HPE7-A01 · Question #143
You are setting up a customer's 150 headless loT devices that do not support 802.1 X. What should you use?
The correct answer is A. Multiple Pre-Shared Keys (MPSK) Local. MPSK Local is correct because headless IoT devices cannot use 802.1X (which requires a supplicant/client software to negotiate credentials). MPSK Local allows you to assign a unique pre-shared key to each device (or group) directly on the Aruba infrastructure - no external…
Question
You are setting up a customer's 150 headless loT devices that do not support 802.1 X. What should you use?
Options
- AMultiple Pre-Shared Keys (MPSK) Local
- BMultiple Pre-Shared Keys (MPSK) with WPA3-AES
- CHPE Aruba Networking ClearPass profiling with MAC-AUTH
- DHPE Aruba Networking ClearPass profiling with WPA-PSK
How the community answered
(22 responses)- A95% (21)
- B5% (1)
Explanation
MPSK Local is correct because headless IoT devices cannot use 802.1X (which requires a supplicant/client software to negotiate credentials). MPSK Local allows you to assign a unique pre-shared key to each device (or group) directly on the Aruba infrastructure - no external RADIUS server or ClearPass required - making it the simplest, most secure fit for 150 devices that only support PSK-based authentication.
Why the distractors are wrong:
- B (MPSK with WPA3-AES): WPA3 is often unsupported on older/embedded IoT hardware. Requiring WPA3 would likely cause connection failures across your device fleet.
- C (ClearPass profiling with MAC-AUTH): MAC addresses are trivially spoofed, making MAC-AUTH a weak security control. It also introduces unnecessary ClearPass dependency for a problem solvable locally.
- D (ClearPass profiling with WPA-PSK): A single shared PSK for 150 devices is a security liability - one compromised device exposes all others. ClearPass adds infrastructure overhead without solving the shared-key problem.
Memory tip: Think "No 802.1X? No problem - MPSK Local." The word Local is the signal that you don't need an external server (ClearPass), and MPSK tells you each device gets its own unique key - the safest PSK approach for large IoT deployments.
Topics
Community Discussion
No community discussion yet for this question.