Blog

  • HPE7-A01

    /70

    HPE07-01

    HPE07-01

    1 / 70

    In AOS 10. which session-based ACL below will only allow ping from any wired station to wireless clients but will not allow ping from wireless clients to wired stations”? The wired host ingress traffic arrives on a trusted port.

    2 / 70

    Your customer is interested in hearing more about how roles can help keep consistent policy enforcement in a distributed overlay fabric How would you explain this concept to them?

    3 / 70

    You are working on a network where the customer has a dedicated router with redundant Internet connections Tor outbound high-importance real-time audio streams from their datacenter All of this traffic.
    • originates from a single subnet
    • uses a unique range of UDP ports
    • is required to be routed to the dedicated router
    All other traffic should route normally The SVI for the subnet containing the servers originating the traffic is located on the core routing switch in the datacenter What should be configured?

    4 / 70

    A system engineer needs to preconfigure several Aruba CX 6300 switches that will be sent to a
    remote office An untrained local field technician will do the rollout of the switches and the mounting
    of several AP-515s and AP-575S. Cables running to theAPs are not labeled.
    The VLANs are already preconfigured to VLAN 100 (mgmt), VLAN 200 (clients), and VLAN 300 (guests)
    What is the correct configuration to ensure that APs will work properly?

    A)

    B)

    C)

    D)

    5 / 70

    With Aruba CX 6300. How do you configure ip address 10.10.10.1 for the interface in default state for interface 1/1/1?

    6 / 70

    With the Aruba CX switch configuration, what is the Active Gateway feature that is used for and is unique to VSX configuration?

    7 / 70

    Refer to the exhibit

    With Core-1. what is the default value for config-revision?

    8 / 70

    What is an Aruba-recommended best practice for hardening that only applies to Aruba CX 6300 series switches with dedicated management ports?

    9 / 70

    What is an OSPF transit network?

    10 / 70

    A customer just upgraded aggregation layer switches and noticed traffic dropping for 120 seconds after the aggregation layer came online again. What is the best way to avoid having this traffic dropped given the topology below?

     

    11 / 70

    You need to create a keepalive network between two Aruba CX 8325 switches for VSX configuration. How should you establish the keepalive connection?

    12 / 70

    The customer needs a network hardware refresh to replace an aging Aruba 5406R core switch pair using spanning tree configuration with Aruba CX 8360-32YC switches What is the benefit of VSX clustering with the new solution?

    13 / 70

    You must ensure the HPE Aruba network you are configuring for a client is capable of plug-and-play provisioning of access points. What enables this capability?

    14 / 70

    A customer wants to deploy a Gateway and take advantage of all the SD-WAN features. Which persona role option should be selected?

    15 / 70

    Your Director of Security asks you to assign AOS-CX switch management roles to new employees based on their specific job requirements After the configuration was complete, it was noted that a user assigned with the administrators role did not have the appropriate level of access on the switch.
    The user was not limited to viewing nonsensitive configuration information and a level of 1 was not assigned to their role Which default management role should have been assigned for the user?

    16 / 70

    A network administrator is troubleshooting some issues guest users are having when connecting and authenticating to the network The access switches are AOS-CX switches. What command should the administrator use to examine information on which role the guest user has been assigned?

    17 / 70

    Which statements regarding Aruba NAE agents are true? (Select two )

    18 / 70

    your customer has asked you to assign a switch management role for a new user The customer requires the user role to View switch configuration information and have access to the PUT and POST methods for REST API.
    Which default AOS-CX user role meets these requirements?

    19 / 70

    On AOS10 Gateways, which device persona is only available when configuring a Gateway-only group?

    20 / 70

    Due to a shipping error, five (5) Aruba AP-515S and one (1) Aruba CX 6300 were sent directly to your new branch office You have configured a new group persona for the new branch office devices in Central, but you do not know their MAC addresses or serial numbers The office manager is instructed via text message on their smartphone to onboard all the new hardware into Aruba Central
    What application must the office manager use on their phone to complete this task?

    21 / 70

    Your Director of Security asks you to assign AOS-CX switch management roles to new employees based on their specific job requirements. After the configuration was complete, it was noted that a user assigned with the auditors role did not have the appropriate level of access on the switch. The user was not allowed to perform firmware upgrades and a privilege level of 15 was not assigned to their role. Which default management role should have been assigned for the user?

    22 / 70

    Which component is used by the Aruba Network Analytics Engine (NAE)?

    23 / 70

    A customer wants to provide wired security as close to the source as possible The wired security must meet the following requirements:

    -allow ping from the IT management VLAN to the user VLAN
    -deny ping sourcing from the user VLAN to the IT management VLAN

    The customer is using Aruba CX 6300s
    What is the correct way to implement these requirements?

    24 / 70

    A company recently deployed new Aruba Access Points at different branch offices Wireless 802.1X authentication will be against a RADIUS server in the cloud. The security team is concerned that the traffic between the AP and the RADIUS server will be exposed.
    What is the appropriate solution for this scenario?

