HPE7-A02 · Question #136
A ClearPass Policy Manager (CPPM) service includes these settings: Role Mapping Policy: Evaluate: Select first Rule 1 conditions: Authorization:AD:Groups EQUALS Managers…
The correct answer is A. [Deny Access Profile]. Note: The stated correct answer of A appears to be incorrect based on standard ClearPass logic. Tracing through the policies reveals that D (domain-only) is the logically correct answer. How the logic actually flows: Role Mapping (Select first): Rule 1 requires AD:Groups =…
Question
A ClearPass Policy Manager (CPPM) service includes these settings:
Role Mapping Policy:
Evaluate: Select first Rule 1 conditions:
Authorization:AD:Groups EQUALS Managers Authentication:TEAP-Method-1-Status EQUALS Success Rule 1 role: manager Rule 2 conditions:
Authentication:TEAP-Method-1-Status EQUALS Success Rule 2 role: domain-comp Default role: [Other] Enforcement Policy:
Evaluate: Select first Rule 1 conditions:
Tips Role EQUALS manager AND Tips Role EQUALS domain-comp Rule 1 profile list: domain- manager Rule 2 conditions:
Tips Role EQUALS manager Rule 2 profile list: manager-only Rule 3 conditions:
Tips Role EQUALS domain-comp Rule 3 profile list: domain-only Default profile: [Deny access] A client is authenticated by the service. CPPM collects attributes indicating that the user is in the Contractors group, and the client passed both TEAP methods. Which enforcement policy will be applied?
Options
- A[Deny Access Profile]
- Bmanager-only
- Cdomain-manager
- Ddomain-only
How the community answered
(40 responses)- A50% (20)
- B13% (5)
- C10% (4)
- D28% (11)
Explanation
Note: The stated correct answer of A appears to be incorrect based on standard ClearPass logic. Tracing through the policies reveals that D (domain-only) is the logically correct answer.
How the logic actually flows:
Role Mapping (Select first):
- Rule 1 requires AD:Groups = Managers AND TEAP-Method-1-Status = Success. The user is in Contractors, so Rule 1 fails.
- Rule 2 requires only TEAP-Method-1-Status = Success. Since the client passed both TEAP methods, this is TRUE → Rule 2 matches.
- Assigned role: domain-comp only (Select first stops here).
Enforcement Policy (Select first):
- Rule 1 requires both manager AND domain-comp roles - client only has domain-comp → fails.
- Rule 2 requires manager → client lacks it → fails.
- Rule 3 requires domain-comp → client has it → matches.
- Applied profile: domain-only (D).
For A (Deny Access) to be correct, both Role Mapping rules would need to fail - which would only happen if TEAP-Method-1-Status were not Success. The question contradicts this by stating the client passed both TEAP methods.
Why the distractors are wrong:
- B (manager-only) requires the manager role, which is never assigned (user is not in Managers).
- C (domain-manager) requires both manager AND domain-comp simultaneously, which is impossible with "Select first" role mapping assigning only one role.
Memory tip: "Select first" is the key phrase - it assigns one role only from the first matching rule. Whenever you see it, trace exactly which rule fires first, then check whether enforcement rules that require multiple roles can ever be satisfied.
Topics
Community Discussion
No community discussion yet for this question.