HPE6-A78 · Question #97
Which correctly describes one of HPE Aruba Networking ClearPass Policy Manager's (CPPM's) device profiling methods?
The correct answer is C. CPPM can analyze settings such as TTL and time window size in endpoints' TCP traffic in order to. HPE Aruba Networking ClearPass Policy Manager (CPPM) uses device profiling to identify and classify endpoints on the network, enabling granular access control based on device type, OS, or other attributes. CPPM supports both passive and active profiling methods. Option C, "CPPM…
Question
Which correctly describes one of HPE Aruba Networking ClearPass Policy Manager's (CPPM's) device profiling methods?
Options
- ACPPM can use Wireshark to actively probe devices, analyze their traffic patterns, and construct an
- BCPPM can use SNMP to configure Aruba switches and mobility devices to mirror client traffic to
- CCPPM can analyze settings such as TTL and time window size in endpoints' TCP traffic in order to
- DCPPM can analyze settings such as TCP/UDP ports used for HTTP, DHCP, and DNS in
How the community answered
(16 responses)- C94% (15)
- D6% (1)
Explanation
HPE Aruba Networking ClearPass Policy Manager (CPPM) uses device profiling to identify and classify endpoints on the network, enabling granular access control based on device type, OS, or other attributes. CPPM supports both passive and active profiling methods. Option C, "CPPM can analyze settings such as TTL and time window size in endpoints' TCP traffic in order to fingerprint the OS," is correct. TCP fingerprinting is a passive profiling method used by CPPM. It involves analyzing TCP packet headers, such as the Time To Live (TTL) value and TCP window size, which vary between operating systems (e.g., Windows, Linux, macOS). CPPM captures this traffic (e.g., via mirrored traffic from a switch or controller) and matches the TCP attributes against its fingerprint database to identify the OS of the endpoint.
Topics
Community Discussion
No community discussion yet for this question.