nerdexam
HP

HPE7-A02 · Question #117

You need to set up HPE Aruba Networking ClearPass Policy Manager (CPPM) to provide certificate- based authentication of 802.1X supplicants. How should you upload the root CA certificate for the…

The correct answer is D. As a Trusted CA with the EAP usage. Option D is correct because in CPPM, a Trusted CA certificate is used to validate certificates presented by others - in this case, the supplicants. Uploading it with the EAP usage tells ClearPass to apply that trust anchor specifically during EAP-based authentication (which is…

Implementing Advanced Security Features

Question

You need to set up HPE Aruba Networking ClearPass Policy Manager (CPPM) to provide certificate- based authentication of 802.1X supplicants. How should you upload the root CA certificate for the supplicants' certificates?

Options

  • AAs a ClearPass Server certificate with the RADIUS/EAP usage.
  • BAs a ClearPass Server certificate with the Database usage.
  • CAs a Trusted CA with the AD/LDAP usage.
  • DAs a Trusted CA with the EAP usage.

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    10% (3)
  • D
    83% (24)

Explanation

Option D is correct because in CPPM, a Trusted CA certificate is used to validate certificates presented by others - in this case, the supplicants. Uploading it with the EAP usage tells ClearPass to apply that trust anchor specifically during EAP-based authentication (which is what 802.1X uses), allowing it to verify the chain of trust for each supplicant's certificate.

Why the distractors are wrong:

  • A & B are wrong because Server Certificates are certificates ClearPass presents to identify itself - not certificates used to validate client/supplicant certs. RADIUS/EAP usage means ClearPass uses that cert as its own EAP identity; Database usage is for inter-node cluster replication. Neither is about trusting external certs.
  • C is wrong because the AD/LDAP usage on a Trusted CA tells ClearPass to use that CA when securing connections to Active Directory or LDAP servers (e.g., LDAPS) - completely separate from authenticating 802.1X supplicants.

Memory tip: Split the two dimensions: who owns the cert vs. what context it's used in. "Server Certificate" = ClearPass's own identity. "Trusted CA" = someone else's CA you trust. For validating supplicants in 802.1X (which runs over EAP), you need to trust their CA in the EAP context → Trusted CA + EAP usage.

Topics

#ClearPass Policy Manager#certificate-based authentication#802.1X#Trusted CA

Community Discussion

No community discussion yet for this question.

Full HPE7-A02 Practice