Pre-Summer Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Aruba Certified Network Security Professional Exam Question and Answers

Aruba Certified Network Security Professional Exam

Last Update May 31, 2026
Total Questions : 156

We are offering FREE HPE7-A02 HP exam questions. All you do is to just go and sign up. Give your details, prepare HPE7-A02 free exam questions and then go for complete pool of Aruba Certified Network Security Professional Exam test questions that will help you more.

HPE7-A02 pdf

HPE7-A02 PDF

$36.75  $104.99
HPE7-A02 Engine

HPE7-A02 Testing Engine

$43.75  $124.99
HPE7-A02 PDF + Engine

HPE7-A02 PDF + Testing Engine

$57.75  $164.99
Questions 1

A company wants to apply a standard configuration to all AOS-CX switch ports and have the ports dynamically adjust their configuration based on the identity of

the user or device that connects. They want to centralize configuration of the identity-based settings as much as possible.

What should you recommend?

Options:

A.  

Having HPE Aruba Networking ClearPass Policy Manager (CPPM) send standard RADIUS AVPs to customize port settings

B.  

Having switches pull port configurations dynamically from HPE Aruba Networking Activate

C.  

Having switches download user-roles from HPE Aruba Networking gateways

D.  

Having switches download user-roles from HPE Aruba Networking ClearPass Policy Manager (CPPM)

Discussion 0
Questions 2

A company requires a centralized audit trail for commands that managers enter on AOS-CX switches.

What can you set up on the switches to meet this requirement?

Options:

A.  

RADIUS start-stop and interim accounting with the port-access option

B.  

Command authorization to HPE Aruba Networking ClearPass Policy Manager (CPPM) acting as a TACACS+ server

C.  

SSH public key authentication for all managers who access the AOS-CX switches

D.  

Logging to a Syslog server with the severity set at error level

Discussion 0
Questions 3

You have created this rule in an HPE Aruba Networking ClearPass Policy Manager (CPPM) service ' s enforcement policy: IF Authorization [Endpoints Repository]

Conflict EQUALS true THEN apply " quarantine_profile "

What information can help you determine whether you need to configure cluster-wide profiler parameters to ignore some conflicts?

Options:

A.  

Whether the company has rare Internet of Things (loT) devices

B.  

Whether some devices are incapable of captive portal or 802.1X authentication

C.  

Whether the company has devices that use PXE boot

D.  

Whether some devices are running legacy operating systems

Discussion 0
Questions 4

The following firewall role is configured on HPE Aruba Networking Central-managed APs:

wlan access-rule employees

index 3

rule any any match 17 67 67 permit

rule any any match any 53 53 permit

rule 10 5 5.0 255.255 255.0 match any any any deny

rule 10.5 0.0 255.255 0.0 match 6 80 80 permit

rule 10.5 0.0 255.255.0.0 match 6 443 443 permit

rule 10.5.0.0 255.255.0.0 match any any any deny

rule any any match any any any permit

A client has authenticated and been assigned to the employees role. The client has IP address 10.2.2.2. Which correctly describes behavior in this policy?

Options:

A.  

HTTPS traffic from 10.2.2.2 to 10.5.5.5 is denied.

B.  

HTTPS traffic from 10.2.2.2 to 203.0.113.12 is denied.

C.  

Traffic from 10.5.3.3 in an active HTTPS session between 10.2.2.2 and 10.5.3.3 is permitted.

D.  

Traffic from 198.51.100.12 in an active HTTP session between 10.2.2.2 and 198.51.100.12 is denied.

Discussion 0
Questions 5

A company has HPE Aruba Networking Central-managed APs. The company wants to block all clients connected through the APs from using YouTube.

Which steps should you take?

Options:

A.  

Deploy gateways and have the APs tunnel traffic to the gateways. Then, enable the gateway IDS/IPS engine.

B.  

Enable Client IPS at the " custom " level, and then specify the check for YouTube.

C.  

Enable WebCC on all client firewall roles. Then, create WebCC category rules that deny suspicious URLs.

D.  

Enable DPI. Then, create application rules to deny YouTube on the firewall roles.