    25 / 70

    What is used to retrieve data stored in a Management Information Base (MIS)?

    26 / 70

    Your customer is having connectivity issues with a newly-deployed Microbranch group The access points in this group are online in Aruba Central, but no VPN tunnels are forming.

    What is the most likely cause of this issue?

    27 / 70

    you are implementing ClearPass Policy Manager with EAP-TLS for authenticating all corporate-owned devices. What are two possible solutions to the problem of deploying client certificates to corporate MacBooks that are joined to a Windows domain? (Select two.)

    28 / 70

    A company deployed Dynamic Segmentation with their CX switches and Gateways After performing a security audit on their network, they discovered that the tunnels built between the CX switch and the Aruba Gateway are not encrypted. The company is concerned that bad actors could try to insert spoofed messages on the Gateway to disrupt communications or obtain information about the network.

    Which action must the administrator perform to address this situation?

    29 / 70

    What is one advantage of using OCSP vs CRLs for certificate validation?

    30 / 70

    What is enabled by LLDP-MED? (Select two.)

    31 / 70

    A customer is using a legacy application that communicates at layer-2. The customer would like to keep this application working across the campus which is connected via layer-3. The legacy devices are connected to Aruba CX 6300 switches throughout the campus.

    Which technology minimizes flooding so the legacy application can work efficiently?

    32 / 70

    Refer to Exhibit

    With Access-1, What needs to be identically configured With MSTP to load-balance VLANS?

    33 / 70

    You are deploying Aruba CX 6300’s with the customers requirement to only allow one (1) VoIP phone and one (1) device.
    The following local role gets assigned to the phone port-access rote VoIP device-traffic-class voice. What set of commands best fits this requirement?

    34 / 70

    You are configuring an SVI on an Aruba CX switch that needs to have the following characteristics:

    • VLANID = 25
    • IPv4 address 10 105 43 1 with mask 255 255 255.0
    • IPv6 address fd00:5708::f02d:4df6 with a 64 bit prefix length
    • member of VRF eng
    • VRF eng and VLAN 25 have not yet been created

    Which command lists will satisfy the requirements with the least number of commands?

    A)

    B)

    C)

    D)

    35 / 70

    Which statements are true about VSX LAG? (Select two.)

    36 / 70

    With the Aruba CX switch configuration, what is the Active Gateway feature that is used for and is unique to VSX configuration?

    37 / 70

    With the Aruba CX 6100 48G switch with uplinks of 1/1/47 and 1/1/48. how do you automate the process of resuming the port operational state once a loop on a client port is cleared?

    38 / 70

    Which statement best describes QoS?

    39 / 70

    When configuring UBT on a switch what will happen when a gateway role is not specified?

    40 / 70

    A network administrator is attempting to troubleshoot a connectivity issue between a group of users and a particular server The administrator needs to examine the packets over a period of time from their desktop; however, the administrator is not directly connected to the AOS-CX switch involved with the traffic flow.
    What statements are correct regarding the ERSPAN session that needs to be established on an AOS-
    CX switch’? (Select two )

    41 / 70

    When setting up an Aruba CX VSX pair, which information does the Inter-Switch Link Protocol configuration use in the configuration created?

    42 / 70

    For the Aruba CX 6400 switch, what does virtual output queueing (VOQ) implement that is different from most typical campus switches?

    43 / 70

    A customer is concerned about me unprotected traffic between an AOS-CX switch and a gateway, running on AOS 10. What is a feasible option to protect this traffic?

    44 / 70

    You are helping an onsite network technician bring up an Aruba 9004 gateway with ZTP for a branch office The technician was to plug in any port for the ZTP process to start Thirty minutes after the gateway was plugged in new users started to complain they were no longer able to get to the internet. One user who reported the issue stated their IP address is 172.16 0.81 However, the branch office network is supposed to be on 10.231.81.0/24.
    What should the technician do to alleviate the issue and get the ZTP process started correctly?

    45 / 70

    Two AOS-CX switches are configured with VSX at the the Access-Aggregation layer where servers attach to them An SVI interface is configured for VLAN 10 and serves as the default gateway for VLAN10. The ISL link between the switches fails, but the keepalive interface functions. Active gateway has been configured on the VSX switches.

    What is correct about access from the servers to the Core? (Select two.)

    46 / 70

    A customer is using stacked Aruba CX 6200 and CX 6300 switches for access and a VSX pair of Aruba CX 8325 as a collapsed core 802 1X is implemented for authentication. Due to the lack of cabling, some unmanaged switches are still in use Sometimes devices behind these switches cause network outages The switch should send a warning to the Helpdesk when the problem occurs You have been asked to implement an effective solution to the problem-
    What is the solution for this?

