HPE6-A87 · Question #12
Which two features are key to the security of the CX 10000 series? (Select TWO)
The correct answer is B. ASIC-based Threat Detection C. VRF-Based Microsegmentation. ASIC-based Threat Detection (B) is correct because the Aruba CX 10000 leverages AMD Pensando DPU ASICs to perform stateful firewall inspection and threat detection entirely in hardware - delivering line-rate security processing without the latency penalty of software-based…
Question
Which two features are key to the security of the CX 10000 series? (Select TWO)
Options
- ADistributed Data Encryption
- BASIC-based Threat Detection
- CVRF-Based Microsegmentation
- DHTTP-based Management
How the community answered
(40 responses)- A5% (2)
- B88% (35)
- D8% (3)
Explanation
ASIC-based Threat Detection (B) is correct because the Aruba CX 10000 leverages AMD Pensando DPU ASICs to perform stateful firewall inspection and threat detection entirely in hardware - delivering line-rate security processing without the latency penalty of software-based solutions. VRF-Based Microsegmentation (C) is correct because the CX 10000 uses Virtual Routing and Forwarding instances to logically isolate traffic flows, preventing lateral movement between segments - a cornerstone of zero-trust architecture.
Distributed Data Encryption (A) is a distractor; while encryption matters in broader security architectures, it is not a defining security capability of the CX 10000's feature set as described in Aruba's documentation. HTTP-based Management (D) is actually a security anti-pattern - HTTP transmits management traffic in plaintext, making it a vulnerability rather than a feature; HTTPS would be the secure alternative.
Memory tip: Think "ASIC + VRF = CX 10000 security DNA." The ASIC handles what enters (threat detection at hardware speed), while VRF controls where traffic goes (microsegmentation). Both work at the data plane level - if an answer sounds management-layer or generic, it's likely a distractor.
Topics
Community Discussion
No community discussion yet for this question.