Winter Sale - Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dpt65

HPE7-A01 Questions and Answers

Question # 6

The administrator notices that wired guest users that have exceeded their bandwidth limit are not being disconnected Access Tracker in ClearPass indicates a disconnect CoA message is being sent to the AOS-CX switch.

An administrator has performed the following configuration

What is the most likely cause of this issue?

A.

Change of Authorization has not been globally enabled on the switch

B.

The SSL certificate for CPPM has not been added as a trust point on the switch

C.

There is a mismatch between the RADIUS secret on the switch and CPPM.

D.

There is a time difference between the switch and the ClearPass Policy Manager

Full Access
Question # 7

Select the Aruba stacking technology matching each option (Options may be used more than once or not at all.)

Full Access
Question # 8

A customer wants to enable wired authentication across all their CX switches One of the requirements is that the switch must be able to authenticate a single computer connected through a VoIP phone.

Which feature should be enabled to support this requirement?

A.

Multi-Domain Authentication

B.

Device-Based Mode

C.

MAC Authentication

D.

Multi-Auth Mode

Full Access
Question # 9

Match the appropriate QoS concept with its definition. (Options may be used more than once or not at all.)

Full Access
Question # 10

You are helping an onsite network technician bring up an Aruba 9004 gateway with ZTP for a branch office The technician was to plug in any port for the ZTP process to start Thirty minutes after the gateway was plugged in new users started to complain they were no longer able to get to the internet. One user who reported the issue stated their IP address is 172.16 0.81 However, the branch office network is supposed to be on 10.231 81.0/24.

What should the technician do to alleviate the issue and get the ZTP process started correctly?

A.

Turn off the DHCP scope on the gateway, and set DNS correctly on the gateway to reach Aruba Activate

B.

Move the cable on the gateway from port G0/0V1 tc port G0 0.0

C.

Move the cable on the gateway to G0/0/1. and add the device's MAC and Serial number in Central

D.

Factory default and reboot the gateway to restart the process.

Full Access
Question # 11

What does the 802.3bz standard describe?

A.

2.5Gb and 5Gb Ethernet ports

B.

60 W and 90W PoE

C.

AP directed roaming between APs

D.

60 GHz P2P Wi-Fi

Full Access
Question # 12

You are setting up a customer's 15 headless loT devices that do not support 802.1X. What should you use?

A.

Multiple Pre-Shared Keys (MPSK) Local

B.

Clearpass with WPA3-PSK

C.

Clearpass with WPA3-AES

D.

Multiple Pre-Shared Keys (MPSK) with WPA3-AES

Full Access
Question # 13

Your Director of Security asks you to assign AOS-CX switch management roles to new employees based on their specific job requirements After the configuration was complete, it was noted that a user assigned with the administrators role did not have the appropriate level of access on the switch.

The user was not limited to viewing nonsensitive configuration information and a level of 1 was not assigned to their role Which default management role should have been assigned for the user?

A.

sysadmin

B.

operators

C.

helpdesk

D.

config

Full Access
Question # 14

You are troubleshooting an issue with a pair of Aruba CX 8360 switches configured with VSX Each switch has multiple VRFs. You need to find the IP address of a particular client device with a known MAC address You run the "show arp" command on the primary switch in the pair but do not find a matching entry for the client MAC address.

The client device is connected to an Aruba CX 6100 switch by VSX LAG.

Which action can be used to find the IP address successfully?

A)

B)

C)

D)

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 15

What is enabled by LLDP-MED? (Select two.)

A.

Voice VLANs can be automatically configured for VoIP phones

B.

APs can request power as needed from PoE-enabled switch ports

C.

iSCSl client devices can request to have flow control enabled

D.

GVRP VLAN information can be used to dynamically add VLANs to a trunk

E.

iSCSl client devices can set the required MTU setting for the port.

Full Access
Question # 16

A customer is using a legacy application that communicates at layer-2. The customer would like to keep this application working to a remote site connected via layer-3 All legacy devices are connected to a dedicated Aruba CX 6200 switch at each site.

