation between 10.1.70.90 and 10.1.79.11 that uses source port 5448.

What is a simple way to do this in Wireshark?

Options:
A.

Apply a capture filter that selects for both the 10.1.70.90 and 10.1.79.11 IP addresses.

B.

Click the Source column and then the Destination column to sort the packets into the desired order.

C.

Apply a capture filter that selects for TCP port 5448.

D.

Right-click one of the packets between those addresses and choose to follow the stream.

Questions 40

A company wants to use HPE Aruba Networking ClearPass Onboard to issue certificates to BYOD devices. These certificates should be valid only for authenticating the company’s ClearPass cluster.

What type of Onboard CA should you set up?

Options:
A.

Intermediate CA with EST disabled

B.

Intermediate CA with EST enabled

C.

Root CA

D.

Registration authority