nerdexam
HP

HPE7-A01 · Question #149

Your manufacturing client is deploying twenty headless scanners in their warehouse. These new devices do not support 802.1X authentication. How does the gateway determine the device's role and VLAN…

The correct answer is A. From the Type-Length-Value based on the Aruba-MPSK-Key-Name. When a headless device connects using MPSK Local, the gateway identifies which pre-shared key was used and reads the associated Aruba-MPSK-Key-Name delivered as a Type-Length-Value (TLV) attribute - this is what drives role assignment and VLAN derivation rules, making option A…

Securing Campus Access Networks

Question

Your manufacturing client is deploying twenty headless scanners in their warehouse. These new devices do not support 802.1X authentication. How does the gateway determine the device's role and VLAN derivation-rules when using MPSK Local?

Options

  • AFrom the Type-Length-Value based on the Aruba-MPSK-Key-Name.
  • BIt pulls the device roles from HPE Aruba Networking Central during deployment.
  • CFrom the device's Calling-Station-ID in the RADIUS Access-Request.
  • DFrom the MPSK roles defined in HPE Aruba Networking Central's security dashboard.

How the community answered

(65 responses)
  • A
    57% (37)
  • B
    14% (9)
  • C
    6% (4)
  • D
    23% (15)

Explanation

When a headless device connects using MPSK Local, the gateway identifies which pre-shared key was used and reads the associated Aruba-MPSK-Key-Name delivered as a Type-Length-Value (TLV) attribute - this is what drives role assignment and VLAN derivation rules, making option A correct. Option B is wrong because "Local" in MPSK Local means the policy is stored and enforced on the gateway itself, not fetched from Central at deployment time. Option C is incorrect because Calling-Station-ID carries the device's MAC address and is relevant to MAC-based authentication, not MPSK key-name role derivation. Option D is a plausible-sounding distractor, but MPSK roles are not defined in a Central "security dashboard" - they are tied to the key name configured locally on the gateway.

Memory tip: Think "Local TLV Label" - with MPSK Local, the key name (via TLV) acts as the device's label that the gateway reads locally to assign its role and VLAN.

Topics

#MPSK Local#VLAN derivation#role assignment#TLV Aruba-MPSK-Key-Name

Community Discussion

No community discussion yet for this question.

Full HPE7-A01 Practice