HPE7-A02 · Question #76
You are helping an organization deploy HPE Aruba Networking SSE. What is one reason to recommend that the company install agents on remote users' devices?
The correct answer is A. To run posture checks and apply different permissions based on those checks. Installing agents on remote users' devices enables the SSE solution to perform device posture checks - evaluating factors like OS patch level, antivirus status, and disk encryption - and then dynamically assign permissions based on the results (e.g., a compliant device gets…
Question
You are helping an organization deploy HPE Aruba Networking SSE. What is one reason to recommend that the company install agents on remote users' devices?
Options
- ATo run posture checks and apply different permissions based on those checks.
- BTo permit admins to manage the HPE Aruba Networking SSE policy rules.
- CTo permit users to access private servers using SSH.
- DTo run threat inspection on clients in a local sandbox rather than in the cloud.
How the community answered
(36 responses)- A89% (32)
- B6% (2)
- C3% (1)
- D3% (1)
Explanation
Installing agents on remote users' devices enables the SSE solution to perform device posture checks - evaluating factors like OS patch level, antivirus status, and disk encryption - and then dynamically assign permissions based on the results (e.g., a compliant device gets full access, a non-compliant one gets restricted access). This is a foundational Zero Trust principle: trust is never assumed and is always verified based on device health.
Why the distractors are wrong:
- B is wrong because policy management is handled through the SSE admin console in the cloud, not through endpoint agents on user devices.
- C is wrong because SSH access to private servers is controlled by SSE application policies, not by the presence of an agent - and agentless browser-based access can also support this.
- D is wrong because SSE is inherently a cloud-delivered security model; threat inspection happens in the cloud infrastructure, not in a local sandbox on the endpoint.
Memory tip: Think "A = Agent → Assessment → Access" - the Agent runs posture Assessments to determine the right level of Access. If the agent isn't there, SSE can't check device health and must apply one-size-fits-all policies.
Topics
Community Discussion
No community discussion yet for this question.