Discussion 0
Questions 6

A company has AOS-CX switches and HPE Aruba Networking ClearPass Policy Manager (CPPM). The company wants switches to implement 802.1X

authentication to CPPM and download user roles.

What is one task that you must complete on the switches to support this use case?

Options:

A.  

Specify CPPM as the RADIUS server with the exact CN in CPPM ' s HTTPS certificate.

B.  

Install the root CA certificate for CPPM ' s RADIUS certificate in a TA profile on the switches.

C.  

Configure empty user-roles with names that match enforcement profile names on CPPM.

D.  

Specify a ClearPass username and password that match the name and RADIUS secret in a CPPM network device entry.

Discussion 0
Questions 7

A company wants you to integrate HPE Aruba Networking ClearPass Policy Manager (CPPM) with HPE Aruba Networking ClearPass Device Insight (CPDI).

What is one aspect of the integration that you should explain?

Options:

A.  

CPPM no longer supports any Device Profiler features and relies on CPDI for this profile information.

B.  

CPDI must be configured as an audit server on CPPM for the integration to be successful.

C.  

CPDI must have security analysis disabled on it for the integration to be successful.

D.  

CPPM can submit profile information to CPDI, but if CPDI derives a different classification, CPDI takes precedence.

Discussion 0
Questions 8

A company wants to turn on Wireless IDS/IPS infrastructure and client detection at the high level on HPE Aruba Networking APs. The company does not want to

enable any prevention settings.

What should you explain about HPE Aruba Networking recommendations?

Options:

A.  

HPE Aruba Networking recommends turning on both wired and wireless prevention whenever you enable detection at high.

B.  

HPE Aruba Networking recommends using hybrid AP mode, as opposed to Air Monitors (AMs), when implementing detection without prevention.

C.  

HPE Aruba Networking recommends disabling client detection when you configure infrastructure detection at high, as infrastructure detection includes all the client checks and more.

D.  

HPE Aruba Networking recommends configuring infrastructure and client detection at a custom level and disabling or tuning some of the settings that are likely to produce false positives.

Discussion 0
Questions 9

(Note that the HPE Aruba Networking Central interface shown here might look slightly different from what you see in your HPE Aruba Networking Central

interface as versions change; however, similar concepts continue to apply.)

An HPE Aruba Networking 9x00 gateway is part of an HPE Aruba Networking Central group that has the settings shown in the exhibit. What would cause the

gateway to drop traffic as part of its IDPS settings?

Options:

A.  

Its site-to-site VPN connections failing

B.  

Traffic matching a rule in the active ruleset

C.  

Its IDPS engine failing

D.  

Traffic showing anomalous behavior

Discussion 0
Questions 10

A company has HPE Aruba Networking infrastructure devices. The devices authenticate clients to HPE Aruba Networking ClearPass Policy Manager (CPPM). You want CPPM to track information about clients, such as their IP addresses and their network bandwidth utilization. What should you set up on the network infrastructure devices to help that happen?

Options:

A.  

Logging with CPPM configured as a Syslog server.

B.  

Dynamic authorization enabled in the RADIUS settings for CPPM.

C.  

RADIUS accounting to CPPM, including interim updates.

D.  

An IF-MAP interface with CPPM as the destination.

Discussion 0
Questions 11

A company lacks visibility into the many different types of user and loT devices deployed in its internal network, making it hard for the security team to address

those devices.

Which HPE Aruba Networking solution should you recommend to resolve this issue?

Options:

A.  

HPE Aruba Networking ClearPass Device Insight (CPDI)

B.  

HPE Aruba Networking Network Analytics Engine (NAE)

C.  

HPE Aruba Networking Mobility Conductor

D.  

HPE Aruba Networking ClearPass OnBoard

Discussion 0
Questions 12

Refer to the exhibit.

You are reviewing packets in Wireshark. The capture shows traffic from source IP address 10.1.14.10 to several destinations in the 10.1.15.0/24 network. The packets use TCP flags FIN, PSH, and URG together.

What can you interpret from the packets that you see here?

Options:

A.  

