Summer Special Discount 60% Offer - Ends in 0d 00h 00m 00s - Coupon code: brite60

ExamsBrite Dumps

Aruba Certified Campus Access Professional Exam Question and Answers

Aruba Certified Campus Access Professional Exam

Last Update Oct 15, 2025
Total Questions : 139

We are offering FREE HPE7-A01 HP exam questions. All you do is to just go and sign up. Give your details, prepare HPE7-A01 free exam questions and then go for complete pool of Aruba Certified Campus Access Professional Exam test questions that will help you more.

HPE7-A01 pdf

HPE7-A01 PDF

$42  $104.99
HPE7-A01 Engine

HPE7-A01 Testing Engine

$50  $124.99
HPE7-A01 PDF + Engine

HPE7-A01 PDF + Testing Engine

$66  $164.99
Questions 1

Your Director of Security asks you to assign AOS-CX switch management roles to new employees based on their specific job requirements. After the configuration was complete, it was noted that a user assigned with the auditors role did not have the appropriate level of access on the switch.

The user was not allowed to perform firmware upgrades and a privilege level of 15 was not assigned to their role. Which default management role should have been assigned for the user?

Options:

A.  

sysadmin

B.  

sysops

C.  

administrators

D.  

config

Discussion 0
Questions 2

Refer to Exhibit:

With Access-1, What needs to be identically configured With MSTP to load-balance VLANS?

Options:

A.  

Spanning-tree bpdu-guard setting

B.  

Spanning-tree instance vlan mapppjng

C.  

spanning-tree Cist mapping

D.  

Spanning-tree root-guard setting

Discussion 0
Questions 3

You need to ensure that voice traffic sent through an ArubaOS-CX switch arrives with minimal latency What is the best scheduling technology to use for this task?

Options:

A.  

Strict queuing

B.  

Rate limiting

C.  

QoS shaping

D.  

DWRR queuing

Discussion 0
Questions 4

When configuring UBT on a switch what will happen when a gateway role is not specified?

Options:

A.  

The switch will put the client on the access VLAN

B.  

The gateway will assign a default role to the client

C.  

The switch will assign the default deny role to the client.

D.  

The gateway will send back the deny role to the client.

Discussion 0
Questions 5

You are working on a network where the customer has a dedicated router with redundant Internet connections Tor outbound high-importance real-time audio streams from their datacenter All of this traffic.

• originates from a single subnet

• uses a unique range of UDP ports

• is required to be routed to the dedicated router

All other traffic should route normally The SVI for the subnet containing the servers originating the traffic is located on the core routing switch in the datacenter What should be configured?

Options:

A.  

Configure a new OSPF area including both the core routing switch and the dedicated router

B.  

Configure a BGP link between the core routing switch and the dedicated router and route filtering.

C.  

Configure Policy Based Routing (PBR) on the core routing switch for the VRF with the servers’ SVI

D.  

Configure a dedicated VRF on the core routing switch and make the dedicated router the default route.

Discussion 0
Questions 6

Which standard supported by some Aruba APs can enable a customer to accurately locate wireless client devices within a few meters?

Options:

A.  

802.11mc

B.  

802.11W

C.  

802.11k

D.  

802.11r

Discussion 0
Questions 7

What is one advantage of using OCSP vs CRLs for certificate validation?

Options:

A.  

reduces latency between the time a certificate is revoked and validation reflects this status

B.  

less complex to implement

C.  

higher availability for certificate validation

D.  

supports longer certificate validity periods

Discussion 0
Questions 8

Your customer currently has two (2) 5406 modular switches with MSTP configured as their core switches. You are proposing a new solution. What would you explain regarding the AOS-CX VSX switch pair when the Spanning-tree needs to be set up?

Options:

A.  

Use vsx-sync in the MSTP region configuration to get synced.

B.  

Enable vsx-sync stp-global in vsx mode to sync the configuration.

C.  

Spanning-tree configuration is synced by default with VSX.

D.  

Enable vsx-peer stp-global in vsx mode to sync the configuration.

Discussion 0
Questions 9

When setting up an Aruba CX VSX pair, which information does the Inter-Switch Link Protocol configuration use in the configuration created?

