nerdexam
HP

HPE6-A78 · Question #75

You have a network with AOS-CX switches for which HPE Aruba Networking ClearPass Policy Manager (CPPM) acts as the TACACS+ server. When an admin authenticates, CPPM sends a response with…

The correct answer is C. The user receives administrators access. HPE Aruba Networking AOS-CX switches support TACACS+ for administrative authentication, where ClearPass Policy Manager (CPPM) can act as the TACACS+ server. When an admin authenticates, CPPM sends a TACACS+ response that includes attributes such as the TACACS+ privilege level…

Implementing and Configuring Aruba Network Security

Question

You have a network with AOS-CX switches for which HPE Aruba Networking ClearPass Policy Manager (CPPM) acts as the TACACS+ server. When an admin authenticates, CPPM sends a response with:

Aruba-Priv-Admin-User = 1 TACACS+ privilege level = 15 What happens to the user?

Options

  • AThe user receives auditors access.
  • BThe user receives no access.
  • CThe user receives administrators access.
  • DThe user receives operators access.

How the community answered

(46 responses)
  • A
    2% (1)
  • B
    4% (2)
  • C
    83% (38)
  • D
    11% (5)

Explanation

HPE Aruba Networking AOS-CX switches support TACACS+ for administrative authentication, where ClearPass Policy Manager (CPPM) can act as the TACACS+ server. When an admin authenticates, CPPM sends a TACACS+ response that includes attributes such as the TACACS+ privilege level and vendor-specific attributes (VSAs) like Aruba-Priv-Admin-User. In this scenario, CPPM sends: TACACS+ privilege level = 15: In TACACS+, privilege level 15 is the highest level and typically grants full administrative access (equivalent to a superuser or administrator role). Aruba-Priv-Admin-User = 1: This Aruba-specific VSA indicates that the user should be granted the highest level of administrative access on the switch. On AOS-CX switches, the privilege level 15 maps to the administrator role, which provides full read- write access to all switch functions. The Aruba-Priv-Admin-User = 1 attribute reinforces this by explicitly assigning the admin role, ensuring the user has unrestricted access.

Topics

#TACACS+#privilege level#ClearPass#admin authentication

Community Discussion

No community discussion yet for this question.

Full HPE6-A78 Practice