What technology on the Aruba CX 6200 could be used to meet this requirement?

A.

Inclusive Multicast Ethernet Tag (IMET)

B.

Ethernet over IP (EolP)

C.

Generic Routing Encapsulation (GRE)

D.

Static VXLAN

Full Access
Question # 17

You are deploying a bonded 40 MHz wide channel What is the difference in the noise floor perceived by a client using this bonded channel as compared to an unbonded 20MHz wide channel?

A.

2dB

B.

3dB

C.

8dB

D.

4dB

Full Access
Question # 18

A customer is concerned about me unprotected traffic between an AOS-CX switch and a gateway, running on AOStO. What is a feasible option to protect this traffic?

A.

Implement an IPSec tunnel to protect PAPI between the AOS-CX switches and the gateway

B.

Implement an MD5 HMAC function lo protect PAPI between the AOS-CX switches and the gateway

C.

Implement a GRE tunnel to protect PAPI between the AOS-CX switches and the gateway

D.

no action is needed, an RSA certificate already encrypts the traffic

Full Access
Question # 19

Your customer has asked you to assign a switch management role for a new user The customer requires the user role to only have Web Ul access to the System > Log page and only have access to the GET method for REST API for the /logs/event resource

Which default AOS-CX user role meets these requirements?

A.

administrators

B.

auditors

C.

sysops

D.

operators

Full Access
Question # 20

A large retail client is looking to generate a rich set of contextual data based on the location information of wireless clients in their stores Which standard uses Round Trip Time (RTT) and Fine Time Measurements (FTM) to calculate the distance a client is from an AP?

A.

802.11ah

B.

802.11mc

C.

802.11be

D.

802.11V

Full Access
Question # 21

Match the topics of an AOS10 Tunneled mode setup between an AP and a Gateway. (Options may be used more than once or not at all.)

Full Access
Question # 22

With the Aruba CX 6000 24G switch with uplinks of 1/1/25 and what does the switch do when a client port detects a loop and the do-not-disabie parameter is used?

A.

Port status will be validated once status is cleared

B.

An event log message is created.

C.

The network analytics engine is triggered.

D.

Port status led blinks in amber with 100hz.

Full Access
Question # 23

Which statements are true regarding a VXLAN implementation on Aruba Switches? (Select two.)

A.

MTU size must be increased beyond the default

B.

VNIs encapsulate and decapsulate VXLAN traffic

C.

VTEPs encapsulate and decapsulate VXLAN traffic

D.

They are only available for datacenter switches (CX 8k, 9k,10k)

E.

All Aruba CX switches support VXLAN.

Full Access
Question # 24

A customer is using stacked Aruba CX 6200 and CX 6300 switches for access and a VSX pair of Aruba CX 8325 as a collapsed core 802 1X is implemented for authentication. Due to the lack of cabling, some unmanaged switches are still in use Sometimes devices behind these switches cause network outages The switch should send a warning to the helpdesk when the problem occurs You have been asked to implement an effective solution to the problem

What is the solution for this?

A.

Configure spanning tree on the Aruba CX 8325 switches Set the trap-option

B.

Configure loop protection on all edge ports of the Aruba CX 6200 and CX 6300 switches No trap option is needed

C.

Configure loop protection on all edge ports of the Aruba CX 6200 and CX 6300 switches Set up the trap-option

D.

Configure spanning tree on the Aruba CX 6200 and CX 6300 switches No trap option is needed

Full Access
Question # 25

Your manufacturing client is having installers deploy seventy headless scanners and fifty IP cameras in their warehouse These new devices do not support 802 1X authentication.

How can HPE Aruba reduce the IT administration overhead associated with this deployment while maintaining a secure environment using MPSK?

A.

Have the installers generate keys with ClearPass Self Service Registration.

B.

Have the MPSK gateway derive the unique pre-shared keys based on the MAC OUI.

