Big Cyber Monday Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

HP HPE7-A07 Aruba Certified Campus Access Mobility Expert Written Exam Exam Practice Test

Demo: 32 questions
Total 126 questions

Aruba Certified Campus Access Mobility Expert Written Exam Questions and Answers

Question 1

Exhibit.

You updated your gateway to me most recent firmware However after the firmware was updated, the gateway could no longer connect to HPE Aruba Networking Central. Your corporate ITIL procedures require you to implement your backout plan. You connected a console cable to your gateway and saw the following prompt.

Cpxload#

in what order, do you need to execute the following commands to return to the previous firmware version?

Options:

Question 2

A customer would like to allow their IT Helpdesk to configure loT devices to connect lo a single SSID using a unique PSK that other devices cannot use. Which solution would you recommend?

Options:

A.

MPSK AES with MAC Auth

B.

MPSK Local

C.

MPSK AES with Cloud Auth

D.

MPSK AES with ClearPass

Question 3

A customer deployed AP-535s for IoT devices that send many small packets. They want to reduce congestion and allow simultaneous transmission to or from multiple users.

Options:

A.

UL MU-MIMO

B.

DL MU-MIMO

C.

HE TXBF

D.

OFDMA

Question 4

In a campus topology using VSX with two aggregation switches and downlinks to access switches, which LAG interface configuration at the aggregation layer is correct based on the parameters below?

    ZTP VLAN 1001

    access switch MGMT VLAN 2002

    access switch MGMT VLAN is tagged

    connectivity to the access switch should be maintained before and after the ZTP operation is complete

Options:

A.

B.

C.

D.

Question 5

A network administrator accesses HPE Aruba Networking Central and notices that visitors consume too much internet bandwidth starving employee traffic when accessing an external service. Therefore, the administrator wants to limit wireless bandwidth to 60 Mops in both directions among all users in the voice rote and no more than 10 Mops in both directions for YouTube traffic. Deep packet inspection, web content classification, and firewall visibility are enabled.

Which configurations are required to accomplish this task? (Select two.)

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 6

The wireless administrator for a college campus is gelling reports of connectivity issues when students are working outdoors.

Reviewing the settings above, watch change is needed to align with best practices?

Options:

A.

Disable 802 11r.

B.

Disable 802 11k.

C.

increase 5Gnz TX power range Min/Max.

D.

increase 5 GHz wireless coverage tuning to Aggressive.

Question 7

Refer to the exhibit.

You have recently implemented a VoWiFi solution with QoS, but users are experiencing poor call quality during busy periods. Based on the output generated after some test calls, what change should you make to improve call quality?

Options:

A.

reconfigure DSCP mapping

B.

enable WMM for the SSID

C.

disable AirSlice

D.

update ACLs

Question 8

You recently added ClearPass as an authentication server to an HPE Aruba Networking Central group. RADIUS authentication with Local User Roles (LUR) works fine Out the same access points cannot use Downloadable User Roles (DUR).

What should he corrected in this configuration to fa the issue with DUR?

Options:

A.

Add a new Enforcement Policy of type ‘’WEBAUTH’’ on ClearPass and associate it with the matching service on ClearPass

B.

Add the correct IP addresses or IP subnets of the Network Access Devices (NADs) under the "Devices" tab on ClearPass

C.

Replace the AP's expiree digital certificate using the "crypto pki-import pem serverCert" command.

D.

Add the correct values for "CPPM username" and "CPPM Password" m the authentication server configuration on HPE Aruba Networking Central

Question 9

Based on best practices if an SSID is configured Tor a primary and secondary gateway cluster with cluster preemption enabled, which will decide if the APs move to the secondary gateway cluster if all of the nodes in the primary gateway cluster are down?

