HPE7-A02 · Question #90
You need to create a rule in an HPE Aruba Networking ClearPass Policy Manager (CPPM) role mapping policy that references a ClearPass Device Insight Tag. Which Type (namespace) should you specify for…
The correct answer is A. Endpoint. Option A is correct because ClearPass Device Insight Tags are stored as attributes within the Endpoint repository in ClearPass Policy Manager. When building a role mapping rule that checks for a Device Insight Tag, you must select the Endpoint namespace so CPPM looks up the tag…
Question
You need to create a rule in an HPE Aruba Networking ClearPass Policy Manager (CPPM) role mapping policy that references a ClearPass Device Insight Tag. Which Type (namespace) should you specify for the rule?
Options
- AEndpoint
- BTIPS
- CDevice
- DApplication
How the community answered
(30 responses)- A87% (26)
- B3% (1)
- C3% (1)
- D7% (2)
Explanation
Option A is correct because ClearPass Device Insight Tags are stored as attributes within the Endpoint repository in ClearPass Policy Manager. When building a role mapping rule that checks for a Device Insight Tag, you must select the Endpoint namespace so CPPM looks up the tag value from the endpoint's profile record.
Why the distractors are wrong:
- B. TIPS - This namespace exposes internal ClearPass Policy Server system attributes (like the tip:role or enforcement profile results), not Device Insight data.
- C. Device - "Device" refers to the Network Access Device (NAD/switch/AP) sending the RADIUS request, not the endpoint being profiled.
- D. Application - This namespace is used for application-layer or posture-related attributes, unrelated to Device Insight tagging.
Memory tip: Think of it this way - Device Insight tags the endpoint, so the tag lives in the Endpoint namespace. If the question ever involves profiling data, posture results, or tags applied to a client device, Endpoint is almost always the right namespace.
Topics
Community Discussion
No community discussion yet for this question.