HPE7-A02 · Question #73
A company has AOS-CX switches, which authenticate clients to HPE Aruba Networking ClearPass Policy Manager (CPPM). CPPM is set up to receive a variety of information about clients' profile and…
The correct answer is C. Enable dynamic authorization, and specify CPPM as a dynamic authorization client. Dynamic authorization (CoA - Change of Authorization) is the correct mechanism because it allows CPPM to push updated enforcement policies to the switch mid-session without requiring the client to re-authenticate. When CPPM receives new profiling or posture data that changes a…
Question
A company has AOS-CX switches, which authenticate clients to HPE Aruba Networking ClearPass Policy Manager (CPPM). CPPM is set up to receive a variety of information about clients' profile and posture. New information can mean that CPPM should change a client's enforcement profile. What should you set up on the switches to help the solution function correctly?
Options
- AEnable RADIUS accounting to CPPM, including interim RADIUS accounting.
- BConfigure a RADIUS track that references CPPM's FQDN or IP address.
- CEnable dynamic authorization, and specify CPPM as a dynamic authorization client.
- DRe-configure the authentication server on the switch specifying CPPM as a TACACS server.
How the community answered
(54 responses)- A15% (8)
- B4% (2)
- C72% (39)
- D9% (5)
Explanation
Dynamic authorization (CoA - Change of Authorization) is the correct mechanism because it allows CPPM to push updated enforcement policies to the switch mid-session without requiring the client to re-authenticate. When CPPM receives new profiling or posture data that changes a client's risk level, it sends a CoA or Disconnect message to the switch, which then applies the new VLAN, ACL, or role - exactly what the scenario describes.
Why the distractors are wrong:
- A - RADIUS accounting sends session data from the switch to CPPM, but accounting alone gives CPPM no mechanism to send policy changes back to the switch; it's one-way telemetry.
- B - A RADIUS track monitors reachability of the RADIUS server for failover purposes; it has nothing to do with applying updated client policies.
- D - TACACS is an authentication protocol for device administration (CLI access), not for 802.1X/MAC-auth client enforcement; switching to TACACS would break client authentication entirely.
Memory tip: Think of CoA as CPPM "calling back" the switch - the switch must be listening for that call, which is what enabling dynamic authorization and listing CPPM as a trusted client accomplishes. If CPPM can't call back, it can't change anything mid-session.
Topics
Community Discussion
No community discussion yet for this question.