C.

Use MPSK Local to automatically provide unique pre-shared keys for devices.

D.

MPSK Local will allow the cameras to share a key and the scanners to share a different key

Full Access
Question # 26

A network engineer recently identified that a wired device connected to a CX Switch is misbehaving on the network To address this issue, a new ClearPass policy has been put in place to prevent this device from connecting to the network again.

Which steps need to be implemented to allow ClearPass to perform a CoA and change the access for this wired device? (Select two.)

A.

Confirm that NTP is configured on the switch and ClearPass

B.

Configure dynamic authorization on the switch.

C.

Bounce the switchport

D.

Use Dynamic Segmentation.

E.

Configure dynamic authorization on the switchport

Full Access
Question # 27

A customer is looking Tor a wireless authentication solution for all of their loT devices that meet the following requirements

- The wireless traffic between the IoT devices and the Access Points must be encrypted

- Unique passphrase per device

- Use fingerprint information to perform role-based access

Which solutions will address the customer's requirements? (Select two.)

A.

MPSK and an internal RADIUS server

B.

MPSK Local with MAC Authentication

C.

ClearPass Policy Manager

D.

MPSK Local with EAP-TLS

E.

Local User Derivation Rules

Full Access
Question # 28

A customer wants to deploy a Gateway and take advantage of all the SD-WAN features. Which persona role option should be selected?

A.

ArubaOS 10 Branch

B.

ArubaOS 10 VPN Concentrator

C.

ArubaOS 10 Wireless

D.

ArubaOS 10 Mobility

Full Access
Question # 29

With the Aruba CX switch configuration, what is the first-hop protocol feature that is used for VSX L3 gateway as per Aruba recommendation?

A.

Active Gateway

B.

Active-Active VRRP

C.

SVI with vsx-sync

D.

VRRP

Full Access
Question # 30

How do you allow a new VLAN 100 between VSX pair inter-switch-link 256 for port 1/45 and 2/45?

A.

vlan trunk allowed 100 for ports 1/45 and 1/46

B.

vlan trunk add 100 in LAG256

C.

vlan trunk allowed 100 in LAG256

D.

vlan trunk add 100 in MLAG256

Full Access
Question # 31

You are doing tests in your lab and with the following equipment specifications:

• AP1 has a radio that generates a 20 dBm signal

• AP2 has a radio that generates a 8 dBm signal

• AP1 has an antenna with a gain of 7 dBI.

• AP2 has an antenna with a gain of 12 dBI.

• The antenna cable for AP1 has a 3 dB loss

• The antenna cable forAP2 has a 3 OB loss.

What would be the calculated Equivalent Isotropic Radiated Power (EIRP) for AP1?

A.

2dBm

B.

8 dBm

C.

22 dBm

D.

24 dBm

Full Access
Question # 32

Due to a shipping error, five (5) Aruba AP-515S and one (1) Aruba CX 6300 were sent directly to your new branch office You have configured a new group persona for the new branch office devices in Central, but you do not know their MAC addresses or serial numbers The office manager is instructed via text message on their smartphone to onboard all the new hardware into Aruba Central

What application must the office manager use on their phone to complete this task?

A.

Aruba Onboard App

B.

Aruba Central App

C.

Aruba CX Mobile App

D.

Aruba installer App

Full Access
Question # 33

Which feature supported by SNMPv3 provides an advantage over SNMPv2c?

A.

Transport mapping

B.

Community strings

C.

GetBulk

D.

Encryption

Full Access
Question # 34

What is a primary benefit of BSS coloring?

A.

BSS color tags improve performance by allowing APS on the same channel to be farther apart

B.

BSS color tags improve security by identifying rogue APS and tagging them as threats.

C.

BSS color tags are applied on the wireless controllers and can reduce the threshold for interference_

D.

BSS color tags are applied to WI-Fi channels and can reduce the threshold tor interference

Full Access
Question # 35

List the firewall role derivation flow in the correct order

Full Access