Options:

A.

tunnel orchestrator for LAN tunnel service in HPE Aruba Networking Central

B.

every AP individually

C.

cluster leader in the primary gateway cluster

D.

cluster leader in the secondary gateway cluster

Question 10

A customer has deployed an AOS 10 mobility gateway cluster consisting of three controllers at a single site The WLAN is configured to tunnel wireless device traffic to the AOS 10 mobility cluster. The clients are authorized to use WPA2-Personal. An end-user has opened a ticket with the helpdesk stating they cannot connect their client device to the network. There are other devices currently associated with the SSID with no issues.

Reviewing the output, what Is the issue?

Options:

A.

The RADIUS response from the authentication server is

B.

The client device has an invalid certificate

C.

The client device has an invalid pre-shared key.

D.

transition mode is not enabled

Question 11

Exhibit.

Which statement is true?

Options:

A.

The SSID supports HR-DSSS data rates

B.

The SSID is supports 6 GHz clients.

C.

The SSID supports 802 11ax clients.

D.

The SSID supports 802 11ac clients.

Question 12

Based on the output above, what is required to associate the GBP policy with a user role?

Options:

A.

Configure a user role called GBP-EMPLOYEE instead of EMPLOYEE

B.

Associate the port-access role to the GBP role using the role ID

C.

Update the port-access GBP policies to reference the EMPLOYEE role

D.

Update the entries in the class maps to reference the EMPLOYEE role

Question 13

Refer to the exhibit.

To which devices has AP-1 established tunnels?

Options:

A.

A pair of gateways within a cluster

B.

A pair of switches running VXLAN

C.

A single gateway within a cluster

D.

A pair of standalone gateways

Question 14

What should be defined on the Edge-1 to establish valid BGP routing between agg-sw1 and agg-sw2 using BGP protocol using the IP addresses above?

Options:

A.

OPTION A

B.

OPTION B

C.

OPTION C

D.

OPTION D

Question 15

A deployment using AP-635S is connected to a stack of CX 6300s as shown.

The output of the snow LACP interfaces shews the following:

What is causing this issue?

Options:

A.

e0 is connected to a smart rate interface, and e1 is connected to a non-smart rate interface.

B.

Spanning tree and loop protect are enabled on both AP uplink ports.

C.

Each AP interface is connected to a routed-only interlace on different networks

D.

The AP is configured with LACP active

Question 16

The output of the show LACP interfaces shows the following:

What is causing this issue?

Options:

A.

The AP is configured with LACP active.

B.

Each AP interface is connected to a routed-only interface on different networks.

C.

Spanning tree and loop protect are enabled on both AP uplink ports.

D.

e0 is connected to a smart rate interface, and e is connected to a non-smart rate interface.

Question 17

An existing AOS-10 wireless deployment is expanding its zero-trust wireless network to multiple locations. The requirement is to propagate role information to enforce group-based policies for wireless client traffic across all locations.

To achieve this goal, which must be configured in this infrastructure?

Options:

A.

Configure the gateways to mobility type and configure the Roles under System → Client Roles in HPE Aruba Networking Central

B.

Configure "use switch fabric for role propagation" under Security → Client Roles in HPE Aruba Networking Central

C.

Overlay campus switch fabric with CX switches

D.

Tunneled SSIDs with gateways

Question 18

Your customer asked for help to apply an ACL for wireless guest users with the following criteria:

• Wi-Fi guests are on VLAN 555

• allow internet access

• only allow access to public DNS servers

• deny access to all internal networks except for any DHCP server

These session ACLs are already present in the CLI of the mobility gateway group:

You have access to the CLl. Which user role meets all the criteria?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 19

A customer with a gateway connected to a device on gigabitethernet 0/0/3 configures an Asset ID TLV on the device for inventory management.

Refer to the exhibit.

The customer mentions the Asset ID is not shown. What is causing the issue?

Options:

A.

MTU size is too small.

B.

Unknown TLVs cannot be displayed.

C.

LLDP-MED needs to be enabled.

D.

LLDP TX is not enabled.

