🎄

CertoMetrics - 9% OFF Special Discount Offer - Ends In:

0d 00h 00m 00s
Coupon code: SALE2026

HPE Network Security Expert (HPE7-A10)

Get full access to the updated question bank and confidently prepare for your exam.

Vendor

HPE

Certification

Networking (Data Center)

Content

74 Qs

Status

Verified

Updated

2 hours ago

Test the Practice Engine

Experience our interactive testing environment with free demo questions

Launch Free Demo
Best Value Bundle

Premium Bundle

Complete Success Suite

$83 $49

Save $34 Instantly

  • âś“
    Full PDF + Interactive Engine Everything you need to pass
  • âś“
    All Advanced Question Types Drag & Drop, Hotspots, Case Studies
  • âś“
    Priority 24/7 Expert Support Direct line to certification leads
  • âś“
    90 Days Free Priority Updates Stay current as exams change

Success Metric

98.4% Pass Rate

Verified by 15k+ Students
Secure Checkout
Popular

Standard Simulation

Practice Engine

$44

One-Time Payment

  • Web-Based (Zero Install)
  • Real Testing Environment Virtual & Practice Modes
  • Interactive Engine Drag & Drop, Hotspots
  • 60 Days Free Updates

Compatible with All Devices

Chrome
Verified Secure Checkout

Basic Tier

PDF Study Guide

$39

Digital Access

  • âś“ Exam Questions (PDF)
  • âś“ Mobile Friendly
  • âś“ 60 Days Updates
Download Free Sample PDF

Verified 15-Question Preview (HPE7-A10)

Secure Checkout

Verified Community

The CertoMetrics Standard.

Recommend the #1 platform for verified HPE certification resources.

Success Network

Help a Colleague Succeed.

Invite a peer to get their own updated HPE7-A10 prep kit.

Exam Overview

The HPE Network Security Expert (HPE7-A10) certification validates an individual's advanced proficiency in designing, implementing, and managing robust network security solutions leveraging HPE technologies. In today's dynamic threat landscape, securing critical network infrastructure is paramount. This credential signifies a deep understanding of complex security architectures, threat mitigation strategies, and the ability to deploy sophisticated security controls to protect enterprise assets. Achieving the HPE7-A10 distinguishes IT professionals as trusted advisors capable of addressing advanced security challenges, enhancing their career trajectory, and positioning them as leaders in network security. It demonstrates expertise in safeguarding data, ensuring business continuity, and maintaining compliance in an evolving digital environment.

Questions

60

Passing Score

700/1000

Duration

105 Minutes

Difficulty

Expert

Level

Expert

Skills Measured

Advanced Threat Protection and Prevention: Understanding and implementing next-generation firewall capabilities, intrusion prevention systems (IPS), sandboxing, and data loss prevention (DLP) to counter sophisticated cyber threats.
Secure Network Architecture and Design: Designing highly secure network infrastructures, including VPNs, micro-segmentation, zero-trust principles, and secure access for on-premises and cloud environments, leveraging HPE and partner solutions.
Identity and Access Management (IAM) for Networks: Implementing and managing network access control (NAC), multi-factor authentication (MFA), and secure authentication, authorization, and accounting (AAA) services to ensure secure user and device access.
Security Operations and Incident Response: Knowledge of security information and event management (SIEM) integration, security monitoring, log analysis, and incident response procedures specific to network security events.
HPE Security Portfolio Integration and Management: Expertise in deploying, configuring, and managing HPE Aruba security solutions, integrating with wider HPE GreenLake for Security offerings, and understanding their role in comprehensive enterprise security.

Career Path

Target Roles

Network Security Engineer Cyber Security Architect Senior Security Consultant

Common Questions

Is the material up to date?

Yes. We update our question bank weekly to match the latest HPE standards. You get free updates for 90 days.

What format do I get?

You get instant access to both the **PDF** (for reading) and our **Premium Test Engine** (for exam simulation).

Is there a guarantee?

Absolutely. If you fail the HPE7-A10 exam using our materials, we offer a full money-back guarantee.

When do I get the download?