10.1.14.10 might be running a TCP port scan, but it may simply be trying to open TCP sessions with several destinations.

B.  

10.1.14.10 is almost certainly running a TCP port scan because this type of packet does not legitimately exist.

C.  

10.1.14.10 is launching a denial-of-service attack against Windows machines in 10.1.15.0/24.

D.  

10.1.14.10 is showing some signs of launching a DoS attack, but might simply be misconfigured.

Discussion 0
Questions 13

A company wants you to create a custom device fingerprint on CPPM with rules for profiling a group of specialized devices. What is one requirement?

Options:

A.  

Connecting a known device of this type and getting it discovered in CPPM ' s Endpoints Repository.

B.  

Enabling HPE Aruba Networking ClearPass Device Insight integration with the correct Data Collector token.

C.  

Pre-defining the desired attributes and rules in an XML format file.

D.  

Disabling the " Automatically download Endpoint Profiler Fingerprints " feature in cluster-wide parameters.

Discussion 0
Questions 14

A company wants to use HPE Aruba Networking ClearPass Onboard to issue certificates to BYOD devices. These certificates should be valid only for authenticating the company’s ClearPass cluster.

What type of Onboard CA should you set up?

Options:

A.  

Intermediate CA with EST disabled

B.  

Intermediate CA with EST enabled

C.  

Root CA

D.  

Registration authority

Discussion 0
Questions 15

Refer to the exhibit.

You have verified that AOS-CX Switch-1 has constructed an IP-to-MAC binding table in VLANs 10-19. Now you need to enable ARP inspection for the endpoint connected to Switch-1. What must you do first to prevent traffic disruption?

Options:

A.  

Configure ARP inspection on VLANs 10-19 on Switch-2.

B.  

Configure DHCP snooping on VLANs 10-19 on Switch-2.

C.  

Configure Switch-1 uplinks as trusted ARP inspection ports.

D.  

Create a static IP-to-MAC binding on Switch-1 for the DHCP server.

Discussion 0
Questions 16

A company is using HPE Aruba Networking Central SD-WAN Orchestrator to establish a hub-spoke VPN between branch gateways (BGWs) at 1164 site and VPNCs at multiple data centers. What is part of the configuration that admins need to complete?

Options:

A.  

In VPNCs’ groups, establish VPN pools to control which branches connect to which VPNCs.

B.  

In BGWs’ and VPNCs’ groups, create default IKE policies for the SD-WAN Orchestrator to use.

C.  

In BGWs’ groups, select the VPNCs to which to connect in a DC preference list.

D.  

At the global level, create default IPsec policies for the SD-WAN Orchestrator to use.

Discussion 0
Questions 17

What is one use case for implementing user-based tunneling (UBT) on AOS-CX switches?

Options:

A.  

Centralizing the distribution of wired traffic without requiring HPE Aruba Networking gateways

B.  

Tunneling traffic directly to a third-party firewall in a client data center

C.  

Adding 802.1X while continuing to use the existing VLAN and ACL structure in the Ethernet network

D.  

Applying enhanced security features such as deep packet inspection (DPI) to wired traffic

Discussion 0
Questions 18

A company wants to implement Virtual Network based Tunneling (VNBT) on a particular group of users and assign those users to an overlay network with VNI

3000.

Assume that an AOS-CX switch is already set up to:

. Implement 802.1X to HPE Aruba Networking ClearPass Policy Manager (CPPM)

. Participate in an EVPN VXLAN solution that includes VNI 3000

Which setting should you configure in the users ' AOS-CX role to apply VNBT to them when they connect?

Options:

A.  

Gateway zone set to " 3000 " with no gateway role set

B.  

Gateway zone set to " vni-3000 " with no gateway role set

C.  

Access VLAN set to the VLAN mapped to VNI 3000

D.  

Access VLAN ID set to " 3000 "

Discussion 0
Questions 19

Refer to the exhibits.

HPE Aruba Networking ClearPass Policy Manager (CPPM) is authenticating 802.1X clients using Active Directory as the source. CPPM has a custom attribute for AD that uses AccountStatus as userAccountControl .

