nerdexam
HP

HPE6-A84 · Question #9

Refer to the scenario. A customer is migrating from on-prem AD to Azure AD as its sole domain solution. The customer also manages both wired and wireless devices with Microsoft Endpoint Manager…

The correct answer is D. AS HTTP type, referencing Azure AD's FODN. An authentication source is a configuration element in CPPM that defines how to connect to an external identity provider and retrieve user or device information . CPPM supports various types of authentication sources, such as Active Directory, LDAP, SQL, Kerberos, and HTTP . To…

Implementing and Integrating Advanced Network Security

Question

Refer to the scenario. A customer is migrating from on-prem AD to Azure AD as its sole domain solution. The customer also manages both wired and wireless devices with Microsoft Endpoint Manager (Intune). The customer wants to improve security for the network edge. You are helping the customer design a ClearPass deployment for this purpose. Aruba network devices will authenticate wireless and wired clients to an Aruba ClearPass Policy Manager (CPPM) cluster (which uses version 6.10). The customer has several requirements for authentication. The clients should only pass EAP-TLS authentication if a query to Azure AD shows that they have accounts in Azure AD. To further refine the clients' privileges, ClearPass also should use information collected by Intune to make access control decisions. Assume that the Azure AD deployment has the proper prerequisites established. You are planning the CPPM authentication source that you will reference as the authentication source in 802.1X services. How should you set up this authentication source?

Options

  • AAs Kerberos type
  • BAs Active Directory type
  • CAs HTTP type, referencing the Intune extension
  • DAS HTTP type, referencing Azure AD's FODN

How the community answered

(61 responses)
  • A
    18% (11)
  • B
    3% (2)
  • C
    10% (6)
  • D
    69% (42)

Explanation

An authentication source is a configuration element in CPPM that defines how to connect to an external identity provider and retrieve user or device information . CPPM supports various types of authentication sources, such as Active Directory, LDAP, SQL, Kerberos, and HTTP . To authenticate wireless and wired clients to Azure AD, you need to set up an authentication source as HTTP type, referencing Azure AD's FQDN This type of authentication source allows CPPM to use REST API calls to communicate with Azure AD and validate the user or device credentials. You also need to configure the OAuth 2.0 settings for the authentication source, such as the client ID, client secret, token URL, and resource URL . To use information collected by Intune to make access control decisions, you need to set up another authentication source as HTTP type, referencing the Intune extension . This type of authentication source allows CPPM to use REST API calls to communicate with Intune and retrieve the device compliance status . You also need to configure the OAuth 2.0 settings for the authentication source, such as the client ID, client secret, token URL, and resource URL .

Topics

#Azure AD#ClearPass authentication source#EAP-TLS#HTTP auth type

Community Discussion

No community discussion yet for this question.

Full HPE6-A84 Practice