Options:

A.  

hello interval is disabled by default

B.  

hello interval is based on the value set by dead interval

C.  

hello interval 100ms by default

D.  

hello interval is 1s by default

Discussion 0
Questions 10

A company recently deployed new Aruba Access Points at different branch offices Wireless 802.1X authentication will be against a RADIUS server in the cloud. The security team is concerned that the traffic between the AP and the RADIUS server will be exposed.

What is the appropriate solution for this scenario?

Options:

A.  

Enable EAP-TLS on all wireless devices

B.  

Configure RadSec on the AP and Aruba Central.

C.  

Enable EAP-TTLS on all wireless devices.

D.  

Configure RadSec on the AP and the RADIUS server

Discussion 0
Questions 11

For an Aruba AOS10 AP in mixed mode, which factors can be used to determine the forwarding role assigned to a client? (Select two.)

Options:

A.  

Client IP address

B.  

802.1X authentication result

C.  

Client MAC address

D.  

Client SSID

E.  

Client VLAN

Discussion 0
Questions 12

You are configuring an SVI on an Aruba CX switch that needs to have the following characteristics:

• VLANID = 25

. IPv4 address 10 105 43 1 with mask 255 255 255.0

• IPv6 address fd00:5708::f02d:4df6 with a 64 bit prefix length

• member of VRF eng

• VRF eng and VLAN 25 have not yet been created

Which command lists will satisfy the requirements with the least number of commands?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 13

A client is connecting to 802.1X SSID that has been configured in tunnel mode with the default AP-group settings.

After receiving Access-Accept from the RADIUS server, the Aruba Gateway will send Access-Accept to the AP through which tunnel?

Options:

A.  

IPsec tunnel

B.  

Split tunnel

C.  

GRE tunnel

D.  

PAR tunnel

Discussion 0
Questions 14

Due to a shipping error, five (5) Aruba AP-515S and one (1) Aruba CX 6300 were sent directly to your new branch office You have configured a new group persona for the new branch office devices in Central, but you do not know their MAC addresses or serial numbers The office manager is instructed via text message on their smartphone to onboard all the new hardware into Aruba Central

What application must the office manager use on their phone to complete this task?

Options:

A.  

Aruba Onboard App

B.  

Aruba Central App

C.  

Aruba CX Mobile App

D.  

Aruba installer App

Discussion 0
Questions 15

Match the terms below to their characteristics (Options may be used more than once or not at all.)

Options:

Discussion 0
Questions 16

You are configuring Policy Based Routing (PBR) for a subnet that will be used to test a new default route for your network Traffic originating from 10.2.250.0/24 should use a new default route to 10.1.1.253. Other non-default routes for this subnet should not be affected by this change.

What are two parts of the solution for these requirements? (Select two.)

A)

B)

C)

D)

E)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

E.  

Option E

Discussion 0
Questions 17

A customer has a site with 200 AP-515 access points 75AP-565 access points installed. The customer is rolling out new mobile phones with Wi-Fi-calling. 802.1X is in use for authentication

What should be enabled to ensure the best roaming experience?

Options:

A.  

802.1X

B.  

802. 11r

C.  

802.11W

D.  

802 .11h

Discussion 0
Questions 18

A customer wants to deploy a Gateway and take advantage of all the SD-WAN features. Which persona role option should be selected?

Options:

A.  

ArubaOS 10 Branch

B.  

ArubaOS 10 VPN Concentrator

C.  

ArubaOS 10 Wireless

D.  

ArubaOS 10 Mobility

Discussion 0
Questions 19

Match the topics of an AOS10 Tunneled mode setup between an AP and a Gateway. (Options may be used more than once or not at all.)

Options:

Discussion 0
Questions 20

Refer to the exhibit.

In the Core-2 configuration of spanning-tree instance 2 priority 0, what needs to be configured to enable the root for VLAN 20 while VLAN 10 remains root on Core-1?

Options:

A.  

Spanning-tree instance 2 VLAN 20

B.  

Spanning-tree priority 0 VLAN 20

C.  

Spanning-tree priority root VLAN 20

D.  

Spanning-tree VLAN 20

Discussion 0
Questions 21

Which feature allows the device to remain operational when a remote link failure occurs between a Gateway cluster and a RADIUS server that is either in the cloud or a datacenter?