Instantly. The download link is available in your dashboard immediately after payment is confirmed.

Free Study Guide Samples

Previewing updated HPE7-A10 bank (15 Questions).

QUESTION 1

# Introduction to the customer

You are helping a company add HPE Aruba Networking ClearPass to their network, which uses HPE Aruba Networking network infrastructure devices.

The company currently has a Windows domain and Windows CA. The Window CA issues certificates to domain computers, domain users, and servers such as domain controllers. An example of a certificate issued by the Windows CA is shown here.

# ClearPass cluster IP addressing and hostnames

A customer's ClearPass cluster has these IP addresses:

• Publisher = 10.47.47.5

• Subscriber 1 = 10.47.47.6

• Subscriber 2 = 10.47.47.7

• Virtual IP with Subscriber 1 and Subscriber 2 = 10.47.47.8

The customer's DNS server has these entries

• cp.acnsxtest.com = 10.47.47.5

• cps1.acnsxtest.com = 10.47.47.6

• cps2.acnsxtest.com = 10.47.47.7

• radius.acnsxtest.com = 10.47.47.8

• onboard.acnsxtest.com = 10.47.47.8

Refer to the scenario.

On CPPM, you are creating the authentication source. You have configured the settings shown in the tab and have not altered any other settings.

What else do you need to do to help authentication proceed correctly?

A
Change the Connection Security method to StartTLS.
B
Add a custom attribute to the authentication filter to collect the account's userPrincipalName.
C
Change the authentication filter to query for userPrincipalName as well as sAMAccountName.
D
Add two custom filters that query AD based on TEAP Method 1 Username and TEAP Method 2 Username.

Correct Option: C

To ensure authentication proceeds correctly, the Active Directory authentication source in ClearPass needs to be able to locate user accounts using both sAMAccountName and userPrincipalName. Clients may present either format. Changing the authentication filter to query for both attributes allows ClearPass to find the user regardless of the supplied identity format, which is a crucial step for robust AD integration.



Reference: https://www.arubanetworks.com/techdocs/ClearPass/6.9/PolicyMgr_UG/Content/AuthSources/AD_auth_sources.htm
QUESTION 2

# Introduction to the customer

You are helping a company add HPE Aruba Networking ClearPass to their network, which uses HPE Aruba Networking network infrastructure devices.

The company currently has a Windows domain and Windows CA. The Window CA issues certificates to domain computers, domain users, and servers such as domain controllers. An example of a certificate issued by the Windows CA is shown here.

# ClearPass cluster IP addressing and hostnames

A customer's ClearPass cluster has these IP addresses:

• Publisher = 10.47.47.5

• Subscriber 1 = 10.47.47.6

• Subscriber 2 = 10.47.47.7

• Virtual IP with Subscriber 1 and Subscriber 2 = 10.47.47.8

The customer's DNS server has these entries

• cp.acnsxtest.com = 10.47.47.5

• cps1.acnsxtest.com = 10.47.47.6

• cps2.acnsxtest.com = 10.47.47.7

• radius.acnsxtest.com = 10.47.47.8

• onboard.acnsxtest.com = 10.47.47.8

Refer to the scenario.

A customer has AOS-CX switches with this configuration on their edge ports: port-access onboarding-method concurrent enable aaa authentication port-access mac-auth enable quiet-period 60 aaa authentication port-access dotx1 authenticator enable

The switch authenticates clients to HPE Aruba Networking ClearPass Policy Manager (CPPM) which has these services:

1. An 802.1 X service that uses an EAP-TLS method for most clients

2. A MAC-Auth service that uses the [MAC-Auth] method for devices such as printers imported from an inventory manager

The customer now wants to provide limited access to wired guest devices and new devices that need to be enrolled with certificates. You have set up these rights in an AOS-CX role named "guest-login."

How should you apply the "guest-login" role on the switches?