Which enforcement profile does CPPM apply to a client that:

    Succeeds in authenticating to an active AD user account: userAccountControl = 512

    Does not succeed at authenticating as a computer

Options:

A.  

profile3

B.  

profile1

C.  

Deny Access Profile

D.  

profile2

Discussion 0
Questions 20

A company is using HPE Aruba Networking ClearPass Device Insight (CPDI) (the standalone application). You have identified a device, which is currently

classified as one type, but you want to classify it as a custom type. You also want to classify all devices with similar attributes as this type, both already-discovered

devices and new devices discovered later.

What should you do?

Options:

A.  

Create a user tag from the Generic Devices page, select the desired attributes for the tag, and save the tag.

B.  

In the device details, select reclassify, create a user rule based on its attributes, and choose " Save & Reclassify. "

C.  

In the device details, select filter, create a user tag based on the device attributes, and save the tag.

D.  

Create a user rule from the Generic Devices page, select the desired attributes for the rule, and choose " Save. "

Discussion 0
Questions 21

You are configuring the HPE Aruba Networking ClearPass Device Insight Integration settings on ClearPass Policy Manager (CPPM). For which use case should you set the ' Tag Updates Action " to " apply for all tag updates " ?

Options:

A.  

When the Device Insight integration poll interval is set to a relatively long interval but you still want CPPM to be informed quickly about devices ' new tags.

B.  

When Device Insight tags are only used to identify dangerous devices, and you want to disconnect those devices without having to set up new rules in enforcement policies.

C.  

When CPPM is gathering posture information for CPDI, and you want CPDI to always have access to the most up-to-date information.

D.  

When you plan to have CPPM issue CoAs for clients with new tags, but do not want to have to list those specific tags in the Device Integration settings in advance.

Discussion 0
Questions 22

A company uses HPE Aruba Networking ClearPass Device Insight (CPDI) (the standalone application option). In the details for a generic device cluster, you see a

recommendation for " Windows 8/10 " with 70% accuracy.

What does this mean?

Options:

A.  

CPDI has detected that these devices match about 70% of the system rule for defining " Windows 8/10 " devices.

B.  

CPDI has matched these devices against several, conflicting system rules. 70% of those rules are for " Windows 8/10 " devices.

C.  

CPDI has grouped this cluster with similar classified devices. 70% of those classified devices are " Windows 8/10. "

D.  

CPDI has used MAC OUI to group these devices together. The average device ' s MAC address matches 70% of the " Windows 8/10 " OUI.

Discussion 0
Questions 23

A company has HPE Aruba Networking APs, which authenticate users to HPE Aruba Networking ClearPass Policy Manager (CPPM).

What does HPE Aruba Networking recommend as the preferred method for assigning clients to a role on the AOS firewall?

Options:

A.  

Configure CPPM to assign the role using a RADIUS enforcement profile with a RADIUS:IETF Username attribute.

B.  

Configure CPPM to assign the role using a RADIUS enforcement profile with an Aruba-User-Role VSA.

C.  

OCreate server rules on the APs to assign clients to roles based on RADIUS IETF attributes returned by CPPM.

D.  

Create user rules on the APs to assign clients to roles based on a variety of criteria.

Discussion 0
Questions 24

A company needs you to integrate HPE Aruba Networking ClearPass Policy Manager (CPPM) with HPE Aruba Networking ClearPass Device Insight (CPDI). What is one task you should do to prepare?

Options:

A.  

Install the root CA for CPPM’s HTTPS certificate as trusted in the CPDI application.

B.  

Enable Insight in the CPPM server configuration settings.

C.  

Configure WMI, SSH, and SNMP external accounts for device scanning on CPPM.

D.  

Collect a Data Collector token from HPE Aruba Networking Central.

Discussion 0
Questions 25

A company is using HPE Aruba Networking ClearPass Device Insight (CPDI) (the standalone application). In the CPDI security settings, Security Analysis is On, the Data Source is ClearPass Device Insight, and Enable Posture Assessment is On. You see that a device has a Risk Score of 90.

What can you know from this information?

Options:

A.  