Options:

A.  

MAC caching

B.  

MAC Authentication

C.  

Authentication survivability

D.  

Opportunistic key caching

Discussion 0
Questions 22

Which network components communicate using the RADIUS protocol for authentication and accounting?

Options:

A.  

an access point and the endpoint device

B.  

a Network Access Server and a RADIUS authentication server

C.  

an endpoint device and a RADIUS authentication server

D.  

a Network Access Server and an endpoint device

Discussion 0
Questions 23

Your customer has four (4) Aruba 7200 Series Gateways and two (2) 7000 Series Gateways. The customer wants to form a cluster with these Gateways. What design consideration would prevent you from using all of those Gateways?

Options:

A.  

Multiple versions between Gateways in the same cluster profile are not allowed AOS 10.x.

B.  

A heterogeneous cluster is not supported in AOS 10.x.

C.  

The AP load should be lowest value of worst-case scenario load.

D.  

A combination of 7200 series and 7000 series gateways supports up to 4 nodes

Discussion 0
Questions 24

A customer is using a legacy application that communicates at layer-2. The customer would like to keep this application working across the campus which is connected via layer-3. The legacy devices are connected to Aruba CX 6300 switches throughout the campus.

Which technology minimizes flooding so the legacy application can work efficiently?

Options:

A.  

Generic Routing Encapsulation (GRE)

B.  

EVPN-VXLAN

C.  

Ethernet over IP (EolP)

D.  

Static VXLAN

Discussion 0
Questions 25

List the firewall role derivation flow in the correct order

Options:

Discussion 0
Questions 26

For the Aruba CX 6400 switch, what does virtual output queueing (VOQ) implement that is different from most typical campus switches?

Options:

A.  

large ingress packet buffers

B.  

large egress packet buffers

C.  

per port ASICs

D.  

VSX

Discussion 0
Questions 27

With the CX 6000 48G switch with uplinks of 1/1/47 and 1/1/48, what does the switch do when a client port detects a loop and tx-disable parameter is used?

Options:

A.  

The ports that confirmed the loop are disabled.

B.  

The ports that transmitted and received the loop are disabled.

C.  

The port that transmitted the loop is disabled.

D.  

The port that received the loop is disabled.

Discussion 0
Questions 28

What does the 802.3bz standard describe?

Options:

A.  

2.5Gb and 5Gb Ethernet ports

B.  

60 W and 90W PoE

C.  

AP directed roaming between APs

D.  

60 GHz P2P Wi-Fi

Discussion 0
Questions 29

Refer to the output from a CX 6100 switch:

What is the correct detail that can be observed from the output above?

Options:

A.  

The dBm values for Tx are too high and affect Rx signals.

B.  

The dBm values for Rx are too low, indicating that the link is down.

C.  

The dBm values for Rx are within acceptable values, and the link is up.

D.  

The dbm values for T are too far away from 0, and the link is down.

Discussion 0
Questions 30

How do you allow a new VLAN 100 between VSX pair inter-switch-link 256 for port 1/45 and 2/45?

Options:

A.  

vlan trunk allowed 100 for ports 1/45 and 1/46

B.  

vlan trunk add 100 in LAG256

C.  

vlan trunk allowed 100 in LAG256

D.  

vlan trunk add 100 in MLAG256

Discussion 0
Questions 31

With Aruba CX 6300. how do you configure ip address 10 10 10 1 for the interface in default state for interface 1/1/1?

Options:

A.  

int 1/1/1. switching, ip address 10 10 10 1/24

B.  

int 1/1/1. no switching, ip address 10 10 10.1/24

C.  

int 1/1/1. ip address 10.10.10.1/24

D.  

int 1/1/1. routing, ip address 10.10.10 1/24

Discussion 0
Questions 32

A customer wants to enable wired authentication across all their CX switches One of the requirements is that the switch must be able to authenticate a single computer connected through a VoIP phone.

Which feature should be enabled to support this requirement?

Options:

A.  

Multi-Domain Authentication

B.  

Device-Based Mode

C.  

MAC Authentication

D.  

Multi-Auth Mode

Discussion 0
Questions 33

What is an Aruba-recommended best practice for hardening that only applies to Aruba CX 6300 series switches with dedicated management ports?

