New Year Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70special

HP HPE6-A73 Aruba Certified Switching Professional Exam Exam Practice Test

Page: 1 / 13
Total 127 questions

Aruba Certified Switching Professional Exam Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$37.5  $124.99

PDF Study Guide

  • Product Type: PDF Study Guide
$33  $109.99
Question 1

A network administrator is implementing BGP for a larger network. The network has over 20 exit points across 15 different BGP routers. The administrator does not want to implement a fully-meshed iBGP peering between all BGP routers.

Which feature should the administrator implement to reduce the number of peers the administrator needs to define?

Options:

A.

Next-hop-self

B.

BFD

C.

Peer-Groups

D.

Route reflectors

Question 2

An administrator has an AOS-CX switch configured with:

router ospf 1

area 0

area 1 stub no-summary

It is the only ABR for area 1. The switch has the appropriate adjacencies to routing switches in areas 0 and 1.

The current routes in each area are:

Area 0: 5 routes (LSA Type 1 and 2)

Area 1: 10 routes (LSA Type 1 and 2)

External routes: 2 (LSA Type 5)

Based on the above configuration, how many OSPF routes will routing switches see in Area 1?

Options:

A.

15

B.

6

C.

11

D.

12

Question 3

When cutting and pasting configurations into NetEdit, which character is used to enter commands within the context of the previous command?

Options:

A.

<ESC>

B.

">"

C.

Space

D.

Tab

Question 4

A network administrator is implementing a configuration plan in NetEdit. The administrator used NetEdit to push the configuration plan to the switch. Which option in the NetEdit planning section should the administrator select to save the configuration running on the switch to the startup-config?

Options:

A.

EDIT

B.

VALIDATE

C.

COMMIT

D.

DEPLOY

Question 5

A company has a third-party AAA server solution. The campus access layer was just upgraded to AOS-CX

switches that perform access control with MAC-Auth and 802.1X. The company has an Aruba Mobility

Controller (MC) solution for wireless, and they want to leverage the firewall policies on the controllers for the wired traffic.

What is correct about how the company should implement a security solution where the wired traffic is

processed by the gateways?

Options:

A.

Implement downloadable user roles with a gateway role defined on the AOS-CX switches

B.

Implement local user roles with a gateway role defined on the AOS-CX switches

C.

Implement standards-based RADIUS VSAs to pass policy information directly to the AOS-CX switches and MCs

D.

Implement downloadable user roles with a device role defined on the AOS-CX switches and MCs

Question 6

A network administrator wants to centralize the management of AOS-CX switches by implementing NetEdit.

How should the administrator purchase and/or install the NetEdit solution?

Options:

A.

Install as a hardware appliance

B.

Installed on a supported version of RedHat Enterprise Linux

C.

Installed in a virtualized solution by using the Aruba-supplied OVA file

D.

Installed on a supported version of Debian Linux

Question 7

An administrator is looking for a data center switching solution that will greatly reduce the likelihood of dropped

frames when uplink congestion is experienced. Which AOS-CX switch queuing feature meets the

administrator’s needs?

Options:

A.

FIFO

B.

VOQ

C.

WFQ

D.

DWWR

Question 8

In AOS-CX switching, what determines when a frame is forwarded by the switch between the ingress and the egress port?

Options:

A.

Egress port

B.

Ingress port

C.

VSX switch tables

D.

Fabric Load Balancer

Question 9

An administrator is implementing a multi-area OSPF network. The network contains a backbone (area 0) and two other areas (1 and 2) connected to ABRs in the backbone The network has one routing switch connected to a service provider located in area 2 Which network design would minimize the number of routes in the routing switches' link state databases (LSDBs) while still allowing full connectivity?

Options:

A.

Area 0: Normal

Area 1: Totally stubby Area 2: Totally stubby

B.

Area 0: Normal

Area 1: Totally not-so-stubby Area 2: Totally stubby

C.

Area 0: Normal

Area 1: Totally stubby

Area 2: Totally not-so-stubby

D.

Area 0: Not-so-stubby

Area 1: Totally not-so-stubby Area 2: Totally not-so-stubby

Question 10

A network administrator is managing a network that deploys a multicast service. The administrator has

multiple streams successfully being routed by PIM-DM in the network. The administrator then adds a new stream with a destination address of 239.0.0.1. However, clients who have not joined the stream are receiving it.