A
As the role assigned by the default enforcement profile in CPPM's MAC-Auth service
B
As the port-access preauth-role on the edge interfaces
C
As the port-access reject-role on the edge interfaces
D
As the role assigned by the default enforcement profile in CPPM's 802.1X service

Correct Option: B

âś… Option B (Correct)Reasoning: The port-access preauth-role on AOS-CX switches provides initial, limited network access to devices before they successfully authenticate. This allows wired guest devices to reach a captive portal or new devices needing enrollment to access onboarding services (e.g., ClearPass Onboard) without full network access.
❌ Why the other choices are incorrect:

  • Option A is incorrect: Assigning the guest-login role as the default enforcement in the MAC-Auth service would provide guest access to all devices failing 802.1X or intended for MAC-Auth, including printers, which is not the desired behavior for general default access.
  • Option C is incorrect: The port-access reject-role is used to deny all network access upon authentication failure, which contradicts the requirement to provide "limited access" for guests and new devices.
  • Option D is incorrect: The 802.1X service uses EAP-TLS, requiring certificates. New devices needing enrollment won't have one. Making this the default would incorrectly grant guest access to successfully 802.1X authenticated (e.g., employee) devices.



Reference: https://www.arubanetworks.com/techdocs/AOS-CX/10.12/WebUI/Content/switch-config/port-ac-aut/port-access-config.htm
QUESTION 3

# Introduction to the customer

You are helping a company add HPE Aruba Networking ClearPass to their network, which uses HPE Aruba Networking network infrastructure devices.

The company currently has a Windows domain and Windows CA. The Window CA issues certificates to domain computers, domain users, and servers such as domain controllers. An example of a certificate issued by the Windows CA is shown here.

# ClearPass cluster IP addressing and hostnames

A customer's ClearPass cluster has these IP addresses:

• Publisher = 10.47.47.5

• Subscriber 1 = 10.47.47.6

• Subscriber 2 = 10.47.47.7

• Virtual IP with Subscriber 1 and Subscriber 2 = 10.47.47.8

The customer's DNS server has these entries

• cp.acnsxtest.com = 10.47.47.5

• cps1.acnsxtest.com = 10.47.47.6

• cps2.acnsxtest.com = 10.47.47.7

• radius.acnsxtest.com = 10.47.47.8

• onboard.acnsxtest.com = 10.47.47.8

Refer to the scenario.

You need to configure HPE Aruba Networking ClearPass Onboard to issue client certificates for Azure AD joined devices.

Which step is required to achieve this objective?

A
Create an HTTP authentication source that references an Intune extension.
B
Recreate the CA as a registration authority under Azure AD.
C
Create a CPPM policy that authenticates guest users to Azure AD.
D
Install the Intune SCEP extension on the ClearPass subscribers.

Correct Option: A

To configure HPE Aruba Networking ClearPass Onboard to issue client certificates for Azure AD joined devices, ClearPass must integrate with Microsoft Intune. This integration allows ClearPass to query Intune for device status and compliance. An HTTP authentication source configured to reference an Intune extension (or API integration) provides the mechanism for ClearPass to obtain necessary device attributes from Intune for policy evaluation before issuing a certificate via Onboard's SCEP service. This ensures only managed and compliant devices receive certificates.



Reference: https://www.arubanetworks.com/techdocs/ClearPass/6.11/PolicyManager_CPPM_UserGuide_6.11/Content/MDM/AboutMDM_Intune.htm
QUESTION 4

# Introduction to the customer

You are helping a company add HPE Aruba Networking ClearPass to their network, which uses HPE Aruba Networking network infrastructure devices.

The company currently has a Windows domain and Windows CA. The Window CA issues certificates to domain computers, domain users, and servers such as domain controllers. An example of a certificate issued by the Windows CA is shown here.

# ClearPass cluster IP addressing and hostnames

A customer's ClearPass cluster has these IP addresses:

• Publisher = 10.47.47.5

• Subscriber 1 = 10.47.47.6

• Subscriber 2 = 10.47.47.7

• Virtual IP with Subscriber 1 and Subscriber 2 = 10.47.47.8

The customer's DNS server has these entries

• cp.acnsxtest.com = 10.47.47.5

• cps1.acnsxtest.com = 10.47.47.6

• cps2.acnsxtest.com = 10.47.47.7

• radius.acnsxtest.com = 10.47.47.8

• onboard.acnsxtest.com = 10.47.47.8

Refer to the scenario.

