HPE6-A78 Aruba Certified Network Security Associate Exam

Loading demo links...

Showing 1–3 of 8 questions

Question 1

You have detected a Rogue AP using the Security Dashboard Which two actions should you take in responding to this event? (Select two)

Select all that apply, then click Submit answer.

  • There is no need to locale the AP If you manually contain It.

  • This is a serious security event, so you should always contain the AP immediately regardless of your company's specific policies.

  • You should receive permission before containing an AP. as this action could have legal Implications.

  • For forensic purposes, you should copy out logs with relevant information, such as the time mat the AP was detected and the AP's MAC address.

  • There is no need to locate the AP If the Aruba solution is properly configured to automatically contain it.

Question 2

You configure an ArubaOS-Switch to enforce 802.1X authentication with ClearPass Policy Manager (CPPM) denned as the RADIUS server Clients cannot authenticate You check Aruba ClearPass Access Tracker and cannot find a record of the authentication attempt.

What are two possible problems that have this symptom? (Select two)

Select all that apply, then click Submit answer.

  • users are logging in with the wrong usernames and passwords or invalid certificates.

  • Clients are configured to use a mismatched EAP method from the one In the CPPM service.

  • The RADIUS shared secret does not match between the switch and CPPM.

  • CPPM does not have a network device defined for the switch's IP address.

  • Clients are not configured to trust the root CA certificate for CPPM's RADIUS/EAP certificate.

Question 3

You need to deploy an Aruba instant AP where users can physically reach It. What are two recommended options for enhancing security for management access to the AP? (Select two )

Select all that apply, then click Submit answer.

  • Disable Its console ports

  • Place a Tamper Evident Label (TELS) over its console port

  • Disable the Web Ul.

  • Configure WPA3-Enterpnse security on the AP

  • install a CA-signed certificate