Complete list of current Q & A>> Download Aruba Certified Clearpass Expert (HPE6-A81) – Quiz 1 / 15 Category: Aruba Certified Clearpass Expert (HPE6-A81) 1. An administrator supports a RAP at a branch office. A user’s device that is attached to the Ethernet port is assigned an 802.1X AAA policy and is configured for tunneled node. How is the user’s traffic transmitted to the corporate office? A. It is not encapsulated by GRE and not protected with IPSec. B. It is encapsulated by GRE and protected with IPSec. C. It is not encapsulated by GRE but is protected with IPSec. D. It is encapsulated by GRE and not protected with IPSec. 2 / 15 Category: Aruba Certified Clearpass Expert (HPE6-A81) 2. An administrator creates service-based policies for AirGroup on the Mobility Master (MM). The administrator can define location-based policy limits based on which information? A. controller names, controller groups, and controller Fully Qualified Domain Names (FQDNs) B. AP names, AP groups, controller names, and controller groups C. AP Fully Qualified Location Names (FQLNs) and controller Fully Qualified Domain Names (FQDNs) D. AP names, AP groups, and AP Fully Qualified Location Names (FQLNs) 3 / 15 Category: Aruba Certified Clearpass Expert (HPE6-A81) 3. An administrator needs to modify a VAP used for a branch office RAP. The VAP’s operating mode is currently defined as backup and uses tunnel mode forwarding. The administrator wants to implement split-tunnel forwarding mode in the VAP. Which WLAN operating mode must the administrator define for the VAP before the tunnel forwarding mode can be changed to split-tunnel? A. Trusted B. Always C. Persistent D. Standard 4 / 15 Category: Aruba Certified Clearpass Expert (HPE6-A81) 4. An administrator deploys an AP at a branch office. The branch office has a private WAN circuit that provides connectivity to a corporate office controller. An Ethernet port on the AP is connected to a network storage device that contains sensitive information. The administrator is concerned about sending this traffic in clear-text across the private WAN circuit. What can the administrator do to prevent this problem? A. Enable IPSec encryption on the AP's wired ports. B. Convert the campus AP into a RAP. C. Redirect the wired port traffic to an AP-to-controller GRE tunnel. D. Enable AP encryption for wired ports. 5 / 15 Category: Aruba Certified Clearpass Expert (HPE6-A81) 5. Which statement is true about Radius IETF attributes Called-Stat ion-Id and Calling-Station-ld? A. Called-Station-ld contains the mac address of the supplicant while Calling-Station-ld contains the mac address of the authenticator. B. Called-Station-Id contains the mac address of the supplicant and SSID name while Calling-Station- Id contains the mac address of the authenticator. C. Called-Station-ld contains the mac address of the authenticator while Calling-Station-Id contains the mac address of the supplicant. D. Called-Station-ld contains the mac address of the authenticator while Calling-Station-ld contains the mac address of the supplicant and SSID name. 6 / 15 Category: Aruba Certified Clearpass Expert (HPE6-A81) 6. The customer has configured the guest self-registration with sponsor approval. The guest users that the sponsor email and the other requested details while registering the account but the users were able to complete the authentication and access the internet without the sponsor’s approval. What configuration settings will you check to make this setup work? A. Check if sponsor name field is enabled in the register form page B. Check if sponsor email field is enabled in the register form page C. Check if authentication option n is enabled in the self-registration page enabled. D. Check if sponsor confirmation is enabled in the self-registration page 7 / 15 Category: Aruba Certified Clearpass Expert (HPE6-A81) 7. A customer is troubleshooting a user that has complained about randomly having issues connecting the network with EAP PEAP using the Corporate Laptop. The initial checks are showing a number of authentication failures but no sign of issues with the ClearPass server or AD. What can the Customer do to monitor this user Authentication trend closely over the next few days? A. configure a Report using Radius Failed Authentication template and schedule it to run every 5 mins B. configure an Alert using Failed Authentication template with Threshold 1. Interval 5 mins C. add the user name in the Insight/Alert/Watchlitst and get the authentication failures notifications within 30 seconds D. add to ClearPass Insight Dashboard the Authentication Status widget for this specific user 8 / 15 Category: Aruba Certified Clearpass Expert (HPE6-A81) 8. A corporate Clear