The Onboard CA is using the settings shown in the exhibits below.

Microsoft Entra ID (Azure AD) admins need help setting up the app registration for integrating with ClearPass Onboard.

Which URL should you tell them to use?

A
https://clearpass.acnsxtest.com/.well-known/est/ca:2
B
https://onboard.acnsxtest.com/onboard/mdps_scep.php/2
C
https://cps1.acnsxtest.com/.well-known/est/ca:2
D
https://localhost.acnsxtest.com/onboard/mdps_scep.php/2

Correct Option: B

To integrate Microsoft Entra ID (Azure AD) with ClearPass Onboard for SCEP enrollment, the correct URL must point to the Onboard service's Virtual IP (VIP) and use the standard SCEP endpoint. The DNS entry for ClearPass Onboard is 'onboard.acnsxtest.com', mapping to the VIP 10.47.47.8. The standard SCEP URL path for ClearPass Onboard is '/onboard/mdps_scep.php/2'.



Reference: https://www.arubanetworks.com/techdocs/ClearPass/6.10/PolicyManager/Content/CPPM_UserGuide/Onboard/ConfiguringIntuneIntegration.htm
QUESTION 5

A hospital has an AOS-10 architecture that is managed by HPE Aruba Networking Central. The customer has deployed a pair of HPE Aruba Networking 9000 Series gateways with Security licenses at each clinic. The gateways implement IDS/IPS in IDS mode.

The Security Dashboard shows these several recent events with the same signature, as shown below:

Refer to the scenario.

You have learned that the source of the events is nurse call stations.

What can you conclude?

A
These devices are unlikely to use TOR legitimately, but malware often does. You and the security team should investigate these stations.
B
This event is a common false positive for clients using video streaming, but you should still investigate it further to comply with best practices.
C
The nurses are making their devices vulnerable by contacting unsafe websites. You should educate them about safe browsing practices.
D
The threat destination has an internal IP address, and it is likely a DNS server. You should verify that this server is patched and uncompromised.

Correct Option: A

⛳ Option A (Correct)

The IDS/IPS events show "DNS Query for TOR Hidden Service" originating from nurse call stations. Nurse call stations are specialized medical devices that should not be initiating TOR network connections. TOR is often used for anonymity, including by malware for command-and-control (C2) communication. Therefore, these devices are unlikely to use TOR legitimately, strongly suggesting compromise or misconfiguration, necessitating immediate investigation by the security team.

❌ Why the other choices are incorrect:

  • Option B is incorrect: The event description explicitly refers to "DNS Query for TOR Hidden Service," not video streaming. TOR queries are distinct from video streaming traffic.
  • Option C is incorrect: Nurse call stations are typically embedded systems, not general-purpose browsing devices for nurses. The threat is a system-level TOR DNS query, not user-driven unsafe browsing.
  • Option D is incorrect: The destination IP is an internal DNS server, but the threat is the suspicious TOR DNS query originating *from* the nurse call stations. The DNS server is merely processing the query; the primary concern is the client initiating it.


Reference: https://www.arubanetworks.com/products/network-management/aruba-central/
QUESTION 6

A hospital has an AOS-10 architecture that is managed by HPE Aruba Networking Central. The customer has deployed a pair of HPE Aruba Networking 9000 Series gateways with Security licenses at each clinic. The gateways implement IDS/IPS in IDS mode.

The Security Dashboard shows these several recent events with the same signature, as shown below:

Refer to the scenario.

Which step could give you valuable context about the incident?

A
View firewall sessions on the APs and record the threat sources' type and OS.
B
View the RAPIDS Security Dashboard and see if the threat sources are listed as rogues.
C
Find the HPE Aruba Networking Central client profile for the threat sources and note their category and family.
D
View the user-table on APs and record the threat sources' 802.11 settings.

