HPE6-A85 · Question #53
Drag and Drop Question Please match the use case to the appropriate authentication technology. Answer:
Aruba Authentication Technologies: Match Explanation The two targets represent fundamentally different deployment models: Cloud Authentication and Policy - Aruba Central's native cloud-hosted auth service. Best for simpler, cloud-managed scenarios with minimal on-premises infrast
Question
Drag and Drop Question Please match the use case to the appropriate authentication technology. Answer:
Exhibit
Explanation
Aruba Authentication Technologies: Match Explanation
The two targets represent fundamentally different deployment models:
- Cloud Authentication and Policy - Aruba Central's native cloud-hosted auth service. Best for simpler, cloud-managed scenarios with minimal on-premises infrastructure.
- ClearPass Policy Manager (CPPM) - On-premises/VM NAC platform. Best for complex, multi-source policy decisions requiring integrations with AD, MDM, PKI, and certificate provisioning.
Item 1 → Cloud Authentication and Policy
"Unbound MPSK managed by Aruba Central"
Unbound Multi-PSK is a feature built directly into Aruba Central. "Unbound" means keys are not tied to specific MAC addresses - they're distributed per-user/group and managed entirely from the Central cloud dashboard. There is no ClearPass component involved. CPPM does not manage Aruba Central MPSK pools.
Item 2 → Cloud Authentication and Policy
"802.1X on corporate Chromebooks using context from network devices"
Aruba Central's Cloud Auth has native Google Workspace integration specifically designed for Chromebook 802.1X authentication. It leverages device context (enrollment status, user identity) gathered from the Google infrastructure tied to the Chromebook login. This is a purpose-built Cloud Auth feature - no on-prem ClearPass is required.
Common mistake: Assuming any 802.1X scenario requires ClearPass. Cloud Auth handles 802.1X natively for cloud-managed APs with supported IdP integrations.
Item 3 → ClearPass Policy Manager
"Aruba Onboard app from Google Play for Android certificate provisioning"
The Aruba Onboard app is explicitly a ClearPass Onboard client. ClearPass Onboard is a licensed module of CPPM that manages device certificate enrollment, CA operations, and provisioning. The Play Store app is just the endpoint agent that communicates with the ClearPass Onboard server.
Common mistake: Thinking "Onboard" is a standalone cloud product. It is a CPPM module, not a Cloud Auth feature.
Item 4 → ClearPass Policy Manager
"MDM validation + Active Directory + certificates for BYOD"
This requires multi-source policy enforcement: query an external MDM (e.g., Intune, Jamf) to confirm device compliance, authenticate against corporate AD, and validate certificates - all chained in a single authorization policy. This is the core strength of ClearPass: orchestrating complex, conditional NAC decisions using multiple external data sources. Cloud Authentication and Policy cannot natively integrate with arbitrary MDM databases or perform this level of multi-factor policy chaining.
Common mistake: Assuming Cloud Auth can replace CPPM for BYOD with MDM posture checks. Cloud Auth targets simpler identity-based auth; CPPM handles conditional, posture-aware access control.
Summary Rule of Thumb
| Scenario Type | Use |
|---|---|
| Cloud-managed MPSK, simple 802.1X with cloud IdP, Google Workspace | Cloud Authentication and Policy |
| Certificate provisioning, MDM integration, AD + posture policy | ClearPass Policy Manager |
Topics
Community Discussion
No community discussion yet for this question.
