HPE7-A02 Exam Questions
140 real HPE7-A02 exam questions with expert-verified answers and explanations. Page 2 of 3.
- Question #51Troubleshooting and Monitoring Network Security
You are setting up an HPE Aruba Networking VIA solution for a company. You have already created a VPN pool with IP addresses for the remote clients. During tests, however, the clie...
VIAVPN poolIP address assignmentclient role - Question #52Implementing Advanced Security Features
What is a typical use case for using HPE Aruba Networking ClearPass Onboard to provision devices?
ClearPass Onboardcertificate provisioning802.1XBYOD - Question #53Designing and Planning Network Security Deployments
What role can Internet Key Exchange (IKE)/IKEv2 play in an HPE Aruba Networking client-to-site VPN?
IKEIKEv2IPsecVPN negotiation - Question #54Implementing Advanced Security Features
A company uses HPE Aruba Networking ClearPass Policy Manager (CPPM) as a TACACS+ server to authenticate managers on its AOS-CX switches. The company wants CPPM to control which com...
TACACS+ClearPasscommand authorizationenforcement profile - Question #55Troubleshooting and Monitoring Network Security
An AOS-CX switch has this admin user account configured on it: netadmin in the operators group. You have configured these commands on an AOS-CX switch: tacacs-server host cp.exampl...
TACACS+fail-throughauthentication fallbackAOS-CX - Question #56Troubleshooting and Monitoring Network Security
A port-access role for AOS-CX switches has this policy applied to it: plaintext Copy code port-access policy mypolicy 10 class ip zoneC action drop 20 class ip zoneA action drop 10...
port-access policyACL rule orderingAOS-CXtraffic permit/deny - Question #57Implementing Advanced Security Features
You are setting up HPE Aruba Networking SSE to prohibit users from uploading and downloading files from Dropbox. What is part of the process?
SSEweb categoryDLPcloud application control - Question #58Implementing Advanced Security Features
You are setting up user-based tunneling (UBT) between access layer AOS-CX switches and AOS-10 gateways. You have selected reserved (local) VLAN mode. Tunneled devices include IoT d...
UBTVLAN assignmentIoT securityAOS-CX gateway - Question #59Designing and Planning Network Security Deployments
A company has a third-party security appliance deployed in its data center. The company wants to pass all traffic for certain clients through that device before forwarding that tra...
VNBTtraffic steeringservice chainingAOS-CX - Question #60Troubleshooting and Monitoring Network Security
You manage AOS-10 APs with HPE Aruba Networking Central. A role is configured on these APs with the following rules: Allow UDP on port 67 to any destination Allow any to network 10...
firewall rulesAOS-10rule orderingdenylist - Question #61Implementing Advanced Security Features
HPE Aruba Networking ClearPass Device Insight (CPDI) could not classify some endpoints using system and user rules. Using machine learning, it did assign those endpoints to a clust...
CPDImachine learning classificationendpoint profilingconfidence threshold - Question #62Implementing Advanced Security Features
You are setting up HPE Aruba Networking SSE. Which use case requires you to apply a non- default device posture in a rule?
SSEdevice postureaccess policyantivirus check - Question #63Implementing Advanced Security Features
Refer to Exhibit. All of the switches in the exhibit are AOS-CX switches. What is the preferred configuration on Switch-2 for preventing rogue OSPF routers in this network?
OSPF authenticationrogue router preventionAOS-CXMD5 mode - Question #64Troubleshooting and Monitoring Network Security
A company has HPE Aruba Networking gateways that implement gateway IDS/IPS. Admins sometimes check the Security Dashboard, but they want a faster way to discover if a gateway start...
IDS/IPSthreat alertsAruba Centralemail notifications - Question #65Troubleshooting and Monitoring Network Security
A company has Aruba APs that are controlled by Central and that implement WIDS. When you check WIDS events, you see a "detect valid SSID misuse" event. What can you interpret from...
WIDSSSID misuserogue AP detectionevil twin attack - Question #66Troubleshooting and Monitoring Network Security
A company is using HPE Aruba Networking ClearPass Device Insight (CPDI) (the standalone application). In the CPDI security settings, Security Analysis is On, the Data Source is Cle...
CPDIrisk scoreposture assessmentvulnerability detection - Question #67Designing and Planning Network Security Deployments
Which statement describes Zero Trust Security?
