HPE6-A85 · Question #54
Drag and Drop Question Match the switching technology with the appropriate use case. Answer:
The correct answer is ClearPass Policy Manager - Add certificates to Android devices with the Aruba Onboard application in the Google Play store that will be used for wireless authentication.; Cloud Authentication and Policy - Authenticates users on corporate-owned Chromebook devices using 802.1X and canisel gathered from the network devices that they log into.; Cloud Authentication and Policy - Leverage onboard Multi Pre-Shared Keys (MPSK) managed by Aruba Central to the end-users and client devices.; ClearPass Policy Manager - Validate devices exist in a Mobile Device Management (MDM) database before authenticating BYOD users with corporate Active Directory using certificates. Aruba ClearPass vs Cloud Authentication and Policy - Match Explanation The Two Technologies at a Glance | Technology | Nature | Strengths | |---|---|---| | ClearPass Policy Manager (CPPM) | On-premises NAC solution | Advanced policy, MDM integration, certificate authority…
Question
Drag and Drop Question Match the switching technology with the appropriate use case. Answer:
Exhibit
Answer Area
Drag items
Correct arrangement
- ClearPass Policy Manager - Add certificates to Android devices with the Aruba Onboard application in the Google Play store that will be used for wireless authentication.
- Cloud Authentication and Policy - Authenticates users on corporate-owned Chromebook devices using 802.1X and canisel gathered from the network devices that they log into.
- Cloud Authentication and Policy - Leverage onboard Multi Pre-Shared Keys (MPSK) managed by Aruba Central to the end-users and client devices.
- ClearPass Policy Manager - Validate devices exist in a Mobile Device Management (MDM) database before authenticating BYOD users with corporate Active Directory using certificates
Explanation
Aruba ClearPass vs Cloud Authentication and Policy - Match Explanation
The Two Technologies at a Glance
| Technology | Nature | Strengths |
|---|---|---|
| ClearPass Policy Manager (CPPM) | On-premises NAC solution | Advanced policy, MDM integration, certificate authority, device onboarding (Onboard module) |
| Cloud Authentication and Policy | Cloud-native auth via Aruba Central | MPSK management, 802.1X with cloud-sourced device context, simple cloud-managed policy |
Item-by-Item Breakdown
1. ClearPass → Add certificates to Android devices with the Aruba Onboard app (Google Play)
Why ClearPass: "Aruba Onboard" is a built-in module of ClearPass Policy Manager - not a standalone or Central product. CPPM acts as its own Certificate Authority and uses the Onboard workflow to issue and push certificates to end-user devices. The Google Play app is specifically a companion to the ClearPass Onboard module.
Common mistake: Assuming "Onboard" belongs to Aruba Central because Central handles onboarding tasks. Aruba Central's onboarding is for network devices (APs, switches) - certificate provisioning for end-user devices is a ClearPass Onboard function.
2. Cloud Authentication and Policy → Authenticate corporate Chromebooks using 802.1X and context from network devices
Why Cloud Auth: Cloud Authentication and Policy (part of Aruba Central) natively collects device context from cloud-managed network infrastructure (APs, switches) and uses it in authentication decisions. Chromebook 802.1X in a cloud-managed environment maps to this lightweight, Central-integrated model.
Common mistake: Defaulting to ClearPass for any 802.1X scenario. ClearPass does 802.1X too, but the key phrase is "context gathered from the network devices" - this describes Cloud Auth's integration with Aruba Central's telemetry pipeline, not CPPM's RADIUS flow.
3. Cloud Authentication and Policy → Leverage MPSK managed by Aruba Central
Why Cloud Auth: Multi Pre-Shared Key (MPSK) is a cloud-native feature managed directly through Aruba Central's Cloud Authentication and Policy dashboard. Each user/device gets a unique PSK - the lifecycle of those keys is handled in Central, not CPPM.
Common mistake: Thinking MPSK requires ClearPass because "ClearPass manages access policies." ClearPass can integrate with MPSK in some configurations, but Central-managed MPSK is explicitly a Cloud Auth feature. The phrase "managed by Aruba Central" is the deciding clue.
4. ClearPass → Validate MDM database + authenticate BYOD users via AD certificates
Why ClearPass: This is a textbook CPPM advanced policy scenario: it requires (a) querying an external MDM system to check device enrollment, (b) authenticating against Active Directory, and (c) validating certificates - all chained into one policy decision. ClearPass's policy engine and its native MDM integration connectors (Intune, MobileIron, etc.) handle exactly this multi-condition enforcement.
Common mistake: Thinking Cloud Auth can handle MDM integration. Cloud Authentication and Policy is designed for simpler authentication flows. Complex conditional logic across MDM + AD + certificate validation requires ClearPass's on-prem policy engine.
The Core Decision Rule
| Signal in the question | Maps to |
|---|---|
| Aruba Onboard app, certificates, PKI provisioning | ClearPass |
| MDM database checks, AD integration, BYOD policy | ClearPass |
| MPSK, "managed by Aruba Central" | Cloud Auth |
| Device context from network infrastructure, cloud-managed 802.1X | Cloud Auth |
The pattern: ClearPass = complex on-prem policy with external integrations; Cloud Auth = Central-native, simpler cloud-managed authentication.
Topics
Community Discussion
No community discussion yet for this question.
