nerdexam
HP

HPE6-A84 · Question #34

A customer needs you to configure Aruba ClearPass Policy Manager (CPPM) to authenticate domain users on domain computers. Domain users, domain computers, and domain controllers receive certificates…

The correct answer is C. EAP and Radsec. EAP (Extensible Authentication Protocol) is a framework that allows different authentication methods to be used for network access. EAP is used for RADIUS/EAP authentication, which is a common method for authenticating domain users on domain computers using certificates. EAP…

Implementing and Integrating Advanced Network Security

Question

A customer needs you to configure Aruba ClearPass Policy Manager (CPPM) to authenticate domain users on domain computers. Domain users, domain computers, and domain controllers receive certificates from a Windows CA. CPPM should validate these certificates and verify that the users and computers have accounts in Windows AD. The customer requires encryption for all communications between CPPM and the domain controllers. You have imported the root certificate for the Windows CA to the ClearPass CA Trust list. Which usages should you add to it based on these requirements?

Options

  • ARadec and Aruba infrastructure
  • BEAP and AD/LDAP Server
  • CEAP and Radsec
  • DLDAP and Aruba infrastructure

How the community answered

(63 responses)
  • A
    6% (4)
  • B
    22% (14)
  • C
    57% (36)
  • D
    14% (9)

Explanation

EAP (Extensible Authentication Protocol) is a framework that allows different authentication methods to be used for network access. EAP is used for RADIUS/EAP authentication, which is a common method for authenticating domain users on domain computers using certificates. EAP requires that the RADIUS server, such as ClearPass Policy Manager (CPPM), validates the certificates presented by the clients and verifies their identity against an identity source, such as Windows AD. Therefore, the root certificate for the Windows CA that issues the certificates to the clients should have the EAP usage in the ClearPass CA Trust list. Radsec (RADIUS over TLS) is a protocol that allows secure and encrypted communication between RADIUS servers and clients using TLS. Radsec is used for encrypting all communications between CPPM and the domain controllers, which act as RADIUS clients. Radsec requires that both the RADIUS server and the RADIUS client validate each other's certificates and establish a TLS session. Therefore, the root certificate for the Windows CA that issues the certificates to the domain controllers should have the Radsec usage in the ClearPass

Topics

#CA Trust list#EAP#RadSec#certificate usages

Community Discussion

No community discussion yet for this question.

Full HPE6-A84 Practice