HPE7-A02 · Question #117
You need to set up HPE Aruba Networking ClearPass Policy Manager (CPPM) to provide certificate- based authentication of 802.1X supplicants. How should you upload the root CA certificate for the…
The correct answer is D. As a Trusted CA with the EAP usage. Option D is correct because in CPPM, a Trusted CA certificate is used to validate certificates presented by others - in this case, the supplicants. Uploading it with the EAP usage tells ClearPass to apply that trust anchor specifically during EAP-based authentication (which is…
Question
You need to set up HPE Aruba Networking ClearPass Policy Manager (CPPM) to provide certificate- based authentication of 802.1X supplicants. How should you upload the root CA certificate for the supplicants' certificates?
Options
- AAs a ClearPass Server certificate with the RADIUS/EAP usage.
- BAs a ClearPass Server certificate with the Database usage.
- CAs a Trusted CA with the AD/LDAP usage.
- DAs a Trusted CA with the EAP usage.
How the community answered
(29 responses)- A3% (1)
- B3% (1)
- C10% (3)
- D83% (24)
Explanation
Option D is correct because in CPPM, a Trusted CA certificate is used to validate certificates presented by others - in this case, the supplicants. Uploading it with the EAP usage tells ClearPass to apply that trust anchor specifically during EAP-based authentication (which is what 802.1X uses), allowing it to verify the chain of trust for each supplicant's certificate.
Why the distractors are wrong:
- A & B are wrong because Server Certificates are certificates ClearPass presents to identify itself - not certificates used to validate client/supplicant certs. RADIUS/EAP usage means ClearPass uses that cert as its own EAP identity; Database usage is for inter-node cluster replication. Neither is about trusting external certs.
- C is wrong because the AD/LDAP usage on a Trusted CA tells ClearPass to use that CA when securing connections to Active Directory or LDAP servers (e.g., LDAPS) - completely separate from authenticating 802.1X supplicants.
Memory tip: Split the two dimensions: who owns the cert vs. what context it's used in. "Server Certificate" = ClearPass's own identity. "Trusted CA" = someone else's CA you trust. For validating supplicants in 802.1X (which runs over EAP), you need to trust their CA in the EAP context → Trusted CA + EAP usage.
Topics
Community Discussion
No community discussion yet for this question.