nerdexam
HP

HPE6-A84 · Question #42

You are setting up Aruba ClearPass Policy Manager (CPPM) to enforce EAP-TLS authentication with Active Directory as the authentication source. The company wants to prevent users with disabled…

The correct answer is C. Add a custom attribute for userAccountControl to the filters in the AD authentication source. According to the ClearPass Policy Manager User Guide1, userAccountControl is a custom attribute in Active Directory that contains a set of flags that define the properties and behavior of user accounts. One of these flags is ACCOUNTDISABLE, which indicates whether the account…

Implementing and Integrating Advanced Network Security

Question

You are setting up Aruba ClearPass Policy Manager (CPPM) to enforce EAP-TLS authentication with Active Directory as the authentication source. The company wants to prevent users with disabled accounts from connecting even if those users still have valid certificates. As the first part of meeting these criteria, what should you do to enable CPPM to determine where accounts are enabled in AD or not?

Options

  • AAdd an Endpoint Context Server to the domain controller with actions for querying the domain
  • BEnable OCSP in the EAP-TLS authentication method settings and configure an OCSP override to
  • CAdd a custom attribute for userAccountControl to the filters in the AD authentication source.
  • DInstall a Microsoft Active Directory extension in Aruba ClearPass Guest and set up an HTTP

How the community answered

(55 responses)
  • A
    4% (2)
  • B
    5% (3)
  • C
    78% (43)
  • D
    13% (7)

Explanation

According to the ClearPass Policy Manager User Guide1, userAccountControl is a custom attribute in Active Directory that contains a set of flags that define the properties and behavior of user accounts. One of these flags is ACCOUNTDISABLE, which indicates whether the account is disabled or not. By adding this attribute to the filters in the AD authentication source, CPPM can retrieve this attribute for each user and use it as a condition in the enforcement policies to prevent users with disabled accounts from connecting even if they have valid certificates.

Topics

#EAP-TLS#Active Directory#userAccountControl#authentication source

Community Discussion

No community discussion yet for this question.

Full HPE6-A84 Practice