nerdexam
HP

HPE7-A02 · Question #73

A company has AOS-CX switches, which authenticate clients to HPE Aruba Networking ClearPass Policy Manager (CPPM). CPPM is set up to receive a variety of information about clients' profile and…

The correct answer is C. Enable dynamic authorization, and specify CPPM as a dynamic authorization client. Dynamic authorization (CoA - Change of Authorization) is the correct mechanism because it allows CPPM to push updated enforcement policies to the switch mid-session without requiring the client to re-authenticate. When CPPM receives new profiling or posture data that changes a…

Implementing Advanced Security Features

Question

A company has AOS-CX switches, which authenticate clients to HPE Aruba Networking ClearPass Policy Manager (CPPM). CPPM is set up to receive a variety of information about clients' profile and posture. New information can mean that CPPM should change a client's enforcement profile. What should you set up on the switches to help the solution function correctly?

Options

  • AEnable RADIUS accounting to CPPM, including interim RADIUS accounting.
  • BConfigure a RADIUS track that references CPPM's FQDN or IP address.
  • CEnable dynamic authorization, and specify CPPM as a dynamic authorization client.
  • DRe-configure the authentication server on the switch specifying CPPM as a TACACS server.

How the community answered

(54 responses)
  • A
    15% (8)
  • B
    4% (2)
  • C
    72% (39)
  • D
    9% (5)

Explanation

Dynamic authorization (CoA - Change of Authorization) is the correct mechanism because it allows CPPM to push updated enforcement policies to the switch mid-session without requiring the client to re-authenticate. When CPPM receives new profiling or posture data that changes a client's risk level, it sends a CoA or Disconnect message to the switch, which then applies the new VLAN, ACL, or role - exactly what the scenario describes.

Why the distractors are wrong:

  • A - RADIUS accounting sends session data from the switch to CPPM, but accounting alone gives CPPM no mechanism to send policy changes back to the switch; it's one-way telemetry.
  • B - A RADIUS track monitors reachability of the RADIUS server for failover purposes; it has nothing to do with applying updated client policies.
  • D - TACACS is an authentication protocol for device administration (CLI access), not for 802.1X/MAC-auth client enforcement; switching to TACACS would break client authentication entirely.

Memory tip: Think of CoA as CPPM "calling back" the switch - the switch must be listening for that call, which is what enabling dynamic authorization and listing CPPM as a trusted client accomplishes. If CPPM can't call back, it can't change anything mid-session.

Topics

#dynamic authorization#CoA#RADIUS#CPPM enforcement

Community Discussion

No community discussion yet for this question.

Full HPE7-A02 Practice