nerdexam
HP

HPE7-A02 · Question #94

You have configured an AOS-CX switch to implement 802.1X on edge ports. Assume ports operate in the default auth-mode. VoIP phones are assigned to the "voice" role and need to send traffic that is…

The correct answer is B. As the allowed trunk VLAN in the "voice" role (and not in the edge port settings). In AOS-CX 802.1X with role-based access control, the role overrides port-level VLAN assignments for authenticated devices - meaning VLAN 12 belongs in the "voice" role as a trunk allowed VLAN, not on the edge port itself. Since VoIP phones must send tagged frames for VLAN 12…

Implementing Advanced Security Features

Question

You have configured an AOS-CX switch to implement 802.1X on edge ports. Assume ports operate in the default auth-mode. VoIP phones are assigned to the "voice" role and need to send traffic that is tagged for VLAN 12. Where should you configure VLAN 12?

Options

  • AAs the trunk native VLAN on edge ports and the trunk native VLAN on the "voice" role.
  • BAs the allowed trunk VLAN in the "voice" role (and not in the edge port settings).
  • CAs a trunk allowed VLAN on edge ports and the trunk native VLAN in the "voice" role.
  • DAs the trunk native VLAN in the "voice" role (and not in the edge port settings).

How the community answered

(34 responses)
  • A
    26% (9)
  • B
    56% (19)
  • C
    12% (4)
  • D
    6% (2)

Explanation

In AOS-CX 802.1X with role-based access control, the role overrides port-level VLAN assignments for authenticated devices - meaning VLAN 12 belongs in the "voice" role as a trunk allowed VLAN, not on the edge port itself. Since VoIP phones must send tagged frames for VLAN 12, it must be an allowed (not native) trunk VLAN in the role, making B correct.

Why the distractors fail:

  • A is wrong on two counts: native VLAN carries untagged traffic (phones need tagged), and duplicating VLAN config on both the port and the role is not how AOS-CX roles work - the role takes precedence.
  • C is wrong because configuring VLAN 12 on the edge port is redundant when a role handles it, and assigning it as the native VLAN in the role would make it untagged - contradicting the requirement for tagged traffic.
  • D is tempting but wrong: native VLAN = untagged. Phones explicitly need tagged VLAN 12 traffic, so "trunk native" is the wrong setting regardless of where it's placed.

Memory tip: Think "Role Rules, Tagged Means Allowed." In 802.1X role-based mode, the role owns VLAN control (not the port), and tagged traffic always maps to an allowed trunk VLAN - never the native VLAN.

Topics

#802.1X#voice VLAN#AOS-CX roles#VLAN assignment

Community Discussion

No community discussion yet for this question.

Full HPE7-A02 Practice