Options:

A.  

Implement a control plane ACL to limit access to approved IPs and/or subnets

B.  

Manually enable Enhanced Security Mode from a console session.

C.  

Disable all management services on the default VRF.

D.  

Create a dedicated management VRF, and assign the management port to it.

Discussion 0
Questions 34

You are helping an onsite network technician bring up an Aruba 9004 gateway with ZTP for a branch office The technician was to plug in any port for the ZTP process to start Thirty minutes after the gateway was plugged in new users started to complain they were no longer able to get to the internet. One user who reported the issue stated their IP address is 172.16 0.81 However, the branch office network is supposed to be on 10.231 81.0/24.

What should the technician do to alleviate the issue and get the ZTP process started correctly?

Options:

A.  

Turn off the DHCP scope on the gateway, and set DNS correctly on the gateway to reach Aruba Activate

B.  

Move the cable on the gateway from port G0/0V1 tc port G0 0.0

C.  

Move the cable on the gateway to G0/0/1. and add the device's MAC and Serial number in Central

D.  

Factory default and reboot the gateway to restart the process.

Discussion 0
Questions 35

Refer to the exhibit.

A company has deployed 200 AP-635 access points. To but is not working as expected

What would be the correct action to fix the issue?

Options:

A.  

Change the SSID to WPA3-Enhanced Open

B.  

Change the SSID to WPA3-Enterprise (CCM).

C.  

Change the SSID to WPA3-Personal

D.  

Change the SSID to WPA3-Enterpnse (CNSA).

Discussion 0
Questions 36

A large retail client is looking to generate a rich set of contextual data based on the location information of wireless clients in their stores Which standard uses Round Trip Time (RTT) and Fine Time Measurements (FTM) to calculate the distance a client is from an AP?

Options:

A.  

802.11ah

B.  

802.11mc

C.  

802.11be

D.  

802.11V

Discussion 0
Questions 37

A customer is concerned about me unprotected traffic between an AOS-CX switch and a gateway, running on AOStO. What is a feasible option to protect this traffic?

Options:

A.  

Implement an IPSec tunnel to protect PAPI between the AOS-CX switches and the gateway

B.  

Implement an MD5 HMAC function lo protect PAPI between the AOS-CX switches and the gateway

C.  

Implement a GRE tunnel to protect PAPI between the AOS-CX switches and the gateway

D.  

no action is needed, an RSA certificate already encrypts the traffic

Discussion 0
Questions 38

What is the order of operations tor Key Management service for a wireless client roaming from AP1 to AP2?

Options:

Discussion 0
Questions 39

A customer is using Aruba Cloud Guest, but visitors keep complaining that the captive portal page keeps coming up after devices go to sleep Which solution should be enabled to deal with this issue?

Options:

A.  

MAC Caching under the splash page

B.  

MAC Caching under the user-role

C.  

Wireless Caching under the splash page

D.  

MAC Caching under the WLAN

Discussion 0
Questions 40

Which statements regarding 0SPFv2 route redistribution are true for Aruba OS CX switches? (Select two.)

Options:

A.  

The "redistribute connected" command will redistribute all connected routes for the switch including local loopback addresses

B.  

The "redistribute ospf" command will redistribute routes from all OSPF V2 and V3 processes

C.  

The "redistribute static route-map connected-routes" command will redistribute all static routes without a matching deny in the route map "connected-routes".

D.  

The "redistribute connected" command will redistribute all connected routes for the switch except local loopback addresses.

E.  

The "redistribute static route-map connected-routes" command will redistribute all static routes with a matching permit in the route map "connected-routes-

Discussion 0
Questions 41

Your customer is interested in hearing more about how roles can help keep consistent policy enforcement in a distributed overlay fabric How would you explain this concept to them''

Options:

A.  

Group Based Policy ID is applied on egress VTEP after device authentication and policy is enforced on ingress VTEP

B.  

Role-based policies are tied to IP addresses which have an advantage over IP-based policies and role names are sent between VTEPs

C.  

Group Based Policy ID is applied on ingress VTEP after device authentication and policy is enforced on egress VTEP

D.  

Role-based policies enhance User Based Tunneling across the campus network and the policy traffic is protected with iPsec

Discussion 0