HPE7-A02 · Question #118
You are setting up policy rules in HPE Aruba Networking SSE. You want to create a single rule that permits users in a particular user group to access multiple applications. What is an easy way to…
The correct answer is B. Apply the same tag to the applications; select the tag as a destination in the policy rule. Tagging multiple applications with a shared label and selecting that tag as the destination in a single policy rule is the intended design pattern in HPE Aruba SSE - it lets you group any combination of private or SaaS apps logically without changing how they're hosted or…
Question
You are setting up policy rules in HPE Aruba Networking SSE. You want to create a single rule that permits users in a particular user group to access multiple applications. What is an easy way to meet this need?
Options
- AAssociate the applications directly with the IdP used to authenticate the users; choose any for the
- BApply the same tag to the applications; select the tag as a destination in the policy rule.
- CPlace all the applications in the same connector zone; select that zone as a destination in the
- DSelect the applications within a non-default web profile; select that profile in the policy rule.
How the community answered
(54 responses)- A6% (3)
- B74% (40)
- C4% (2)
- D17% (9)
Explanation
Tagging multiple applications with a shared label and selecting that tag as the destination in a single policy rule is the intended design pattern in HPE Aruba SSE - it lets you group any combination of private or SaaS apps logically without changing how they're hosted or authenticated, making policy management scalable as applications are added or removed. Option A is wrong because associating applications with an IdP is an authentication configuration, not a policy destination selector - choosing "any" would also be overly permissive. Option C is wrong because connector zones are infrastructure-level constructs for routing traffic through Aruba Private Edge connectors, not a grouping mechanism for policy destinations across arbitrary apps. Option D is wrong because web profiles control browser-based access policies and content filtering behavior, not application grouping for access control rules.
Memory tip: Think of tags in SSE like labels on file folders - slap the same tag on any apps that belong together, then write one policy rule pointing at that label instead of rewriting rules every time the app list changes.
Topics
Community Discussion
No community discussion yet for this question.