nerdexam
HP

HPE7-A02 · Question #80

A company wants to apply role-based access control lists (ACLs) on AOS-CX switches, which are implementing authentication to HPE Aruba Networking ClearPass Policy Manager (CPPM). The company wants…

The correct answer is A. You can configure the role on CPPM; however, the CPPM role must reference a policy name that. Option A is correct because on AOS-CX switches integrated with CPPM, you can define and assign a user role centrally from CPPM via RADIUS return attributes - but the policy that the role references must already exist locally on the AOS-CX switch itself; CPPM sends the role…

Implementing Advanced Security Features

Question

A company wants to apply role-based access control lists (ACLs) on AOS-CX switches, which are implementing authentication to HPE Aruba Networking ClearPass Policy Manager (CPPM). The company wants to centralize configuration as much as possible. Which correctly describes your options?

Options

  • AYou can configure the role on CPPM; however, the CPPM role must reference a policy name that
  • BYou can configure the role name on CPPM; however, the role settings, including policy and
  • CYou can configure the role, its policy, and the classes referenced in the policy all on CPPM.
  • DYou can configure the role and its policy on CPPM; however, the classes referenced in the policy

How the community answered

(28 responses)
  • A
    46% (13)
  • B
    32% (9)
  • C
    7% (2)
  • D
    14% (4)

Explanation

Option A is correct because on AOS-CX switches integrated with CPPM, you can define and assign a user role centrally from CPPM via RADIUS return attributes - but the policy that the role references must already exist locally on the AOS-CX switch itself; CPPM sends the role name, not the full ACL definition. This is the boundary of centralization: the role assignment is centralized, but the ACL policy (and the traffic-matching classes it contains) must be pre-provisioned on the switch.

Option B is wrong because it understates CPPM's capability - you aren't limited to just a role name on CPPM; the full role construct can live there as a RADIUS attribute. Option C is wrong because you cannot push ACL classes (the actual traffic-match entries) from CPPM to the switch; they must be configured locally. Option D is wrong because the policy itself cannot reside on CPPM - while the role can, the policy it calls must be local on the AOS-CX device.

Memory tip: Think of it as a chain - Role → Policy → Classes - where CPPM can hold the top link (the role), but everything below it (policy and classes) must be configured locally on the switch. "CPPM sends the key, but the lock lives on the switch."

Topics

#role-based ACL#AOS-CX#CPPM#centralized policy

Community Discussion

No community discussion yet for this question.

Full HPE7-A02 Practice