HPE7-A01 · Question #147
A customer has several hundred wireless loT devices and is looking for an authentication solution that meets the following requirements: Which solutions will address the customer's requirements?…
The correct answer is B. MPSK Local with MAC Authentication E. HPE Aruba Networking ClearPass Policy Manager. MPSK Local with MAC Authentication (B) works because IoT devices typically can't support certificate-based or EAP authentication - MAC-based auth paired with unique pre-shared keys allows scalable, password-free onboarding directly on the Aruba gateway. ClearPass Policy Manager…
Question
A customer has several hundred wireless loT devices and is looking for an authentication solution that meets the following requirements:
Which solutions will address the customer's requirements? (Select two.)
Options
- ALocal User Derivation Rules
- BMPSK Local with MAC Authentication
- CMPSK and an internal RADIUS server
- DMPSK Local with EAP-TLS
- EHPE Aruba Networking ClearPass Policy Manager
How the community answered
(27 responses)- A19% (5)
- B70% (19)
- C4% (1)
- D7% (2)
Explanation
MPSK Local with MAC Authentication (B) works because IoT devices typically can't support certificate-based or EAP authentication - MAC-based auth paired with unique pre-shared keys allows scalable, password-free onboarding directly on the Aruba gateway. ClearPass Policy Manager (E) is the enterprise-grade solution that handles device profiling, MAC authentication, and MPSK management at scale, making it ideal for hundreds of IoT devices requiring centralized policy control.
Why the distractors are wrong:
- A (Local User Derivation Rules) handles role/VLAN assignment after auth, not the authentication mechanism itself.
- C (MPSK with internal RADIUS) is limited - the built-in RADIUS server has a small device database ceiling, making it unsuitable for several hundred devices.
- D (MPSK Local with EAP-TLS) requires certificate infrastructure on each device; IoT devices almost never support EAP-TLS due to hardware and OS constraints.
Memory tip: IoT = "I Only Trust simple auth." MAC auth (B) is simple and local; ClearPass (E) is simple to manage at scale. Anything requiring certificates (EAP-TLS) or a limited internal database is a dead end for IoT fleets.
Topics
Community Discussion
No community discussion yet for this question.