Question 20

A customer is running out of IP addresses in a network segment. What will happen if they add an additional IP subnet to the same VLAN?

Options:

A.

This would result in a single SVI using two subinterfaces

B.

Users can reach each other and establish PTP traffic without passing an L3 point in the same VLAN

C.

Broadcasts for the two subnets will arrive on all ports in the same VLAN

D.

IGMP will not work in both of the subnets in the same VLAN

Question 21

Your customer’s employees connected to a wired network are complaining about a poor user experience. The customer has UXI sensors deployed on their premises. These sensors nave been running for multiple months. They are testing both the wired network (using the wired Interface of each sensor) and the wireless networks. Your customer used the UXI dashboard to find the reason for the poor user experience to find more details, the customer asked you to check the packet captures that have been downloaded from the sensors using the UXI dashboard.

From the zip file downloaded from the UXI sensors, you checked the "datagrams" .pcap file, but you were not able to find any issues How can you explain this?

Options:

A.

The "datagrams- pcap file only contains me successful tests Failed tests are contained in the "datagrams-failed" .pcap file

B.

The UXI sensor could not upload the latest test results to the cloud, so the packet capture is outdated

C.

The datagrams captured on the physical Ethernet interface are in a different .pcap file.

D.

The default filers of the packet captures do not allow tailed tests to be captured by the sensor

Question 22

You are troubleshooting a WLAN deployment with APs and gateways set up with an 802.1X tunneled SSIO. End-users are complaining that they can’t connect to die enterprise SSID. Which possible AP tunnel states could be the cause of the Issue? (Select two.)

Options:

A.

SM_STATE_RE KEYING

B.

SM_STATE_SURVIVED

C.

SM_STATE_CONNECTED

D.

SM_STATE_SURVIVING

E.

SM_STATE_CONNECTING

Question 23

Exhibit.

Which would explain this issue?

Options:

A.

HTTPS wildcard certificates are not supported

B.

HTTPS certificate is not required in ClearPass Guest.

C.

captiveportal-login aruba-training com needs to be entered m the Address field for the ClearPass Guest

D.

".aruba-training com needs to be entered in the Address field for the ClearPass Guest

Question 24

A client connecting to a tunneled open network is receiving the wrong VLAN Your customer has a gateway and has sent over a packet capture from a switch port mirror taken from the upstream switch with a packet capture from the IPsec tunnel and the GRE tunnel to help Identify the VLAN being sent from the controller to the AP.

Where will you see the VLAN assignment?

Options:

A.

The GRE tunnel will include the VLAN lag assignment

B.

VLAN tag assignment win not he captured in any of the packet captures

C.

IPsec tunnel will include the VLAN tag assignment

D.

VLAN tag assignment win be included in the port mirror

Question 25

You configured" a bridged mode SSID with WPA3-Enterprise and EAP-TLS security. When you connect an Active Directory joined client that has valid client certificates. ClearPass shows the following error.

What is needed to resolve this issue?

Options:

A.

Enable authorization in your Authentication Method.

B.

Recreate the SSID m tunneled mode.

C.

Modify your ACX-AD authentication source to include the UPN in the search.

D.

Configure ClearPass to trust the client certificate.

Question 26

A customer is evaluating device profiles on a CX 6300 switch. The test device has the following attribute:

• MAC address=81:cd:93:13:ab:31

The test device needs to be assigned the "lot-prod'' role, in addition the "lot-default" role must be applied for any other device connected lo interface 1/1/1. This is a lab environment with no configuration of any external authentication server for the test.

Given the configuration example, what is required to meet this testing requirement?

Options:

A.

Enter the command "pot-access device-profile mode block-until-profile-applied"" for interface 1/1/1.

B.

Enter the command "port-access fallback-role lot-default globally

C.

Enter the command "port-access onboarding-method precedence" to set device profiles with a lower precedence.

D.

Enter the command "port-access device-profile mode block-until-profile-applied" globally.