The posture is unknown, and CPDI has detected exactly four vulnerabilities on the device.

B.  

The posture is healthy, but CPDI has detected multiple vulnerabilities on the device.

C.  

The posture is unhealthy, and CPDI has also detected at least one vulnerability on the device.

D.  

The posture is unhealthy, but CPDI has not detected any vulnerabilities on the device.

Discussion 0
Questions 26

A company uses HPE Aruba Networking ClearPass Policy Manager (CPPM) as a TACACS+ server to authenticate managers on its AOS-CX switches. The

company wants CPPM to control which commands managers are allowed to enter. You see there is no field to enter these commands in ClearPass.

How do you start configuring the command list on CPPM?

Options:

A.  

Add the Shell service to the managers ' TACACS+ enforcement profiles.

B.  

Edit the TACACS+ settings in the AOS-CX switches ' network device entries.

C.  

Create an enforcement policy with the TACACS+ type.

D.  

Edit the settings for CPPM ' s default TACACS+ admin roles.

Discussion 0
Questions 27

A company has AOS-CX switches, which authenticate clients to HPE Aruba Networking ClearPass Policy Manager (CPPM). CPPM is set up to receive a variety of information about clients ' profile and posture. New information can mean that CPPM should change a client ' s enforcement profile. What should you set up on the switches to help the solution function correctly?

Options:

A.  

Enable RADIUS accounting to CPPM, including interim RADIUS accounting.

B.  

Configure a RADIUS track that references CPPM ' s FQDN or IP address.

C.  

Enable dynamic authorization, and specify CPPM as a dynamic authorization client.

D.  

Re-configure the authentication server on the switch specifying CPPM as a TACACS server.

Discussion 0
Questions 28

Which use case is fulfilled by applying a time range to a firewall rule on an AOS device?

Options:

A.  

Enforcing the rule only during the specified time range

B.  

Tuning the session timeout for sessions established with this rule

C.  

Locking clients that violate the rule for the specified time range

D.  

Setting the time range over which hit counts for the rule are aggregated

Discussion 0
Questions 29

A company has HPE Aruba Networking APs and AOS-CX switches. The APs bridge wireless traffic. They receive DHCP IP addresses on VLAN 18. Wireless users are assigned to VLAN 12.

The company wants the APs to start using 802.1X authentication on their switch ports. You are configuring the port-access role to which the APs are assigned after authentication.

What is one recommended setting for that role?

Options:

A.  

No trust for DSCP

B.  

Trust for DSCP

C.  

Auth-mode left at client-mode

D.  

Access VLAN 18 with no support for VLAN 12

Discussion 0
Questions 30

A company wants HPE Aruba Networking ClearPass Policy Manager (CPPM) to respond to Syslog messages from its Check Point firewall. You have added the

firewall as an event source and set up an event service. However, test Syslog messages are not triggering the expected actions.

What is one CPPM setting that you should check?

Options:

A.  

ClearPass Device Insight integration is disabled.

B.  

The Check Point Extension is installed through ClearPass Guest.

C.  

The CoA delay value is set to 0 on the server.

D.  

Ingress Event Dictionaries for Check Point messages are enabled.

Discussion 0
Questions 31

A company is implementing a client-to-site VPN based on tunnel-mode IPsec.

Which devices are responsible for the IPsec encapsulation?

Options:

A.  

Gateways at the remote clients ' locations and devices accessed by the clients at the main site

B.  

The remote clients and devices accessed by the clients at the main site

C.  

The remote clients and a gateway at the main site

D.  

Gateways at the remote clients ' locations and a gateway at the main site

Discussion 0
Questions 32

What can help justify the extra cost of air monitors (AMs) to a company?

Options:

A.  

AMs support tarpit containment, which introduces fewer legal issues than deauthentication containment.

B.  

AMs can support wireless clients when they are not actively containing a device, so companies benefit from better security and connectivity.

C.  

AMs support additional IDS/IPS features, such as malware and Trojan detection, to enhance overall security.

D.  

AMs can detect wireless threats much faster than hybrid APs, reducing the company’s vulnerability surface.

