Summer Special Flat 65% Limited Time Discount offer - Ends in 0d 00h 00m 00s - Coupon code: suredis

HP HPE7-A01 Aruba Certified Campus Access Professional Exam Exam Practice Test

Demo: 40 questions
Total 139 questions

Aruba Certified Campus Access Professional Exam Questions and Answers

Question 1

Match the topics of an AOS10 Tunneled mode setup between an AP and a Gateway. (Options may be used more than once or not at all.)

Options:

Question 2

How do you allow a new VLAN 100 between VSX pair inter-switch-link 256 for port 1/45 and 2/45?

Options:

A.

vlan trunk allowed 100 for ports 1/45 and 1/46

B.

vlan trunk add 100 in LAG256

C.

vlan trunk allowed 100 in LAG256

D.

vlan trunk add 100 in MLAG256

Question 3

A customer has a large number of food-producing machines

• All machines are connected via Aruba CX6200 switches in VLANs 100.110. and 120

• Several external technicians are maintaining this special equipment

What are the correct commands to ensure that no rogue DHCP server will impact the network?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 4

A company deployed Dynamic Segmentation with their CX switches and Gateways After performing a security audit on their network, they discovered that the tunnels built between the CX switch and the Aruba Gateway are not encrypted. The company is concerned that bad actors could try to insert spoofed messages on the Gateway to disrupt communications or obtain information about the network.

Which action must the administrator perform to address this situation?

Options:

A.

Enable Secure Mode Enhanced

B.

Enable Enhanced security

C.

Enable Enhanced PAPI security

D.

Enable GRE security

Question 5

With Aruba CX 6300. how do you configure ip address 10 10 10 1 for the interface in default state for interface 1/1/1?

Options:

A.

int 1/1/1. switching, ip address 10 10 10 1/24

B.

int 1/1/1. no switching, ip address 10 10 10.1/24

C.

int 1/1/1. ip address 10.10.10.1/24

D.

int 1/1/1. routing, ip address 10.10.10 1/24

Question 6

Refer to the exhibit.

A company has deployed 200 AP-635 access points. To but is not working as expected

What would be the correct action to fix the issue?

Options:

A.

Change the SSID to WPA3-Enhanced Open

B.

Change the SSID to WPA3-Enterprise (CCM).

C.

Change the SSID to WPA3-Personal

D.

Change the SSID to WPA3-Enterpnse (CNSA).

Question 7

For the Aruba CX 6400 switch, what does virtual output queueing (VOQ) implement that is different from most typical campus switches?

Options:

A.

large ingress packet buffers

B.

large egress packet buffers

C.

per port ASICs

D.

VSX

Question 8

A customer wants to deploy a Gateway and take advantage of all the SD-WAN features. Which persona role option should be selected?

Options:

A.

ArubaOS 10 Branch

B.

ArubaOS 10 VPN Concentrator

C.

ArubaOS 10 Wireless

D.

ArubaOS 10 Mobility

Question 9

A customer has several hundred wireless loT devices and is looking for an authentication solution that meets the following requirements:

Which solutions will address the customer's requirements? (Select two.)

Options:

A.

Local User Derivation Rules

B.

MPSK Local with MAC Authentication

C.

MPSK and an internal RADIUS server

D.

MPSK Local with EAP-TLS

E.

HPE Aruba Networking ClearPass Policy Manager

Question 10

Which component is used by the Aruba Network Analytics Engine (NAE)?

Options:

A.

JSON-based scripts

B.

Lisp-based agents

C.

Ruby-based scripts

D.

Current State Database

Question 11

A company is in the planning stages to migrate to all their wireless domain laptops from WPA2 from WPA2 EAP-PEAP to EAP-TLS with machine Authentication. The administrator is testing a new Group Policy (GPO) that was pushed to only a few windows domain Laptops. The policy will configure the wireless profile to perform machine and certificate-based authentication.

To support this new initiative the administrator also configured a new HPE Aruba Networking ClearPass 802.1X wireless service that only allows devices that successfully perform machine and certificate-based authentication. After successfully pushing the GPO, the Windows laptops are unable to join the configured ‘’secure_wireless’’ SSID as shown below.

Which configuration setting would resolve this issue?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 12

What is one advantage of using OCSP vs CRLs for certificate validation?

Options:

A.

reduces latency between the time a certificate is revoked and validation reflects this status

B.

less complex to implement

C.

higher availability for certificate validation

D.

supports longer certificate validity periods

Question 13

Which statements are true regarding a VXLAN implementation on Aruba Switches? (Select two.)

Options:

A.

MTU size must be increased beyond the default

B.