Zero Trustsecurity frameworkresource protectionperimeter security - Question #68Designing and Planning Network Security Deployments
A company has a variety of HPE Aruba Networking solutions, including an HPE Aruba Networking infrastructure and HPE Aruba Networking ClearPass Policy Manager (CPPM). The company pa...
internal threat protectionCPPM integrationSyslogfirewall integration - Question #69Troubleshooting and Monitoring Network Security
Refer to the exhibit. The exhibit shows a saved packet capture, which you have opened in Wireshark. You want to focus on the complete conversation between 10.1.70.90 and 10.1.79.11...
Wiresharkpacket capturestream analysistraffic filtering - Question #70Troubleshooting and Monitoring Network Security
Refer to the Exhibit. These packets have been captured from VLAN 10. which supports clients that receive their IP addresses with DHCP. What can you interpret from the packets that...
MAC spoofingpacket analysisDHCPattack detection - Question #71Implementing Advanced Security Features
A company is using HPE Aruba Networking Central SD-WAN Orchestrator to establish a hub- spoke VPN between branch gateways (BGWs) at 1164 site and VPNCs at multiple data centers. Wh...
SD-WANhub-spoke VPNBGW configurationVPNC - Question #72Implementing Advanced Security Features
A company has HPE Aruba Networking APs running AOS-10 that connect to AOS-CX switches. The APs will: Authenticate as 802.1X supplicants to HPE Aruba Networking ClearPass Policy Man...
802.1XVLAN assignmentAP traffic forwardingAOS-CX roles - Question #73Implementing Advanced Security Features
A company has AOS-CX switches, which authenticate clients to HPE Aruba Networking ClearPass Policy Manager (CPPM). CPPM is set up to receive a variety of information about clients'...
dynamic authorizationCoARADIUSCPPM enforcement - Question #74Implementing Advanced Security Features
A company already uses HPE Aruba Networking ClearPass Policy Manager (CPPM) as the RADIUS server for authenticating wireless clients with 802.1X. Now you are setting up 802.1X on A...
ClearPass service rules802.1Xwired authenticationservice configuration - Question #75Implementing Advanced Security Features
You are configuring the HPE Aruba Networking ClearPass Device Insight Integration settings on ClearPass Policy Manager (CPPM). For which use case should you set the 'Tag Updates Ac...
CPDI integrationtag updatesCoAenforcement policy - Question #76Implementing Advanced Security Features
You are helping an organization deploy HPE Aruba Networking SSE. What is one reason to recommend that the company install agents on remote users' devices?
SSEdevice agentposture checksremote access - Question #77Troubleshooting and Monitoring Network Security
You want to examine the applications that a device is using and look for any changes in application usage over several different ranges. In which HPE Aruba Networking solution can...
application monitoringAruba Centrallive monitoringdevice visibility - Question #78Implementing Advanced Security Features
A company wants to use HPE Aruba Networking ClearPass Policy Manager (CPPM) to profile Linux devices. You have decided to schedule a subnet scan of the devices' subnets. Which addi...
CPPM profilingsubnet scandata portLinux device discovery - Question #79Implementing Advanced Security Features
HPE Aruba Networking switches are implementing MAC-Auth to HPE Aruba Networking ClearPass Policy Manager (CPPM) for a company's printers. The company wants to quarantine a client t...
MAC spoofingMAC-Authenforcement policyendpoint conflict - Question #80Implementing Advanced Security Features
A company wants to apply role-based access control lists (ACLs) on AOS-CX switches, which are implementing authentication to HPE Aruba Networking ClearPass Policy Manager (CPPM). T...
role-based ACLAOS-CXCPPMcentralized policy - Question #81Troubleshooting and Monitoring Network Security
A company has HPE Aruba Networking APs running AOS-10 and managed by HPE Aruba Networking Central. The company also has AOS-CX switches. The security team wants you to capture traf...
packet capturePCAPHPE Aruba Centralwireless client monitoring - Question #82Implementing Advanced Security Features
A company needs you to integrate HPE Aruba Networking ClearPass Policy Manager (CPPM) with HPE Aruba Networking ClearPass Device Insight (CPDI). What is one task you should do to p...