Discussion 0
Questions 33

A company has HPE Aruba Networking APs running AOS-10 and managed by HPE Aruba Networking Central. The company also has AOS-CX switches. The security team wants you to capture traffic from a particular wireless client. You should capture this client’s traffic over a 15-minute time period and then send the traffic to them in a PCAP file. What should you do?

Options:

A.  

Access the CLI for the client’s AP. Set up a mirroring session between its radio and a management station running Wireshark.

B.  

Go to the client’s AP in HPE Aruba Networking Central. Use the " Security " page to run a packet capture.

C.  

Go to that client in HPE Aruba Networking Central. Use the " Live Events " page to run a packet capture.

D.  

Access the CLI for the client’s AP ' s switch. Set up a mirroring session between the AP’s port and a management station running Wireshark.

Discussion 0
Questions 34

You are setting up HPE Aruba Networking SSE. Which use case requires you to apply a non-default device posture in a rule?

Options:

A.  

Applying threat inspection to users when they access certain websites

B.  

Checking whether a client has antivirus software as a condition for receiving access to resources

C.  

Redirecting compromised clients to a remediation server

D.  

Integrating with HPE Aruba Networking ClearPass OnGuard

Discussion 0
Questions 35

What is a typical use case for using HPE Aruba Networking ClearPass Onboard to provision devices?

Options:

A.  

Enabling unmanaged devices to succeed at certificate-based 802.1X

B.  

Enabling managed Windows domain computers to succeed at certificate-based 802.1X

C.  

Enhancing security for loT devices that need to authenticate with MAC-Auth

D.  

Enforcing posture-based assessment on managed Windows domain computers

Discussion 0
Questions 36

What is one benefit of integrating HPE Aruba Networking ClearPass Policy Manager (CPPM) with third-party solutions such as Mobility Device Management (MDM) and firewalls?

Options:

A.  

CPPM can exchange contextual information about clients with third-party solutions, which helps make better decisions.

B.  

CPPM can make the third-party solutions more secure by adding signature-based threat detection capabilities.

C.  

CPPM can offload policy decisions to the third-party solutions, enabling CPPM to respond to authentication requests more quickly.

D.  

CPPM can take over filtering internal traffic so that the third-party solutions have more processing power to devote to filtering external traffic.

Discussion 0
Questions 37

A company has HPE Aruba Networking APs managed by HPE Aruba Networking Central. You have set up a WLAN to enforce WPA3 with 802.1X authentication.

What happens if the client fails authentication?

Options:

A.  

The AP assigns the client to the WLAN ' s default role.

B.  

The AP drops the client because authentication aborts.

C.  

The AP assigns the client to the WLAN ' s critical role.

D.  

The AP assigns the client to the WLAN ' s initial role.

Discussion 0
Questions 38

Which issue can an HPE Aruba Networking Secure Web Gateway (SWG) solution help customers address?

Options:

A.  

The organization needs a faster way to quarantine clients that have generated threats, as detected by third-party firewalls.

B.  

Hybrid workers are exposing their computers to risky internet sites and infection by malware when they work from home.

C.  

Remote workers need access to private data center applications without exposing those applications to unauthorized users.

D.  

The organization currently has no way to prevent users from exfiltrating sensitive data from SaaS applications.

Discussion 0
Questions 39

You manage AOS-10 APs with HPE Aruba Networking Central. A role is configured on these APs with these rules (in order):

Allow UDP on port 67 to any destination

Allow any to network 10.1.4.0/23

Deny any to network 10.1.0.0/18 + log

Deny any to network 10.0.0.0/8

Allow any to any destination

You add this new rule immediately before rule 4:

Deny SSH to network 10.1.0.0/21 + denylist

After this change, what happens when a client assigned to this role sends SSH traffic to 10.1.7.12?

Options:

A.  

The traffic is permitted

B.  

The traffic is dropped and logged

C.  

The traffic is dropped, and the client is denylisted

D.  