VNIs encapsulate and decapsulate VXLAN traffic

C.

VTEPs encapsulate and decapsulate VXLAN traffic

D.

They are only available for datacenter switches (CX 8k, 9k,10k)

E.

All Aruba CX switches support VXLAN.

Question 14

Your customer has four (4) Aruba 7200 Series Gateways and two (2) 7000 Series Gateways. The customer wants to form a cluster with these Gateways. What design consideration would prevent you from using all of those Gateways?

Options:

A.

Multiple versions between Gateways in the same cluster profile are not allowed AOS 10.x.

B.

A heterogeneous cluster is not supported in AOS 10.x.

C.

The AP load should be lowest value of worst-case scenario load.

D.

A combination of 7200 series and 7000 series gateways supports up to 4 nodes

Question 15

You are setting up a customer's 15 headless loT devices that do not support 802.1X. What should you use?

Options:

A.

Multiple Pre-Shared Keys (MPSK) Local

B.

Clearpass with WPA3-PSK

C.

Clearpass with WPA3-AES

D.

Multiple Pre-Shared Keys (MPSK) with WPA3-AES

Question 16

A client is connecting to 802.1X SSID that has been configured in tunnel mode with the default AP-group settings.

After receiving Access-Accept from the RADIUS server, the Aruba Gateway will send Access-Accept to the AP through which tunnel?

Options:

A.

IPsec tunnel

B.

Split tunnel

C.

GRE tunnel

D.

PAR tunnel

Question 17

With the Aruba CX switch configuration, what is the first-hop protocol feature that is used for VSX L3 gateway as per Aruba recommendation?

Options:

A.

Active Gateway

B.

Active-Active VRRP

C.

SVI with vsx-sync

D.

VRRP

Question 18

A company with 10,281 employees recently deployed new HPE Aruba Networking Access Points at different branch offices. Wireless 802.IX authentication will be against a RADIUS server in the cloud. The security team is concerned that the traffic between the AP and the RADIUS server will be exposed.

What is the appropriate solution for this scenario?

Options:

A.

Enable IPSec under Data Handling in HPE Aruba Networking Central

B.

Configure RedSec on the AP and the RADIUS server.

C.

Enable EAP-TLS on all wireless devices. Enable EAP-TTLS on all wireless devices.

Question 19

Which feature allows the device to remain operational when a remote link failure occurs between a Gateway cluster and a RADIUS server that is either in the cloud or a datacenter?

Options:

A.

MAC caching

B.

MAC Authentication

C.

Authentication survivability

D.

Opportunistic key caching

Question 20

Refer to the exhibit.

In the Core-2 configuration of spanning-tree instance 2 priority 0, what needs to be configured to enable the root for VLAN 20 while VLAN 10 remains root on Core-1?

Options:

A.

Spanning-tree instance 2 VLAN 20

B.

Spanning-tree priority 0 VLAN 20

C.

Spanning-tree priority root VLAN 20

D.

Spanning-tree VLAN 20

Question 21

Your customer has asked you to assign a switch management role for a new user The customer requires the user role to only have Web Ul access to the System > Log page and only have access to the GET method for REST API for the /logs/event resource

Which default AOS-CX user role meets these requirements?

Options:

A.

administrators

B.

auditors

C.

sysops

D.

operators

Question 22

Match the solution components of HPE Aruba Networking Central NetConductor (Options may be used more than once or not at all.)

Options:

Question 23

You need to drop excessive broadcast traffic on an ingress port or an ArubaOS-CX switch. What is the best feature to use for this task?

Options:

A.

DWRR queuing

B.

Strict queuing

C.

Rate limiting

D.

QoS shaping

Question 24

Which network components communicate using the RADIUS protocol for authentication and accounting?

Options:

A.

an access point and the endpoint device

B.

a Network Access Server and a RADIUS authentication server

C.

an endpoint device and a RADIUS authentication server

D.

a Network Access Server and an endpoint device

Question 25

Refer to the exhibit.

With Core-1. what is the default value for config-revision?

Options:

A.

0

B.

1

C.

1-0

D.

0. 0

Question 26

Which standard supported by some HPE Aruba Networking APs can enable a customer to accurately locate wireless client devices within a few meters?

Options:

A.

802.1 Imc

B.

807.11ah

C.

802.11be

D.

802.11v

Question 27

A network administrator is troubleshooting some issues guest users are having when connecting and authenticating to the network The access switches are AOS-CX switches.

What command should the administrator use to examine information on which role the guest user has been assigned?