Correct Option: C

To understand the context of a DNS query to a TOR hidden service originating from internal IP addresses, identifying the client device is crucial. HPE Aruba Networking Central maintains detailed client profiles. These profiles provide valuable information such as the device category (e.g., medical device, PC, mobile), operating system family, and potentially associated user, offering direct context for incident investigation.



Reference: https://www.arubanetworks.com/techdocs/central/latest/content/getting_started/monitoring/monitor_security_dash.htm
QUESTION 7

A hospital has an AOS-10 architecture that is managed by HPE Aruba Networking Central. The customer has deployed a pair of HPE Aruba Networking 9000 Series gateways with Security licenses at each clinic. The gateways implement IDS/IPS in IDS mode.

The Security Dashboard shows these several recent events with the same signature, as shown below:

Refer to the scenario.

You would like a record of the specific traffic that triggered the threat event.

What should you do?

A
Search for 10.1.36.150 and 10.1.36.152 in HPE Aruba Networking Central. Then, use live monitoring to obtain a packet capture on these devices.
B
From the Threats List, view the details for one of the threats. Then, download the packet.
C
Find the HPE Aruba Networking APs to which the threat sources are connected and archive those APs’ security logs.
D
Search the DNS logs on the server at 10.254.1.21.

Correct Option: B

To obtain a record of specific traffic that triggered a past threat event, you would typically look within the details of the threat itself. Modern IDS/IPS systems, especially those integrated with a central management platform like HPE Aruba Networking Central, often store the triggering packet or relevant session data with the alert for forensic analysis. The 'Threats List' is the direct interface to these recorded events, and the ability to download packet data is a standard feature for security incident investigation. Option B directly aligns with this forensic capability.



Reference: https://www.arubanetworks.com/techdocs/central/latest/content/gateway/security/ids-ips-overview.htm (General feature set of IDS/IPS on Aruba Gateways with Central)
QUESTION 8

When would you implement BPDU protection on an AOS-CX switch port versus BPDU filtering?

A
Use BPDU protection on edge ports to prevent rogue devices from connecting; use BPDU filtering on inter-switch ports for specialized use cases.
B
Use BPDU protection on inter-switch ports to ensure that they are selected as root; use BPDU filtering on edge ports to prevent rogue devices from connecting.
C
Use BPDU protection on edge ports to protect against rogue devices when the switch implements MSTP; use BPDU filtering to protect against rogue devices when the switch implements PVSTP+.
D
Use BPDU protection on edge ports to permanently lock out rogue devices; use BPDU filtering on edge ports to temporarily lock out rogue devices.

Correct Option: A

BPDU protection (BPDU Guard) is designed for edge ports connected to end devices. Its purpose is to shut down the port if an unexpected BPDU is received, preventing rogue switches from disrupting the STP topology. BPDU filtering prevents the sending and receiving of BPDUs on a port. While typically not used on standard inter-switch links that rely on STP, it can be applied to specific interfaces for specialized use cases, such as connecting to a non-STP aware device or for suppressing BPDUs where STP is explicitly not desired. Therefore, option A accurately describes the appropriate use cases.

Reference: https://www.hpe.com/psnow/doc/a00094776en_us.pdf (HPE ArubaOS-CX documentation on Spanning Tree Protocol features)
QUESTION 9

Your company has an HPE Aruba Networking infrastructure, including a variety of HPE Aruba Networking APs and gateways. The company has recently added HPE Aruba Networking SSE. The company needs to improve security for branch users behind an HPE Aruba Networking SD-WAN gateway.

You need to control users' actions on various SaaS applications. What is part of the setup?

A
Enable gateway IDS/IPS on the gateway's group in HPE Aruba Networking Central
B
Configure an HPE Aruba Networking Central API token on HPE Aruba Networking SSE
C
Use HPE Aruba Networking Central to establish an IPsec tunnel between the gateway and HPE Aruba Networking SSE
D
Configure IPsec crypto maps on HPE Aruba Networking SSE

Correct Option: C

âś… Option C (Correct)Reasoning: To enable HPE Aruba Networking SSE to control user actions on SaaS applications for branch users behind an SD-WAN gateway, traffic must be steered to the SSE. This is fundamentally achieved by establishing an IPsec tunnel from the HPE Aruba Networking SD-WAN gateway to the HPE Aruba Networking SSE. HPE Aruba Networking Central is the management platform used to configure and orchestrate these tunnels on the gateways. This setup allows the SSE to inspect and enforce policies, including CASB functions for SaaS applications.

