nerdexam
HP

HPE7-A02 · Question #75

You are configuring the HPE Aruba Networking ClearPass Device Insight Integration settings on ClearPass Policy Manager (CPPM). For which use case should you set the 'Tag Updates Action" to "apply…

The correct answer is D. When you plan to have CPPM issue CoAs for clients with new tags, but do not want to have to list. Option D is correct because the "apply for all tag updates" action is designed precisely for scenarios where you want CPPM to automatically issue a CoA (Change of Authorization) whenever any Device Insight tag changes on an endpoint - without needing to explicitly enumerate…

Implementing Advanced Security Features

Question

You are configuring the HPE Aruba Networking ClearPass Device Insight Integration settings on ClearPass Policy Manager (CPPM). For which use case should you set the 'Tag Updates Action" to "apply for all tag updates"?

Options

  • AWhen the Device Insight integration poll interval is set to a relatively long interval but you still want
  • BWhen Device Insight tags are only used to identify dangerous devices, and you want to disconnect
  • CWhen CPPM is gathering posture information for CPDI, and you want CPDI to always have access
  • DWhen you plan to have CPPM issue CoAs for clients with new tags, but do not want to have to list

How the community answered

(29 responses)
  • A
    7% (2)
  • B
    3% (1)
  • C
    14% (4)
  • D
    76% (22)

Explanation

Option D is correct because the "apply for all tag updates" action is designed precisely for scenarios where you want CPPM to automatically issue a CoA (Change of Authorization) whenever any Device Insight tag changes on an endpoint - without needing to explicitly enumerate every possible tag in your enforcement policy. This "catch-all" behavior is the defining purpose of that setting: broad CoA coverage without manual tag listing.

Why the distractors are wrong:

  • A is wrong because the Tag Updates Action controls what happens when an update arrives, not how frequently CPPM polls for updates - that's controlled by the poll interval setting separately.
  • B is wrong because selectively targeting only dangerous devices implies you want targeted enforcement on specific tags, not blanket action on all tag updates - a more restrictive setting would be appropriate there.
  • C is wrong because posture gathering and ensuring CPDI access is a one-directional data collection concern, not a CoA-triggering use case tied to tag update actions.

Memory tip: Associate "apply for ALL tag updates" with "fire-and-forget CoA" - you want CPPM to react to every tag change automatically, so you never have to maintain a list. If you find yourself thinking "I don't want to manage a tag list," the answer is "all tag updates."

Topics

#CPDI integration#tag updates#CoA#enforcement policy

Community Discussion

No community discussion yet for this question.

Full HPE7-A02 Practice