What should the administrator do to fix this problem?

Options:

A.

Verify that IGMP is enabled between the switches connecting the multicast source and receivers

B.

Change the destination multicast address to 239.1.1.1

C.

Define the 239.0.0.1 stream on the rendezvous point (RP)

D.

Define the 239.0.0.1 stream on the PIM candidate bootstrap router

Question 11

Which protocols are used by NetEdit to interact with third-party devices? (Choose two.)

Options:

A.

telnet

B.

SNMP

C.

SSH

D.

Restful API

E.

CDP

Question 12

A network engineer is examining NAE graphs from the Dashboard but notices that the time shown in the graph does not represent the current time. The engineer verifies that the AOS-CX switch is configured for NTP and is successfully synchronized. What should be done to fix this issue?

Options:

A.

Ensure the engineer’s web browser is configured for the same timezone as the AOS-CX switch

B.

Ensure the engineer’s PC is synchronized to the same NTP server as the AOS-CX switch

C.

Ensure NetEdit and the AOS-CX switch are synchronized to the same NTP server

D.

Enable trust settings for the AOS-CX switch’s SSL certificate

Question 13

An administrator has an aggregation layer of 8325CX switches configured as a VSX pair. The administrator is

concerned that when OSPF network changes occur, the aggregation switches will respond to the changes

slowly, and this will affect network connectivity, especially VoIP calls, in the connected access layer switches.

What should the administrator do on the aggregation layer switches to alleviate this issue?D18912E1457D5D1DDCBD40AB3BF70D5D

Options:

A.

Implement route aggregation

B.

Implement bidirectional forwarding detection (BFD)

C.

Reduce the hello and dead interval timers

D.

Implement graceful restart

Question 14

What are best practices when implementing VSX on AOS-CX switches? (Choose two.)

Options:

A.

The ISL lag should use the default MTU size.

B.

Timers should be left at their default values.

C.

The default system MAC addresses should be used.

D.

The keepalive connection should use a direct layer-3 connection.

E.

The ISL lag should use at least 10GbE links or faster.

Question 15

Examine the network exhibit.

A company has a guest implementation for wireless and wired access. Wireless access is implemented

through a third-party vendor. The company is concerned about wired guest traffic traversing the same network as the employee traffic. The network administrator has established a GRE tunnel between AOS-CX switches where guests are connected to a routing switch in the DMZ.

Which feature should the administrator implement to ensure that the guest traffic is tunneled to the DMZ while the employee traffic is forwarded using OSPF?

Options:

A.

OSPF route maps using the “set metric” command

B.

Policy-based routing (PBR)

C.

User-based tunneling (UBT)

D.

Classifier policies

Question 16

Examine the output from an AOS-CX switch implementing a dynamic segmentation solution involving

downloadable user roles:

Switch# show port-access role clearpass

Role information:

Name : icxarubadur_employee-3044-2

Type : clearpass

Status: failed, parsing_failed

Reauthentication Period :

Authentication Mode :

Session Timeout :

The downloadable user roles are not being downloaded to the AOS-CX switch. Based on the above output,

what is the problem?

Options:

A.

The certificate that ClearPass uses in invalid

B.

The AOS-CX switch does not have the ClearPass certificate involved

C.

DNS fails to resolve the ClearPass server’s FQDN

D.

There is a date/time issue between the ClearPass server and the switch

Question 17

An administrator is managing a VSX pair of AOS-CX switches An administrator configures the following on the primary AOS-CX switch:

Options:

A.

The primary switch will erase VLAN 200 from the VSX pair

B.

The VLAN is only created on the secondary switch.

C.

The operation is not allowed by the switch and a CLI error is displayed

D.

The VLAN is created on both the primary and secondary switches

Question 18

An administrator is replacing the current access switches with AOS-CX switches. The access layer switches

must authenticate user and networking devices connecting to them. Some devices support no form of

authentication, and some support 802.1X. Some ports have a VoIP phone and a PC connected to the same

port, where the PC is connected to the data port of the phone and the phone’s LAN port is connected to the switch.

Which statement is correct about this situation?

Options:

A.

802.1X must be configured to work in fallback mode

B.

Device fingerprinting is required for authentication

C.

The client-limit setting for port access needs to be changed

D.

Device mode should be implemented

Question 19

Which concept is implemented using Aruba’s dynamic segmentation?