Question 27

A customer’s infrastructure is set up to use both primary and secondary gateway clusters on the SSID profile based on best practices What is a valid cause tor having an equal spirt in APs connected to the primary and secondary gateway clusters?

Options:

A.

The secondary gateway cluster is heterogeneous

B.

The secondary gateway cluster is homogeneous

C.

The primary gateway cluster is up. out some APs are unable to reach the primary gateway cluster. These APs would connect to the secondary gateway cluster

D.

The primary gateway cluster is up. out some APs cannot reach the secondary gateway cluster. These APs would connect to the secondary gateway cluster

Question 28

A customer has deployed an AOS 10 mobility gateway cluster consisting of three controllers at a single site The WLAN is configured to tunnel wireless device traffic to the AOS 10 mobility cluster The clients are authenticated by ClearPass using WPA3-Enterprise (opmode wpa3-aes-ccm-128). The security team has requested the ability to force a wireless device to reauthenticate using ClearPass.

Which steps are required to ensure ClearPass can consistently initiate a change of authorization against an AOS 10 mobility cluster, including during gateway failover scenarios? (Select two)

Options:

A.

set cluster mode to Auto Site under High Availability - Cluster configuration

B.

modify WLAN - SSID - VLAN - Mode Configuration

C.

enable manual cluster configuration under High Availability - Cluster Configuration

D.

enable Dynamic Authorization CoA under High Availability - Cluster Configuration

E.

modify NAS IPv4 address under Security - Advanced - RADIUS Client

Question 29

Which statement is true given the following CLI output from a CX 6300?

Options:

A.

A wired client with IP address 10.203.1.100 is on a remote CX 6300 in the fabric with loopback IP address 172.21.11.2

B.

There are no active fabric clients on the CX switch with RD 172.16.10.1

C.

A wired client with IP address 10.203.1.100 has a host route that is not being properly advertised

D.

The overlay loopback addresses are advertised in the fabric with 24-bit subnet masks

Question 30

A customer's infrastructure is set up to use both primary and secondary gateway clusters on the SSID profile based on best practices. Why do they have an equal split of their 260 APs across the primary and secondary gateway clusters?

Options:

A.

The primary gateway cluster is up, but some APs cannot reach the secondary gateway cluster. These APs would connect to the secondary gateway cluster

B.

The secondary gateway cluster is homogeneous

C.

The secondary gateway cluster is heterogeneous

D.

The primary gateway cluster is up, but some APs cannot reach the primary gateway cluster. These APs would connect to the secondary gateway cluster

Question 31

A university owns a campus with several buildings segmented into east and west wings, which are L3 separated. The east wing has 1600 APs. and the west wing has 1200 Aps. Each wing has a single gateway cluster managed by HPE Aruba Networking Central. Each cluster contains one 7210 mobility gateway The gateways are configured with DHCP relay and route all client VLANs. A new business-critical faculty real-time application requires users to roam within wings but not across wings without disconnections or delay increments.

Which changes must the network administrator make lo successfully meet the requirement without performance degradation matching best practices? (Select two.)

Options:

A.

Replace the 7210 mobility gateway in the west wing with a pair of 7030 mobility gateways.

B.

Add a single 7210 mobility gateway to each cluster.

C.

Remove the DHCP relay from the gateways and enable the DHCP server instead

D.

Replace me 7210 mobility gateway in the east wing with a pair or 9012 mobility gateways

E.

Run L2 for all SSIDs and permit the users' VLANs in the gateway's uplinks.

Question 32

Exhibit.

After configuring VRRP between sw-1 and SW-2. you notice that both switches are showing as active. What could be the reason for this issue?

Options:

A.

VRRP preemptive mode is disabled.

B.

SW-1 cam reach SW-2 on VLAN 10.

C.

Both switches are configured as VRRP 'primary.'

D.

SW-2 has no priority configurations for VRRP 1.

Demo: 32 questions
Total 126 questions