Pass Cluster with two servers located at a single site, has both Management and Data port IP addresses configured. The Management port IPs art in the Data Center networks subnet, while the Data port IPs are in the DMZ. What is the difference between using one Virtual IP for the AAA traffic versus sending AAA requests to the physical IPs for each server’ (Select two.) A. Using the one Virtual IP can provide failover. B. One Virtual IP can be used together with the individual server IPs for load balancing. C. By using the Virtual IP, the failover wait time is faster than using individual server IPs. D. The failover can be accomplished only by using Virtual IP E. The Individual IPs can provide failover and load balancing. 9 / 15 Category: Aruba Certified Clearpass Expert (HPE6-A81) 9. Which statements art true about Aruba down loadable user roles? (select three) A. Administering downloadable user roles can be difficult for a large enterprise. B. Can be applied only on ports or WLAN users authenticated by ClearPass. C. Can use these result for other authentication methods not involving ClearPass. D. Aruba downloadable user role are universally available across the environment. E. Aruba downloadable user role is a built in enforcement template in ClearPass. F. Downloadable role names must be defined in Aruba switch or controller. 10 / 15 Category: Aruba Certified Clearpass Expert (HPE6-A81) 10. You have configured a Guest SSIO with Captive-portaI Web Authentication and MAC authentication. The MAC caching expiry time set to 12 hours and the Guest Account expiration time is set to 8 hours. What will happen if the guest were to disconnect from the SSID and re-connect 9 hours later? A. The client will successfully pass the MAC authentication but still be redirected to captive portal page. B. The client will fail the MAC authentication and be denied access to the Guest SSIO. C. The client will successfully pass the mac authentication until the mac caching time expires. D. The client will fail to get the MAC Caching role and will be redirected to the captive portal login page 11 / 15 Category: Aruba Certified Clearpass Expert (HPE6-A81) 11. Where is the following information stored in Clear Pass? – Roles and Posture for Connected Clients – System Health for OnGuard – Machine authentication State – CoA session info – Mapping of connected clients to NAS/NAD A. ClearPass system cache B. Multi-Master cache C. Insight database D. Endpoint database 12 / 15 Category: Aruba Certified Clearpass Expert (HPE6-A81) 12. A customer has created a Guest Self-Registration page that they would like to use it as ‘template’ for all the new pages that are going to be created from now on. Their goal is to ensure that the header and footer on every page are the same, and any edits made to them are automatically reflected on every Self-Registration Page. What should be configured in order to accomplish this request? A. Save the "template" page as Master Self'Registration page. B. Copy the "template" page and edit it each time a new Self-Registration Page is needed. C. Create child pages when creating new Self-Registration pages and select the "template" as Parent. D. Save this "template" page as a new Skin to be used on other Self-Registration pages. 13 / 15 Category: Aruba Certified Clearpass Expert (HPE6-A81) 13. Which statements are true about that integration between ClearPass Policy Manager and ClearPass Device Insight? (Select two) A. Policy Manager stops using ClearPass Profiler for fingerprinting and uses Device Insight Analyzer instead for endpoint in-depth data analysis B. ClearPass Device Insight updates ClearPass Policy Manager every 60 minutes if it detects a change in device classification like device spoofing. C. To provide enhanced profiling and reporting. additional configuration is required to transmit data in both directions between CPPM and Device Insight. D. When Device Insight integration mode is enabled. you can still use Update Fingerprint button to Update Endpoints at Configuration > Identity > Endpoints E. An attribute named Device Insight Tags art added to the Endpoints that art available to use in service, role-mapping, and enforcement policy Rules 14 / 15 Category: Aruba Certified Clearpass Expert (HPE6-A81) 14. Which forwarding mode is used for a WLAN if a RAP needs to decrypt all user traffic and forward it locally? A. Bridge B. Decrypt-tunnel C. Tunnel D. Split-tunnel 15 / 15 Category: Aruba Certified Clearpass Expert (HPE6-A81) 15. An administrator implements two redundant Aruba Mobility Masters (MMs) . Which protocol should the administrator use to detect a failure in a single subnet? A. PAPI B. VRRP C. SNMP D. IPSec Your score is 0% Restart quiz Send feedback