HPE7-A02 · Question #128
A company uses both HPE Aruba Networking ClearPass Policy Manager (CPPM) and HPE Aruba Networking ClearPass Device Insight (CPDI). What is one way integrating the two solutions can help the company…
The correct answer is B. CPDI can use tags to inform CPPM that clients are using prohibited applications. CPPM can then. Option B is correct because it reflects Zero Trust's core principle of continuous, behavior-based policy enforcement: CPDI acts as the "eyes" on the network, continuously monitoring device application activity and tagging any client found running prohibited applications. It…
Question
A company uses both HPE Aruba Networking ClearPass Policy Manager (CPPM) and HPE Aruba Networking ClearPass Device Insight (CPDI). What is one way integrating the two solutions can help the company implement Zero Trust Security?
Options
- ACPPM can inform CPDI that it has assigned a particular Aruba-User-Role to a client; CPDI can
- BCPDI can use tags to inform CPPM that clients are using prohibited applications. CPPM can then
- CCPPM can provide CPDI with custom device fingerprint definitions in order to enhance the
- DCPDI can provide CPPM with extra information about users' identity. CPPM can then use that
How the community answered
(68 responses)- A10% (7)
- B82% (56)
- C4% (3)
- D3% (2)
Explanation
Option B is correct because it reflects Zero Trust's core principle of continuous, behavior-based policy enforcement: CPDI acts as the "eyes" on the network, continuously monitoring device application activity and tagging any client found running prohibited applications. It then shares those tags with CPPM, which dynamically enforces stricter access policies or quarantines the offending device - ensuring trust is never assumed, even after a device is already on the network.
Option A reverses the useful integration flow - CPPM pushing role assignments to CPDI doesn't trigger any actionable Zero Trust enforcement, since CPDI's job is device/application visibility, not policy execution.
Option C is incorrect because it's CPDI (not CPPM) that owns device fingerprinting and profiling; CPPM doesn't supply fingerprint definitions to CPDI - data flows the other direction.
Option D is wrong because CPDI focuses on device identity and behavior, not user identity - user identity comes from directory services and authentication sources, not CPDI.
Memory tip: Think of CPDI as the security camera (watches what devices do) and CPPM as the door lock (controls what they can access). Zero Trust requires the camera to alert the lock - so the correct integration is CPDI → CPPM, triggered by bad behavior like prohibited apps.
Topics
Community Discussion
No community discussion yet for this question.