nerdexam
HP

HPE7-A02 · Question #93

You have created a Web-based Health Check Service that references a posture policy. You want the service to trigger a RADIUS change of authorization (CoA) when a client receives a Healthy or…

The correct answer is A. In a RADIUS enforcement policy. Option A is correct because a RADIUS enforcement policy is where you define the rules that trigger CoA actions based on posture results. When the Health Check Service evaluates a client and assigns a "Healthy" or "Quarantine" posture status, it's the RADIUS enforcement policy…

Implementing Advanced Security Features

Question

You have created a Web-based Health Check Service that references a posture policy. You want the service to trigger a RADIUS change of authorization (CoA) when a client receives a Healthy or Quarantine posture. Where do you configure those rules?

Options

  • AIn a RADIUS enforcement policy
  • BIn the Agents and Software Updates > OnGuard Settings
  • CIn the posture policy
  • DIn a WEBAUTH enforcement policy

How the community answered

(21 responses)
  • A
    81% (17)
  • B
    5% (1)
  • C
    5% (1)
  • D
    10% (2)

Explanation

Option A is correct because a RADIUS enforcement policy is where you define the rules that trigger CoA actions based on posture results. When the Health Check Service evaluates a client and assigns a "Healthy" or "Quarantine" posture status, it's the RADIUS enforcement policy that maps those posture statuses to CoA messages sent back to the network device - effectively changing the client's network access in real time.

Why the distractors are wrong:

  • B (OnGuard Settings): This is where you configure the OnGuard agent behavior and software update settings - not network enforcement actions.
  • C (Posture policy): The posture policy defines what makes a client Healthy, Quarantine, or Infected (the checks and criteria). It does not define what to do once that status is determined.
  • D (WEBAUTH enforcement policy): This handles web authentication redirects (captive portal behavior). Even though the service is web-based, CoA is a RADIUS mechanism and belongs in a RADIUS enforcement policy, not WEBAUTH.

Memory tip: Split the problem in two - the posture policy answers "what is the client's health?" and the RADIUS enforcement policy answers "what do we do about it?" Since CoA is fundamentally a RADIUS function (it's literally a RADIUS message), the trigger rules always live in the RADIUS enforcement policy.

Topics

#RADIUS CoA#posture policy#OnGuard#RADIUS enforcement

Community Discussion

No community discussion yet for this question.

Full HPE7-A02 Practice