New Year Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70special

HP HPE6-A81 Aruba Certified ClearPass Expert Written Exam Exam Practice Test

Page: 1 / 6
Total 60 questions

Aruba Certified ClearPass Expert Written Exam Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$37.5  $124.99

PDF Study Guide

  • Product Type: PDF Study Guide
$33  $109.99
Question 1

Refer to the exhibit.

A year ago. your customer deployed an Aruba ClearPass Policy Manager Server for a Guest SSID hosted in an IAP Cluster The customer just created a new Web Login Page for the Guest SSiD Even though the previous Web Login page worked test with the new Web Login Page are failing and the customer has forwarded you the above screenshots.

What recommendation would you give the customer to fix the issue?

Options:

A.

The customer should reset the password for the username accxCdlexam.com using Guest Manage Accounts.

B.

The service type configured is not correct. The Guest authentication should be an Application authentication type of service.

C.

The Address filed under the WebLogin Vendor settings is not configured correctly. It should be set to instant, Aruba networks com,

D.

The WebLogin Pre-Auth Check is set to Aruba Application Authentication which requires a separate application service on the policy manager

Question 2

Refer to the exhibit.

A customer is doing a new ClearPass installation and is setting up clustering between two ClearPass servers running a 6.8.6 version. The ClearPass server failed to add the subscriber node. The customer was able to login to the console of the ClearPass server with the same CLI password used during the cluster setup. The customer has sent you the screenshots seeking your support Why did an attempt to add a subscriber node failed showing that error?

Options:

A.

The data and time in the subscriber was not synchronized with the NTP server

B.

The subscriber server is running with a default self -signed HTTPS certificate

C.

The default database certificate used in the publisher server is not a valid certificate

D.

The subscriber server is running with a public signed and trusted HTTPS certificate

Question 3

The customer has configured the guest self-registration with sponsor approval. The guest users that the sponsor email and the other requested details while registering the account but the users were able to complete the authentication and access the internet without the sponsor's approval.

What configuration settings will you check to make this setup work?

Options:

A.

Check if sponsor name field is enabled in the register form page

B.

Check if sponsor email field is enabled in the register form page

C.

Check if authentication option n is enabled in the self-registration page enabled.

D.

Check if sponsor confirmation is enabled in the self-registration page

Question 4

Refer to the exhibit.

You configured a new Wireless 802.1 X service for a Cisco WLC broadcasting the secure-AOM-5007 SSID. The client fails to connect to the SSIO. Using the screenshots as a reference, how would you fix this issue?

Options:

A.

Change the service condition to Radius:lETF Calling-Station-Id EQUALS Secure-ADM-5007

B.

Update the service condition Radws:IETF Called-Stat ion-Id CONTAINS secure-AOM-5007

C.

Remove the service condition Radius:IETF Service-Type BEL0NGS_T0 Login-User (1), 2.8

D.

Make sure that the Network Devices entry for the Cisco WLC has a vendor setting of "Airespace"

Question 5

Refer to the exhibit.

You are doing a ClearPass PoC at a customer site with a single Aruba Mobility Controller. The customer asked for a demonstration of a simple Web Login functionality. You used a service template to create the guest services. During testing, the user gets redirected back to the weblogin page with an Authentication failed message The guest configurations on the Aruba Mobility Controller are configured correctly Why would the guest fail to authenticate successfully?

Options:

A.

The authentication source mapped in the service is incorrect It should be mapped as [Guest Device Repository! (Local SQL DB].

B.

The Unique-Device- Count does not allow any Client devices. Update the Enforcement policy condition: Unique-Device-Count.

C.

The username and/or password used for authentication is incorrect Re-enter the correct password on the weblogin page.

D.

The username used for authentication does not exist in the Guest User Database. Create a new user and authenticate again

Question 6

Refer to the exhibit.

A customer hat configured the Aruba Controller for administrative authentication using ClearPass as A TACAC5 serve' During tasting, the read-only user is getting the root access role What could be a possible reason for this behavior? (Select two.)

Options:

A.

The read-only enforcement profile is mapped to the root role

B.

The ClearPass user role associated to the read-only user is wrong.

C.

On the Controller, the TACACS authentication server is not configured for Session authorization

D.

The Controller's Admin Authentication Options Default role is mapped to root

E.

The Controller Sarver Group Hatch Rules are changing the user role.

Question 7

Your customer has recently implemented a seIf-registration portal in ClearPass Guest to be used on a Guest SSID broadcast from an Aruba controller Your customer has started complaining that the users are not able to reliably access the Internet after clicking the login button on the receipt page They tell you that the users will click the login button multiple times and after about a minute they gam access.

What could be causing this issue?

Options:

A.

The enforcement profile on ClearPass is set up with an IETF:session delay.

B.

The self-registration page is configured with a 1 minute login delay.

C.

The guest users are assigned a firewall user role that has a rate limit.

D.

The guest users are assigned multiple DNS servers delaying DNS response.

Question 8

When building an SNMP-based enforcement profile what option can you assign to the user as actions? (Select three).

Options:

A.

Enforce a VLAN ID for the client

B.

Set a session timeout for the client

C.

Enforce Firewall policies

D.

Send captive portal web re-direct URL

E.

ClearPass Downloadable Role

F.

Reset the connection after the settings has been pushed

Question 9

Refer to the exhibit.

A customer with multiple Aruba Controllers has just installed a new certificate for "'.customerdomain.com- on all Aruba Controllers While testing the existing guest Self-Registration page the customer noticed that the logins are failing While troubleshooting they are finding no entries in the Event Viewer or Access Tracker for the tests Suspecting that the Aruba Controllers may not be properly posting the credentials from the guest browser, they open the NAS Vendor Settings for the Guest Self-Registration Page.

Options:

A.

Add PTR records on the DNS server for "securelogin arubanetworks.com".

B.

Change the "Secure Login' field to "Use Vendor Default".

C.

Change the 'IP Address field to" securelogin.customerdomain.com

D.

Change the "IP Address field to "captiveportal-login.customerdomain.com".

Page: 1 / 6
Total 60 questions