Options:

A.

Root of trust

B.

Device fingerprinting

C.

Zero Touch Provisioning

D.

Colorless port

Question 20

An administrator in a company of 349 users has a pair of AOS-CX switches with connections to external

networks. Both switches are configured for OSPF. The administrator wants to import external routes on both switches, but assigns different seed metrics to the routes, as well as imports them as external type-1 routes.

What is the best way for the administrator to accomplish this?

Options:

A.

Create a route map with the correct route type and metrics

B.

Define the route type and metrics in the OSPF process

C.

Create a classifier policy with the correct route type and metrics

D.

Define a class and policy map with the correct route type and metrics

Question 21

What is correct regarding the operation of VSX and multicasting with PIM-SM routing configured?

Options:

A.

Each VSX peers runs PIM and builds its own group database. One of the VSX peers is elected as the

designated router (DR) to forward multicast streams to a receiver VLAN

B.

Each VSX peers runs PIM and creates a shared group database. Both VSX peers can forward multicast

streams to receivers in a VLAN, achieving load sharing

C.

Each VSX peers runs PIM and builds its own group database. Both VSX peers can forward multicast

streams to receivers in a VLAN, achieving load sharing

D.

Each VSX peers runs PIM and creates a shared group database. One of the VSX peers is elected as the

designated router (DR) to forward multicast streams to a receiver VLAN

Question 22

Which protocol does NetEdit use to discover devices in a subnet during the discovery process?

Options:

A.

LLDP

B.

ARP

C.

DHCP

D.

ICMP

Question 23

What is a best practice concerning voice traffic and dynamic segmentation on AOS-CX switches?

Options:

A.

Controller authentication and user-based tunneling of the voice traffic

B.

Switch authentication and user-based tunneling of the voice traffic

C.

Controller authentication and port-based tunneling of the voice traffic

D.

Switch authentication and local forwarding of the voice traffic

Question 24

An access layer AOS-CX has no OoS configuration on it. The switch receives an 802.1Q tagged VoIP frame on a port. The frame has an 802.1p value of 6. The IP header has a DSCP value of EF46 How will the switch forward this frame?

Options:

A.

Forwards it as a normal frame

B.

Places it in the high priority queue

C.

Forwards It based on the DSCP value in the frame

D.

Forwards It based on the 802.1p value in the frame

Question 25

How does an administrator install a script and create an agent and actions for the Network Analysis Engine running on AOS-CX switches?

Options:

A.

Access the switches' command-line interface.

B.

Access the switches' web user interface

C.

Use Aruba Central's web user interface

D.

Use the NetEdit web user interface

Question 26

Examine the VSX-related configuration of the core layer AOS-CX switch:

A network administrator is troubleshooting a connectivity issue involving the VSX LAG (link aggregation) between the core and access layer switch, during HW replacement of one of the core switches.

Which configuration should the administrator add to the core switch to fix this issue?

Options:

A.

ICX-Tx-Core1(config)# vsx

ICX-Tx-Core1(config-vsx)# system-mac 02:01:00:00:01:00

B.

ICX-Tx-Core1(config)# interface lag 1 multi-chassis

ICX-Tx-Core1(config-if-lag-if)# mtu 9198

C.

ICX-Tx-Core1(config)# interface 1/1/46-1/1/47

ICX-Tx-Core1(config-if-vlan)# active-gateway ip 10.1.11.1 mac 02:02:00:00:01:00

D.

ICX-Tx-Core1(config)# interface 1/1/45

ICX-Tx-Core1(config-if-vlan)# active-gateway ip 192.168.0.0 mac 02:02:00:00:01:00

Question 27

A network administrator is tasked to set up BGP in the company's network. The administrator is defining an eBGP peering between an AOS-CX switch and a directly-connected service provider. The administrator has configured the following on the AOS-CX switch:

However, when using the "show bgp all summary" command, the state does not display "Established" for the eBGP peer. What must the administrator configure to fix this issue?

Options:

A.

router bgp 64500 neighbor 192.168.1.1 ebgp-multihop

B.

router bgp 64500 enable

C.

router bgp 64500 address-family ipv4 unicast neighbor 192.168.1.1 activate

D.

router bgp 64500 neighbor 192.168.1.1 update-source loopback0

Question 28

Examine the network topology.