❌ Why the other choices are incorrect:

  • Option A is incorrect: Enabling gateway IDS/IPS is a network-level threat detection/prevention mechanism, not specifically for controlling user actions within SaaS applications, which is a core function of SSE's CASB capabilities.
  • Option B is incorrect: Configuring an API token facilitates management plane integration for automation or data exchange, but it does not establish the data plane connection necessary to steer user traffic to SSE for security enforcement.
  • Option D is incorrect: While configuring IPsec crypto maps (or equivalent) on HPE Aruba Networking SSE is a necessary part of the overall setup on the SSE side, option C describes the action taken on the Aruba infrastructure (gateway via Central) to establish the tunnel, which is the primary step for integrating the gateway with SSE.



Reference: https://www.arubanetworks.com/products/security/secure-service-edge/
QUESTION 10

A customer requires these rights for clients in the "medical-mobile" AOS firewall role on HPE Aruba Networking Mobility Controllers (MCs):

• Permitted to receive IP addresses with DHCP

• Permitted access to DNS services from 10.8.9.7 and no other server

• Permitted access to all subnets in the 10.1.0.0/16 range except denied access to 10.1.12.0/22

• Denied access to other 10.0.0.0/8 subnets

• Permitted access to the Internet

• Denied access to the WLAN for a period of time if they send any SSH traffic

• Denied access to the WLAN for a period of time if they send any Telnet traffic

• Denied access to all high-risk websites

External devices should not be permitted to initiate sessions with "medical-mobile" clients, only send return traffic.

Refer to the scenario.

The exhibits below show the configuration for the role.

What setting not shown in the exhibit must you check to ensure that the requirements of the scenario?

A
That AppRF and WebCC are enabled globally and on the medical-mobile role
B
That stateful handling of traffic is enabled globally on the MCs’ firewalls and on the medical-mobile role
C
That the MCs are assigned RF Protect licenses
D
That denylisting is enabled globally on the MCs’ firewalls

Correct Option: A

âś… Option A (Correct) The apprf-medical-mobile-s-saci policy contains a rule for web-cc-reputation high-risk deny. For this rule to effectively deny access to high-risk websites, both AppRF (Application Visibility and Control) and WebCC (Web Content Classification) features must be enabled globally on the Mobility Controllers and potentially within the role. These are essential global enablement settings not visible in the provided policy rules but critical for the rule's functionality.

❌ Why the other choices are incorrect:

  • Option B is incorrect: Aruba OS firewalls are stateful by default, addressing the requirement that external devices cannot initiate sessions. While crucial, it's typically an inherent function rather than a distinct setting to enable for specific roles.
  • Option C is incorrect: RF Protect licenses are primarily for Wireless Intrusion Prevention System (WIPS). The deny_opt for SSH/Telnet traffic relates to client containment based on behavior, not WIPS, and doesn't directly necessitate RF Protect licenses.
  • Option D is incorrect: Denylisting is a general concept. Specific deny rules are already configured within the policies. AppRF/WebCC enablement is a more precise setting required for the specific 'high-risk websites' denylist.



Reference: https://www.arubanetworks.com/techdocs/ArubaOS/8.10.0.0/Default.htm#Firewall/Stateful_Firewall_Processing.htm https://www.arubanetworks.com/techdocs/ArubaOS/8.10.0.0/Default.htm#Firewall/AppRF_and_Web_Content_Classification_Configuration.htm
QUESTION 11

What benefit does an organization gain from upgrading wireless security from WPA2-Personal to WPA3-Personal?

A
Users access the wireless network with individual credentials, making it easier to revoke access.
B
Users access the wireless network with individual credentials, enabling role-based access controls.
C
The passphrase used to protect wireless access is more resistant to being cracked.
D
The passphrase used to protect wireless access is more resistant to being leaked by users.

