HPE2-W07 · Question #195
A customer requires a highly secure network solution, and you have proposed an Aruba controller- based solution and Aruba switches. What is one security benefit that the controllers provide?
The correct answer is D. They can apply role-based firewall policies to wireless and wired traffic. Aruba controllers act as a centralized enforcement point, applying role-based firewall policies to both wireless and wired traffic - meaning every user or device gets a specific set of access permissions based on their role (employee, guest, contractor), regardless of whether…
Question
A customer requires a highly secure network solution, and you have proposed an Aruba controller- based solution and Aruba switches. What is one security benefit that the controllers provide?
Options
- AThey can detect intrusion attempts based on machine learning (ML).
- BThey can create a baseline of normal wireless device behavior and detect anomalies.
- CThey can provide secure SNMPv3-based management for the Aruba switches.
- DThey can apply role-based firewall policies to wireless and wired traffic.
How the community answered
(63 responses)- A5% (3)
- B6% (4)
- C11% (7)
- D78% (49)
Explanation
Aruba controllers act as a centralized enforcement point, applying role-based firewall policies to both wireless and wired traffic - meaning every user or device gets a specific set of access permissions based on their role (employee, guest, contractor), regardless of whether they connect over Wi-Fi or a wired port. This is a core, defining security function of Aruba's controller-based architecture.
Why the distractors are wrong:
- A is incorrect because ML-based intrusion detection is associated with Aruba's separate IntroSpect (UEBA) product, not the controller itself.
- B is similarly tied to IntroSpect/UEBA behavioral analytics - a distinct product, not a base controller feature.
- C is backwards: controllers don't manage switches via SNMPv3; Aruba switches are managed through AirWave, Central, or direct CLI/web UI - and SNMPv3 is a switch-side capability, not something the controller provides to the switches.
Memory tip: Think of the controller as a traffic cop at a checkpoint - it knows your role (employee, guest, IoT device) and enforces what you're allowed to access, on any port. If a choice mentions ML, behavior baselines, or anomaly detection, that's a separate UEBA/IntroSpect tool, not the controller.
Community Discussion
No community discussion yet for this question.