nerdexam
HP

HPE6-A84 · Question #5

Refer to the scenario. A customer requires these rights for clients in the "medical-mobile" AOS firewall role on Aruba Mobility Controllers (MCs): - Permitted to receive IP addresses with DHCP…

The correct answer is C. That AppRF and WebCC are enabled globally and on the medical-mobile role. AppRF and WebCC are features that allow the MCs to classify and control application traffic and web content based on predefined or custom categories. These features are required to meet the scenario requirements of denying access to all high-risk websites and denying access to…

Implementing and Integrating Advanced Network Security

Question

Refer to the scenario. A customer requires these rights for clients in the “medical-mobile” AOS firewall role on Aruba Mobility Controllers (MCs):

  • Permitted to receive IP addresses with DHCP
  • Permitted access to DNS services from 10.8.9.7 and no other server
  • Permitted access to all subnets in the 10.1.0.0/16 range except

denied access to 10.1.12.0/22

  • Denied access to other 10.0.0.0/8 subnets
  • Permitted access to the Internet
  • Denied access to the WLAN for a period of time if they send any SSH

traffic

  • Denied access to the WLAN for a period of time if they send any

Telnet traffic

  • Denied access to all high-risk websites

External devices should not be permitted to initiate sessions with “medical-mobile” clients, only send return traffic. The exhibits below show the configuration for the role. What setting not shown in the exhibit must you check to ensure that the requirements of the scenario are met?

Exhibit

HPE6-A84 question #5 exhibit

Options

  • AThat denylisting is enabled globally on the MCs' firewalls
  • BThat stateful handling of traffic is enabled globally on the MCs' firewalls and on the medical- mobile
  • CThat AppRF and WebCC are enabled globally and on the medical-mobile role
  • DThat the MCs are assigned RF Protect licenses

How the community answered

(26 responses)
  • A
    15% (4)
  • B
    4% (1)
  • C
    77% (20)
  • D
    4% (1)

Explanation

AppRF and WebCC are features that allow the MCs to classify and control application traffic and web content based on predefined or custom categories. These features are required to meet the scenario requirements of denying access to all high-risk websites and denying access to the WLAN for a period of time if they send any SSH or Telnet traffic. To enable AppRF and WebCC, you need to check the following settings: On the global level, you need to enable AppRF and WebCC under Configuration > Services > AppRF and Configuration > Services > WebCC, respectively. On the role level, you need to enable AppRF and WebCC under Configuration > Security > Access Control > Roles > medical- mobile > AppRF and Configuration > Security > Access Control > Roles > medical-mobile > WebCC, respectively. You also need to make sure that the MCs have valid licenses for AppRF and WebCC, which are included in the ArubaOS PEFNG license.

Topics

#AppRF#WebCC#AOS firewall role#application visibility

Community Discussion

No community discussion yet for this question.

Full HPE6-A84 Practice