Premium Solution Locked

Unlock all 74 answers & explanations

QUESTION 12

A customer’s admins have added RF Protect licenses and enabled WIDS for a customer's AOS-8-based solution. The customer wants to use the built-in capabilities of APs without deploying dedicated air monitors (AMs). Admins tested rogue AP detection by connecting a unauthorized wireless AP to a switch. The rogue AP was not detected even after several hours.

What is one point about which you should ask?

A
Whether admins enabled wireless containment
B
Whether the customer is using non-standard Wi-Fi channels in the deployment
C
Whether admins set at least one radio on each AP to air monitor mode
D
Whether APs' switch ports support all the VLANs that are accessible at the edge

Premium Solution Locked

Unlock all 74 answers & explanations

QUESTION 13

Refer to the exhibit.

A customer requires protection against ARP poisoning in VLAN 4. Below are listed all settings for VLAN 4 and the VLAN 4 associated physical interfaces on the AOS-CX access layer switch: interface 1/1/2-1/1/24 no shutdown no routing vlan access 4 exit interface lag 1 no shutdown no routing vlan trunk native 1 vlan trunk allowed 2-4 arp inspection trust exit vlan 4 arp inspection exit

What is one issue with this configuration?

A
Edge ports are not configured as untrusted for ARP inspection.
B
ARP proxy is not enabled on VLAN 4.
C
DHCP snooping is not enabled on VLAN 4.
D
LAG 1 is configured as trusted for ARP inspection but should be untrusted.

Premium Solution Locked

Unlock all 74 answers & explanations

QUESTION 14

Refer to the exhibit.

Which IP address should you record as a possibly compromised client?

A
10.254.1.21
B
10.1.26.151
C
10.1.26.1
D
10.1.7.100

Premium Solution Locked

Unlock all 74 answers & explanations

QUESTION 15

A customer is migrating from on-prem AD to Microsoft Entra ID (Azure AD) as its sole domain solution. The customer also manages both wired and wireless devices with Microsoft Endpoint Manager (Intune).

The customer wants to improve security for the network edge. You are helping the customer design an HPE Aruba Networking ClearPass deployment for this purpose. HPE Aruba Networking devices will authenticate wireless and wired clients to a ClearPass Policy Manager (CPPM) cluster (which uses version 6.10).

The customer has several requirements for authentication. The clients should only pass EAP-TLS authentication if a query to Microsoft Entra ID (Azure AD) shows that they have accounts in Microsoft Entra ID (Azure AD). To further refine the clients' privileges, ClearPass also should use information collected by Intune to make access control decisions.

Refer to the scenario.

The Intune extension is configured as shown in this exhibit.

The customer wants to reduce the overhead of polling information from Intune to CPPM. However, they require fresh information about clients at least every hour.

What should you recommend?

A
Setting the "enableEndpointCache" setting to false
B
Setting "enableSyncAll" to false
C
Setting "syncAllOnStart" to false
D
Setting "syncUpdatedOnly" to true

Premium Solution Locked

Unlock all 74 answers & explanations

Full Question Bank Locked

You have reached the end of the free study guide preview. Upgrade now to unlock all 74 questions and the full simulation engine.

Customer Reviews

5 / 5
(15,000+ verified)
5
100%
4
0%
3
0%
2
0%
1
0%

Global Community Feedback

DM

David M.

Verified Student

"The practice engine is incredible. It feels exactly like the real testing environment and helped me build so much confidence."

SJ

Sarah J.

Premium Member

"The PDF is very well organized and the explanations for the answers are actually helpful, not just random text."

MC

Michael C.

Verified Buyer

"I was skeptical, but the content is high quality and definitely worth the price. I passed on my first try!"

Need Assistance?

Our expert support team is available to assist you with any inquiries about our exam materials.

Contact Support
Average response: < 24 Hours

Get Exam Updates

Subscribe to receive instant notifications on new questions and exclusive flash sales.

* Join 5,000+ students getting weekly updates

Support Chat â—Ź Active Now

đź‘‹ Hi! How can we help you pass your exam?

Enter email to start chatting