Options:

A.

show aaa authentication port-access interface all client-status

B.

show port-access captiveportal profile

C.

show port-access role

D.

diag-dump captiveportal client verbose

Question 28

You are troubleshooting an issue with a pair of Aruba CX 8360 switches configured with VSX Each switch has multiple VRFs. You need to find the IP address of a particular client device with a known MAC address You run the "show arp" command on the primary switch in the pair but do not find a matching entry for the client MAC address.

The client device is connected to an Aruba CX 6100 switch by VSX LAG.

Which action can be used to find the IP address successfully?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 29

In AOS 10. which session-based ACL below will only allow ping from any wired station to wireless clients but will not allow ping from wireless clients to wired stations"? The wired host ingress traffic arrives on a trusted port.

Options:

A.

ip access-list session pingFromWired any user any permit

B.

ip access-list session pingFromWired user any svc-icmp deny any any svc-icmp permit

C.

ip access-list session pingFromWired any any svc-icmp permit user any svc-icmp deny

D.

ip access-list session pingFromWired any any svc-icmp deny any user svc-icmp permit

Question 30

By default, Best Effort is higher priority than which priority traffic type?

Options:

A.

All queues

B.

Background

C.

Internet Control

D.

Network Control

Question 31

You need to have different routing-table requirements with Aruba CX 6300 VSF configuration

Assuming the correct layer-2 VLAN already exists how would you create a new OSPF configuration for a separate routing table?

Options:

A.

Create a new OSPF area, and attach VRF name.

B.

Create a new OSPF process ID with vrf name.

C.

Attach a new OSFP process ID with a custom routing table

D.

Attach OSPF process ID in the VRF configuration.

Question 32

Match the topics with the underlying technologies (Options may be used more than once or not at all.)

Options:

Question 33

Using Aruba best practices what should be enabled for visitor networks where encryption is needed but authentication is not required?

Options:

A.

Wi-Fi Protected Access 3 Enterprise

B.

Opportunistic Wireless Encryption

C.

Wired Equivalent Privacy

D.

Open Network Access

Question 34

What is the best practice for handling voice traffic with dynamic segmentation on AOS-CX switches?

Options:

A.

Switch authentication and local forwarding of the voice traffic

B.

Switch authentication and user-based tunneling of the voice traffic.

C.

Central authentication and port-based tunneling of the voice traffic.

D.

Controller authentication and port-based tunneling of all traffic

Question 35

When setting up an Aruba CX VSX pair, which information does the Inter-Switch Link Protocol configuration use in the configuration created?

Options:

A.

hello interval is disabled by default

B.

hello interval is based on the value set by dead interval

C.

hello interval 100ms by default

D.

hello interval is 1s by default

Question 36

Which statements are true regarding a VXLAN Implementation on HPE Aruba Networking switches? (Select two.)

Options:

A.

They are only available for datacenter switches (CX 8k, 9k, 10k).

B.

VNIs encapsulate and decapsulate VXLAN traffic.

C.

MTU size must be increased beyond the default.

D.

All AOS-CX switches support VXLAN.

E.

VTEPs encapsulate and decapsulate VXLAN traffic.

Question 37

AppRF 2.0 allows you to:

Options:

A.

configure ACL and bandwidth control for applications

B.

classify web content based on reputation

C.

customize application signatures

D.

monitor applications and radio frequencies

Question 38

On AOS10 Gateways, which device persona is only available when configuring a Gateway-only group'?

Options:

A.

Edge

B.

Mobility

C.

Branch

D.

VPN Concentrator

Question 39

Your customer currently has two (2) 5406 modular switches with MSTP configured as their core switches. You are proposing a new solution. What would you explain regarding the AOS-CX VSX switch pair when the Spanning-tree needs to be set up?

Options:

A.

Use vsx-sync in the MSTP region configuration to get synced.

B.

Enable vsx-sync stp-global in vsx mode to sync the configuration.

C.

Spanning-tree configuration is synced by default with VSX.

D.

Enable vsx-peer stp-global in vsx mode to sync the configuration.

Question 40

You are building a configuration in Central that will be used for a standardized network design for small sites for your company, you want to use GUI configuration for gateways and Aps, while template configuration for switches. You need to align with Aruba best practices.

Which set of actions will satisfy these requirements?

Options:

A.

Create one group in Central for switches a second group for APs. and a third group for gateways Create a unique site for each location, and assign devices to the appropriate site.

B.

Create one group in Central for switches and a second group for APs and gateways. Create a unique site for each location, and assign devices to the appropriate site.

C.

Create a single group in Central. Create a unique site for each location, and assign devices to the appropriate site.

D.

Create a single group in Central. Create a unique site for each type of device, and assign devices to the appropriate site.

Demo: 40 questions
Total 139 questions