nerdexam
HP

HPE7-A01 · Question #143

You are setting up a customer's 150 headless loT devices that do not support 802.1 X. What should you use?

The correct answer is A. Multiple Pre-Shared Keys (MPSK) Local. MPSK Local is correct because headless IoT devices cannot use 802.1X (which requires a supplicant/client software to negotiate credentials). MPSK Local allows you to assign a unique pre-shared key to each device (or group) directly on the Aruba infrastructure - no external…

Securing Campus Access Networks

Question

You are setting up a customer's 150 headless loT devices that do not support 802.1 X. What should you use?

Options

  • AMultiple Pre-Shared Keys (MPSK) Local
  • BMultiple Pre-Shared Keys (MPSK) with WPA3-AES
  • CHPE Aruba Networking ClearPass profiling with MAC-AUTH
  • DHPE Aruba Networking ClearPass profiling with WPA-PSK

How the community answered

(22 responses)
  • A
    95% (21)
  • B
    5% (1)

Explanation

MPSK Local is correct because headless IoT devices cannot use 802.1X (which requires a supplicant/client software to negotiate credentials). MPSK Local allows you to assign a unique pre-shared key to each device (or group) directly on the Aruba infrastructure - no external RADIUS server or ClearPass required - making it the simplest, most secure fit for 150 devices that only support PSK-based authentication.

Why the distractors are wrong:

  • B (MPSK with WPA3-AES): WPA3 is often unsupported on older/embedded IoT hardware. Requiring WPA3 would likely cause connection failures across your device fleet.
  • C (ClearPass profiling with MAC-AUTH): MAC addresses are trivially spoofed, making MAC-AUTH a weak security control. It also introduces unnecessary ClearPass dependency for a problem solvable locally.
  • D (ClearPass profiling with WPA-PSK): A single shared PSK for 150 devices is a security liability - one compromised device exposes all others. ClearPass adds infrastructure overhead without solving the shared-key problem.

Memory tip: Think "No 802.1X? No problem - MPSK Local." The word Local is the signal that you don't need an external server (ClearPass), and MPSK tells you each device gets its own unique key - the safest PSK approach for large IoT deployments.

Topics

#MPSK Local#headless IoT devices#802.1X#wireless authentication

Community Discussion

No community discussion yet for this question.

Full HPE7-A01 Practice