The traffic is dropped (without any logging or further action against the client)

Discussion 0
Questions 40

You are deploying a virtual Data Collector for use with HPE Aruba Networking ClearPass Device Insight (CPDI). You have identified VLAN 101 in the data center

as the VLAN to which the Data Collector should connect to receive its IP address and connect to HPE Aruba Networking Central.

Which Data Collector virtual ports should you tell the virtual admins to connect to VLAN 101?

Options:

A.  

The one with the lowest MAC address

B.  

The one with the highest port ID

C.  

The one with the highest MAC address

D.  

The one with the lowest port ID

Discussion 0
Questions 41

A company has AOS-CX switches and HPE Aruba Networking ClearPass Policy Manager (CPPM). The company wants switches to implement 802.1X authentication to CPPM and download user roles. What is one task that you must complete on CPPM to support this use case?

Options:

A.  

Export roles on CPPM to a file that uses XML format.

B.  

Create an admin account for the switch on CPPM with the HPE Aruba Networking User Role Download privilege level.

C.  

Configure RADIUS enforcement profiles that specify the HPE-User-Role VSA.

D.  

Upload the switch TPM certificate as a trusted CA certificate with the Others usage.

Discussion 0
Questions 42

HPE Aruba Networking ClearPass Device Insight (CPDI) could not classify some endpoints using system and user rules. Using machine learning, it did assign those endpoints to a cluster and discover a recommendation. In which of these circumstances does CPDI automatically classify the endpoints based on that recommendation?

Options:

A.  

The recommendation has 96% confidence, and it is based on 13 classified devices.

B.  

The recommendation has 98% confidence, and it is based on 5 classified devices.

C.  

The recommendation has 93% confidence, and it is based on 36 classified devices.

D.  

The recommendation has 100% confidence, and it is based on 4 classified devices.

Discussion 0
Questions 43

A company is using HPE Aruba Networking ClearPass Policy Manager (CPPM) and HPE Aruba Networking ClearPass Device Insight (CPDI). CPDI and CPPM are integrated. The security staff wants you to show them a list of all devices that are contacting a specific known command-and-control center.

What should you do?

Options:

A.  

In CPPM’s Access Tracker, filter for that destination.

B.  

Use ClearPass Insight to run an Active Endpoint Security report.

C.  

In CPDI, look in Generic Device clusters based on that destination.

D.  

In CPDI, filter for that destination and save the filter as a tag.

Discussion 0
Questions 44

You are setting up policy rules in HPE Aruba Networking SSE. You want to create a single rule that permits users in a particular user group to access multiple applications. What is an easy way to meet this need?

Options:

A.  

Associate the applications directly with the IdP used to authenticate the users; choose any for the destination in the policy rule.

B.  

Apply the same tag to the applications; select the tag as a destination in the policy rule.

C.  

Place all the applications in the same connector zone; select that zone as a destination in the policy rule.

D.  

Select the applications within a non-default web profile; select that profile in the policy rule.

Discussion 0
Questions 45

An AOS-CX switch has been configured to implement UBT to two HPE Aruba Networking gateways that implement VRRP on the users ' VLAN. What correctly describes how the switch tunnels UBT users ' traffic to those gateways?

Options:

A.  

The switch always sends the users ' traffic to the VRRP master.

B.  

The switch always sends all users ' traffic to the primary gateway configured in the UBT zone.

C.  

The switch always load shares the users ' traffic across both gateways.

D.  

The switch always sends all users ' traffic to the gateway assigned as the active device designed gateway.

Discussion 0
Questions 46

A company has AOS-CX switches managed by HPE Aruba Networking Central. The network infrastructure devices authenticate clients to HPE Aruba Networking ClearPass Policy Manager (CPPM), which is integrated with HPE Aruba Networking ClearPass Device Insight (CPDI). You have seen suspicious activity on a client connected to one of the switches. To investigate the client’s activity further, you need to know all of the IP addresses that it has used in the past two weeks.

Where can you find this information collected together?

Options:

A.  

In CPPM’s Device Profiler dashboard

B.  

In HPE Aruba Networking Central’s Audit Trail for the client’s switch

C.  

In the logs stored on the client’s switch

D.  

In CPDI’s History tab for the client

Discussion 0