HPE7-A01 · Question #124
In an AOS-10 architecture using an AP. a gateway and traffic forwarding mode * mixed, what happens when a client connects to an open enhanced 5SID where their VLAN assignment will be bridged?
The correct answer is A. Authenticated Diffie-Hellman is not utilized. In an AOS-10 "Enhanced Open" SSID (WPA3 OWE - Opportunistic Wireless Encryption), the client and AP perform an unauthenticated Diffie-Hellman exchange to negotiate per-session encryption, meaning Authenticated DH is never involved - making A correct. Option B is wrong because Enh
Question
In an AOS-10 architecture using an AP. a gateway and traffic forwarding mode * mixed, what happens when a client connects to an open enhanced 5SID where their VLAN assignment will be bridged?
Options
- AAuthenticated Diffie-Hellman is not utilized
- BRADIUS protocol is utilized.
- CNo encryption is applied.
- DThe gateway will not respond.
How the community answered
(21 responses)- A67% (14)
- B19% (4)
- C10% (2)
- D5% (1)
Explanation
In an AOS-10 "Enhanced Open" SSID (WPA3 OWE - Opportunistic Wireless Encryption), the client and AP perform an unauthenticated Diffie-Hellman exchange to negotiate per-session encryption, meaning Authenticated DH is never involved - making A correct. Option B is wrong because Enhanced Open is a credential-free, open network; no RADIUS server is consulted for authentication. Option C is wrong because OWE's entire purpose is to provide over-the-air encryption even without a passphrase - encryption is absolutely applied. Option D is wrong because in AOS-10 mixed forwarding mode with a bridged VLAN, the gateway participates normally in the data path and responds as expected.
Memory tip: Think "Enhanced but not Authenticated" - OWE enhances a plain open SSID by adding DH-based encryption, but the DH is anonymous/unauthenticated. If you see "Authenticated DH" paired with "open Enhanced Open SSID," that's the mismatch the exam is testing.
Topics
Community Discussion
No community discussion yet for this question.