    47 / 70

    Your customer currently has Two (2) 5406 modular switches with MSTP configured as their core switches. You are proposing a new solution. What would you explain regarding the Aruba CX VSX switch pair when the Primary VSX node is replaced and the system MAC is replaced?

    48 / 70

    You need to have different routing-table requirements With Aruba CX 6300 VSF configuration. Assuming the correct layer-2 VLAN already exists, how would you create a new SVI for a separate routing table?

    49 / 70

    A network engineer recently identified that a wired device connected to a CX Switch is misbehaving on the network To address this issue, a new ClearPass policy has been put in place to prevent this device from connecting to the network again. Which steps need to be implemented to allow ClearPass to perform a CoA and change the access for this wired device?
    (Select two.)

    50 / 70

    What is the best practice for handling voice traffic with dynamic segmentation on AOS-CX switches?

    51 / 70

    Which Aruba AP mode is sending captured RF data to Aruba Central for waterfall plot?

    52 / 70

    A large retail client is looking to generate a rich set of contextual data based on the location information of wireless clients in their stores Which standard uses Round Trip Time (RTT) and Fine Time Measurements (FTM) to calculate the distance a client is from an AP?

    53 / 70

    Your manufacturing client is having installers deploy seventy headless scanners and fifty IP cameras in their warehouse These new devices do not support 802 1X authentication. How can HPE Aruba reduce the IT administration overhead associated with this deployment while maintaining a secure environment using MPSK?

    54 / 70

    How is Dynamic Multicast Optimization (DMO) implemented in an HPE Aruba wireless network?

    55 / 70

    You are setting up a customer’s 15 headless loT devices that do not support 802.1X. What should you use?

    56 / 70

    What are the requirements to ensure that WMM is working effectively’? (Select two)

    57 / 70

    What is a primary benefit of BSS coloring?

    58 / 70

    A new network design is being considered to minimize client latency in a high-density environment. The design needs to do this by eliminating contention overhead by dedicating subcarriers to clients.
    Which technology is the best match for this use case?

    59 / 70

    Which feature allows the device to remain operational when a remote link failure occurs between a Gateway cluster and a RADIUS server that is either in the cloud or a datacenter?

    60 / 70

    What is a primary benefit of BSS coloring?

    61 / 70

    A customer has a site with 200 AP-515 access points 75AP-565 access points installed. The customer is rolling out new mobile phones with Wi-Fi-calling. 802.1X is in use for authentication What should be enabled to ensure the best roaming experience?

    62 / 70

    For an Aruba AOS-10 AP in mixed mode, which factors can be used to determine the forwarding role assigned to a client? (Select two.)

    63 / 70

    Refer to the image

    Your customer is complaining of weak Wi-Fi coverage in their office. They mention that the office on the other side of the hall has much better signal What is the likely cause of this issue?

    64 / 70

    You are deploying a bonded 40 MHz wide channel What is the difference in the noise floor perceived by a client using this bonded channel as compared to an unbonded 20MHz wide channel?

    65 / 70

    You are are doing tests in your lab and with the following equipment specifications:
    • AP1 has a radio that generates a 16 dBm signal.
    • AP2 has a radio that generates a 13 dBm signal.
    • AP1 has an antenna with a gain of 8 dBi.
    • AP2 has an antenna with a gain of 12 dBi. The antenna cable for AP1 has a 4 dB loss. The
    antenna cable for AP2 has a 3 dB loss.
    What would be the calculated Equivalent Isotropic Radiated Power (EIRP) for AP1?

    66 / 70

    Using Aruba best practices what should be enabled for visitor networks where encryption is needed but authentication is not required?

    67 / 70

    Refer to Exhibit

     

    A company has deployed 200 AP-635 access points. To take advantage of the 6 GHz band, the administrator has attempted to configure a new WPA3-OWE SSID in Central but is not working as expected.
    What would be the correct action to fix the issue?

    68 / 70

    Your customer is having issues with Wi-Fi 6 clients staying connected to poor-performing APs when a higher throughput APs are closer. Which technology should you implement?

    69 / 70

    A customer is looking for a wireless authentication solution for all of their loT devices that meet the following requirements
    – The wireless traffic between the IoT devices and the Access Points must be encrypted
    – Unique passphrase per device
    – Use fingerprint information to perform role-based access
    Which solutions will address the customer’s requirements? (Select two.)

    70 / 70

    You are doing tests in your lab and with the following equipment specifications:
    • AP1 has a radio that generates a 20 dBm signal
    • AP2 has a radio that generates a 8 dBm signal
    • AP1 has an antenna with a gain of 7 dBI.
    • AP2 has an antenna with a gain of 12 dBI.
    • The antenna cable for AP1 has a 3 dB loss
    • The antenna cable forAP2 has a 3 dB loss.
    What would be the calculated Equivalent Isotropic Radiated Power (EIRP) for AP1?

    Your score is

    The average score is 27%

    0%