nerdexam
HP

HPE6-A78 · Question #61

A company has an ArubaOS solution. The company wants to prevent users assigned to the "user_group1" role from using gaming and peer-to-peer applications. What is the recommended approach for these…

The correct answer is A. Make sure DPI is enabled, and add application rules that deny gaming and peer-to-peer. The recommended approach for preventing users in the "user_group1" role from using gaming and peer-to-peer applications in an ArubaOS environment is to enable Deep Packet Inspection (DPI) and add application rules that specifically deny access to these types of applications for…

Implementing and Configuring Aruba Network Security

Question

A company has an ArubaOS solution. The company wants to prevent users assigned to the "user_group1" role from using gaming and peer-to-peer applications. What is the recommended approach for these requirements?

Options

  • AMake sure DPI is enabled, and add application rules that deny gaming and peer-to-peer
  • BCreate ALGs for the gaming and peer-to-peer applications, and deny the "user_group1" role on the
  • CAdd access control rules to the "user_group1" role, which deny HTTP/HTTPS traffic to IP
  • DCreate service aliases for the TCP ports associated with gaming and peer-to-per applications, and

How the community answered

(23 responses)
  • A
    83% (19)
  • B
    4% (1)
  • C
    9% (2)
  • D
    4% (1)

Explanation

The recommended approach for preventing users in the "user_group1" role from using gaming and peer-to-peer applications in an ArubaOS environment is to enable Deep Packet Inspection (DPI) and add application rules that specifically deny access to these types of applications for the role. DPI allows the network system to analyze the content of network traffic in real time and apply policies based on what it detects, including blocking specific applications like gaming and peer-to-peer sharing. This capability is essential for effectively managing application usage on the network and ensuring compliance with organizational policies. Application-specific rules provide precise control over the network traffic by identifying the application regardless of the network port used, making it a more effective method than blocking based on ports or IP addresses.

Topics

#DPI#application rules#role-based access#firewall policy

Community Discussion

No community discussion yet for this question.

Full HPE6-A78 Practice