Company XYZ has two connections to a service provider (ISP1). Here is the configuration of Router1:

Here is the configuration of Router2:

Based on configuration of Router1 and Router2, which BGP metric is being manipulated?

Options:

A.

Weight

B.

Multiple exit discriminator

C.

Local preference

D.

AS path length

Question 29

Examine the commands entered on an AOS-CX switch:

What is true regarding this configuration for traffic received on interface 100?

Options:

A.

The default next-hop address supersedes the two preceding next-hop addresses

B.

The traffic is always dropped is the next-hop addresses are unreachable

C.

The traffic will be routed with the IP routing table entries if the next-hop addresses are unreachable

D.

The next-hop address of 1.1.1.1 is overwritten by the next-hop address of 2.2.2.2

Question 30

Examine the AOS-CX configuration:

The switches have a default factory password setting NetEdit fails to access the configuration of the AOS-CX switches. What should the administrator do to solve this problem?

Options:

A.

Set a password for the default admin user account.

B.

Disable telnet globally.

C.

Use the default VRF instead of the mgmt VRF

D.

Enable IP routing globally

Question 31

An administrator wants to leverage the Network Analysis Engine (NAE) feature on AOS-CX switches to perform rootcause analysis and to assist in quicklyidentifying problems. Which two AOS-CX databases does the administrator have access to when implementing scripts? (Select two.)

Options:

A.

Time-series

B.

API

C.

VSX

D.

Configuration

E.

Audit

Question 32

When implementing user-based tunneling on an AOS-CX switch, which component defines the primary and backup Aruba gateways?

Options:

A.

Transit VLAN

B.

Gateway role

C.

Server group

D.

Zone

Question 33

A company is implementing a new wireless design and needs it to support high availability, even during times of switch system upgrades. The solution will involve Aruba Mobility Controller (MC) and Aruba AP connections requiring POE. Which campus AOS-CX switch solution and virtual switching should the company implement at the campus access layer?

Options:

A.

AOS-CX 6400 and VSX

B.

AOS-CX 6300 and VSF

C.

AOS-CX 8325 and VSF

D.

AOS-CX 8400 and VSX

Question 34

A network administrator is implementing OSPF, where there are two exit points. Each exit point has a stateful, application inspection firewall to implement company policies.

What would the best practice be to ensure that one firewall will see both directions of the traffic, preventing asynchronous connections in the network?

Options:

A.

Both ASBRs should define External Type 1 routes for the

B.

Both ASBRs should define External Type 1 routes for the

C.

Both ASBRs should define External Type 2 routes for the

D.

Both ASBRs should define External Type 2 routes for the

Question 35

What is correct regarding multicasting and AOS-CX switches?

Options:

A.

IGMP snooping is disabled, by default, on Layer-2 VLAN interfaces

B.

IGMP query functions are enabled, by default, on Layer-2 VLAN interfaces

C.

IGMP snooping is enabled, by default, on Layer-3 VLAN interfaces

D.

IGMP-enabled AOS-CX switches flood unknown multicast destinations

Question 36

An AOS-CX switch is configured to implement downloadable user roles. Examine the AOS-CX switch output:

Based on this output, what is the state of the user’s access?

Options:

A.

No downloadable user role exists

B.

MAC authentication has passed, but 802.1X authentication is in progress

C.

The RADIUS request timed out to the AAA server

D.

The port should be configured for 802.1X

Question 37

An administrator creates an ACL rule with both the “count” and “log” option enabled. What is correct about the

action taken by an AOS-CX switch when there is a match on this rule?

Options:

A.

By default, a summarized log is created every minute with a count of the number of matches

B.

Logging will not include certificate and TLS events, but counting will

C.

The “count” and “log” options are processed by the AOS-CX switch’s hardware ASIC

D.

The total in the “log” record and the count could contain different rule matching statistics

Question 38

A company has an existing wireless solution involving Aruba APs and Mobility controllers running 8.4 code.

The solution leverages a third-party AAA solution. The company is replacing existing access switches with AOS-CX 6300 and 6400 switches. The company wants to leverage the same security and firewall policies for both wired and wireless traffic.

Which solution should the company implement?

Options:

A.

RADIUS dynamic authorization

B.

Downloadable user roles

C.

IPSec

D.

User-based tunneling

Page: 1 / 13
Total 127 questions