nerdexam
HP

HPE2-W07 · Question #187

Your customer is considering Aruba ClearPass for policy management, but suggests Microsoft's Active Directory is enough of an access control system to protect the enterprise network. How should you…

The correct answer is A. Active Directory authenticates users, but true network access control must define who and which. Option A is correct because it captures the fundamental limitation of Active Directory: AD handles authentication (verifying who you are) and manages permissions to resources like files and applications, but it lacks comprehensive Network Access Control (NAC) - which must also…

Question

Your customer is considering Aruba ClearPass for policy management, but suggests Microsoft's Active Directory is enough of an access control system to protect the enterprise network. How should you counter this objection?

Options

  • AActive Directory authenticates users, but true network access control must define who and which
  • BWhile Active Directory can define access controls for users based on factors such as identity and
  • CMicrosoft's Active Directory has been proven by multiple security analysts to be easily hackable, so
  • DActive Directory alone is not enough, but when it is integrated with the role-based access firewall,

How the community answered

(46 responses)
  • A
    72% (33)
  • B
    9% (4)
  • C
    17% (8)
  • D
    2% (1)

Explanation

Option A is correct because it captures the fundamental limitation of Active Directory: AD handles authentication (verifying who you are) and manages permissions to resources like files and applications, but it lacks comprehensive Network Access Control (NAC) - which must also govern which devices can connect, their health posture, location, time-of-day, and guest/BYOD scenarios. ClearPass fills this gap by enforcing granular, context-aware policies across the entire network, not just Windows resources.

Why the distractors fail:

  • B is cut off but implies AD can handle access control based on identity - which is partially true, making it a tempting trap; however, AD still cannot assess device posture or non-Windows endpoints the way ClearPass can.
  • C is unprofessional fear-mongering and factually inaccurate as a blanket claim - never counter a customer objection by attacking a competing vendor's credibility without solid evidence.
  • D muddles the solution by referencing a vague "role-based access firewall" instead of correctly positioning ClearPass as the NAC answer.

Memory tip: Think of AD as a bouncer who checks IDs (authentication), while ClearPass is the full security system that also checks if you're carrying contraband, what door you're allowed through, and whether your guest badge is expired - it controls the who and the which.

Community Discussion

No community discussion yet for this question.

Full HPE2-W07 Practice