CPPM integrationClearPass Device Insightserver configurationCPDI - Question #83Implementing Advanced Security Features
A company wants you to create a custom device fingerprint on CPPM with rules for profiling a group of specialized devices. What is one requirement?
device fingerprintingendpoint profilingCPPMcustom fingerprint - Question #84Implementing Advanced Security Features
Refer to the exhibit. The exhibit shows the TACACS+ enforcement profile that HPE Aruba Networking ClearPass Policy Manager (CPPM) assigns to a manager. When this manager logs into...
TACACS+AOS-CXprivilege levelsenforcement profiles - Question #85Troubleshooting and Monitoring Network Security
You are using Wireshark to view packets captured from HPE Aruba Networking infrastructure, but you're not sure that the packets are displaying correctly. In which circumstance does...
Wireshark802.11packet capturewireless traffic analysis - Question #86Implementing Advanced Security Features
You have enabled "rogue AP containment" in the Wireless IPS settings for a company's HPE Aruba Networking APs. What form of containment does HPE Aruba Networking recommend?
rogue AP containmentWIPSwireless deauthenticationwireless IPS - Question #87Implementing Advanced Security Features
The exhibit shows the 802.1X-related settings for Windows domain clients. What should admins change to make the settings follow best security practices?
802.1XWindows domaincertificate validationserver name verification - Question #88Implementing Advanced Security Features
Refer to the exhibit. You have verified that AOS-CX Switch-1 has constructed an IP-to-MAC binding table in VLANs 10-19. Now you need to enable ARP inspection for the endpoint conne...
ARP inspectionAOS-CXtrusted portsDHCP snooping - Question #89Implementing Advanced Security Features
A company has AOS-CX switches and HPE Aruba Networking APs, which run AOS-10 and bridge their SSIDs. Company security policies require 802.1X on all edge ports, some of which conne...
802.1X auth-modeAOS-CXAP bridgingdevice auth - Question #90Implementing Advanced Security Features
You need to create a rule in an HPE Aruba Networking ClearPass Policy Manager (CPPM) role mapping policy that references a ClearPass Device Insight Tag. Which Type (namespace) shou...
CPPM role mappingClearPass Device Insightnamespaceendpoint tags - Question #91Designing and Planning Network Security Deployments
What is one benefit of integrating HPE Aruba Networking ClearPass Policy Manager (CPPM) with third-party solutions such as Mobility Device Management (MDM) and firewalls?
CPPM integrationMDMfirewallcontextual information sharing - Question #92Implementing Advanced Security Features
What is a benefit of Online Certificate Status Protocol (OCSP)?
OCSPcertificate revocationPKIdigital certificates - Question #93Implementing Advanced Security Features
You have created a Web-based Health Check Service that references a posture policy. You want the service to trigger a RADIUS change of authorization (CoA) when a client receives a...
RADIUS CoAposture policyOnGuardRADIUS enforcement - Question #94Implementing Advanced Security Features
You have configured an AOS-CX switch to implement 802.1X on edge ports. Assume ports operate in the default auth-mode. VoIP phones are assigned to the "voice" role and need to send...
802.1Xvoice VLANAOS-CX rolesVLAN assignment - Question #95Implementing Advanced Security Features
A company wants to detect rogue APs and automatically prevent unauthorized access to its WLAN. Which security feature should be enabled?
WIPSrogue AP detectionwireless IPSunauthorized access - Question #96Designing and Planning Network Security Deployments
What is the primary function of Public Key Infrastructure (PKI) in network security?
PKIdigital certificatesencryptioncertificate authority - Question #97Implementing Advanced Security Features
A security administrator at a company detects unauthorized devices attempting to connect to the network. The company uses Aruba ClearPass for authentication. Which solution should...
CPDI profilingunauthorized devicesClearPassdevice detection - Question #98Troubleshooting and Monitoring Network Security
Which log level is the most critical for analyzing security threats?
log levelssyslogsecurity monitoringthreat analysis - Question #99Implementing Advanced Security Features
Which authentication protocol is used in Aruba VPN deployments for secure user authentication?
EAP-TLSVPN authenticationAruba VPNauthentication protocols - Question #100Troubleshooting and Monitoring Network Security
A security team wants to use passive classification methods to profile unauthorized devices attempting to connect to their network. Which technique should be used?
passive profilingdevice classificationtraffic monitoringendpoint profiling