nerdexam
HP

HPE7-A02 · Question #79

HPE Aruba Networking switches are implementing MAC-Auth to HPE Aruba Networking ClearPass Policy Manager (CPPM) for a company's printers. The company wants to quarantine a client that spoofs a…

The correct answer is D. Authorization: [Endpoints Repository] Conflict EQUALS true. Option D is correct because ClearPass Policy Manager tracks endpoint authentication history in the Endpoints Repository, and when two different devices authenticate using the same MAC address, it sets the Conflict attribute to true. This flag is the precise mechanism CPPM uses…

Implementing Advanced Security Features

Question

HPE Aruba Networking switches are implementing MAC-Auth to HPE Aruba Networking ClearPass Policy Manager (CPPM) for a company's printers. The company wants to quarantine a client that spoofs a legitimate printer's MAC address. You plan to add a rule to the MAC-Auth service enforcement policy for this purpose. What condition should you include?

Options

  • AEndpoint Compliance EQUALS false
  • BEndpoint Device Insight Tag EXISTS
  • CAuthorization: [Endpoints Repository] Compromised EQUALS true
  • DAuthorization: [Endpoints Repository] Conflict EQUALS true

How the community answered

(40 responses)
  • A
    5% (2)
  • B
    18% (7)
  • C
    13% (5)
  • D
    65% (26)

Explanation

Option D is correct because ClearPass Policy Manager tracks endpoint authentication history in the Endpoints Repository, and when two different devices authenticate using the same MAC address, it sets the Conflict attribute to true. This flag is the precise mechanism CPPM uses to signal a MAC address collision - exactly what occurs during spoofing - making it the right condition to trigger a quarantine enforcement action.

Option A (Endpoint Compliance EQUALS false) is wrong because compliance status reflects device health/posture checks (e.g., OnGuard agent results), not MAC address conflicts - a non-compliant device isn't necessarily a spoofer.

Option B (Endpoint Device Insight Tag EXISTS) is wrong because Device Insight tags are used for device profiling and classification, not for detecting duplicate MAC address usage.

Option C (Authorization: [Endpoints Repository] Compromised EQUALS true) is a plausible-sounding distractor, but Compromised is not the standard Endpoints Repository attribute CPPM uses for this scenario - Conflict is the specific attribute populated when a MAC collision is detected.

Memory tip: Think of it as two devices in a conflict over the same MAC address - when a spoofer steals a printer's identity, there's a territorial Conflict that ClearPass can detect and act on.

Topics

#MAC spoofing#MAC-Auth#enforcement policy#endpoint conflict

Community Discussion

No community discussion yet for this question.

Full HPE7-A02 Practice