nerdexam
HP

HPE6-A78 · Question #105

What is a difference between passive and active endpoint classification?

The correct answer is D. Passive classification analyzes traffic that endpoints send as part of their normal functions; active. HPE Aruba Networking ClearPass Policy Manager (CPPM) uses endpoint classification (profiling) to identify and categorize devices on the network, enabling policy enforcement based on device type, OS, or other attributes. CPPM supports two primary profiling methods: passive and…

Aruba Security Solutions and Architectures

Question

What is a difference between passive and active endpoint classification?

Options

  • APassive classification refers exclusively to MAC OUI-based classification, while active
  • BPassive classification classifies endpoints based on entries in dictionaries, while active
  • CPassive classification is only suitable for profiling endpoints in small business environments, while
  • DPassive classification analyzes traffic that endpoints send as part of their normal functions; active

How the community answered

(48 responses)
  • A
    2% (1)
  • B
    8% (4)
  • C
    4% (2)
  • D
    85% (41)

Explanation

HPE Aruba Networking ClearPass Policy Manager (CPPM) uses endpoint classification (profiling) to identify and categorize devices on the network, enabling policy enforcement based on device type, OS, or other attributes. CPPM supports two primary profiling methods: passive and active Passive Classification: This method involves observing network traffic that endpoints send as part of their normal operation, without CPPM sending any requests to the device. Examples include DHCP fingerprinting (analyzing DHCP Option 55), HTTP User-Agent string analysis, and TCP fingerprinting (analyzing TTL and window size). Passive classification is non-intrusive and does not generate additional network traffic. Active Classification: This method involves CPPM sending requests to the endpoint to gather information. Examples include SNMP scans (to query device details), WMI scans (for Windows devices), and SSH scans (to gather system information). Active classification is more intrusive and may require credentials or network access to the device.

Topics

#endpoint classification#passive profiling#active profiling#traffic analysis

Community Discussion

No community discussion yet for this question.

Full HPE6-A78 Practice