nerdexam
HP

HPE7-A02 · Question #72

A company has HPE Aruba Networking APs running AOS-10 that connect to AOS-CX switches. The APs will: Authenticate as 802.1X supplicants to HPE Aruba Networking ClearPass Policy Manager (CPPM) Be…

The correct answer is B. Whether the APs bridge or tunnel traffic on their SSIDs. Option B is correct because the AP's traffic forwarding mode on its SSIDs directly determines which VLANs the switch port must carry. If the APs bridge client traffic locally, the switch port must trunk all the client VLANs; if the APs tunnel client traffic (e.g., to a…

Implementing Advanced Security Features

Question

A company has HPE Aruba Networking APs running AOS-10 that connect to AOS-CX switches. The APs will:

Authenticate as 802.1X supplicants to HPE Aruba Networking ClearPass Policy Manager (CPPM) Be assigned to the "APs" role on the switches Have their traffic forwarded locally What information do you need to help you determine the VLAN settings for the "APs" role?

Options

  • AWhether the switches are using local user-roles (LURs) or downloadable user-roles (DURs).
  • BWhether the APs bridge or tunnel traffic on their SSIDs.
  • CWhether the switches have established tunnels with an HPE Aruba Networking gateway.
  • DWhether the APs have static or DHCP-assigned IP addresses.

How the community answered

(56 responses)
  • A
    9% (5)
  • B
    71% (40)
  • C
    4% (2)
  • D
    16% (9)

Explanation

Option B is correct because the AP's traffic forwarding mode on its SSIDs directly determines which VLANs the switch port must carry. If the APs bridge client traffic locally, the switch port must trunk all the client VLANs; if the APs tunnel client traffic (e.g., to a gateway), the switch only needs the AP's management VLAN - two very different role configurations.

Option A is wrong because LUR vs. DUR only affects how the role is delivered to the switch (locally stored vs. downloaded from CPPM), not what VLANs the role actually needs to permit.

Option C is wrong because the question already tells you traffic is forwarded locally, so gateway tunnels from the switch are irrelevant to the AP role's VLAN requirements.

Option D is wrong because static vs. DHCP addressing on the APs doesn't change which VLANs the switch port must carry - that's a management concern, not a role/VLAN scope concern.

Memory tip: Ask yourself "where does the client traffic go?" - Bridged = client VLANs must reach the switch (fat trunk), Tunneled = only management VLAN needed (thin trunk). The answer to that question is the VLAN configuration.

Topics

#802.1X#VLAN assignment#AP traffic forwarding#AOS-CX roles

Community Discussion

No community discussion yet for this question.

Full HPE7-A02 Practice