nerdexam
HP

HPE7-A08 · Question #114

A customer is starting to test AAA on their edge switch interfaces. The client device support team is concerned about clients being denied access to the network due to mistakes in configuration or…

The correct answer is B. Configure the critical role D. Configure the fallback role. When RADIUS authentication servers are unreachable, the critical role (B) automatically assigns connecting clients a predefined access level instead of denying them - directly addressing the server reachability concern. The fallback role (D) handles the configuration mistake…

Perform HPE Aruba Networking CX Switch Configurations

Question

A customer is starting to test AAA on their edge switch interfaces. The client device support team is concerned about clients being denied access to the network due to mistakes in configuration or reachability to the authentication servers. What should be enabled to address the concerns of the client device support team? (Select two)

Options

  • AConfigure onboarding-method concurrent
  • BConfigure the critical role
  • CConfigure auth-mode multi-device
  • DConfigure the fallback role
  • EConfigure port-access radius-override

How the community answered

(48 responses)
  • A
    4% (2)
  • B
    75% (36)
  • C
    8% (4)
  • E
    13% (6)

Explanation

When RADIUS authentication servers are unreachable, the critical role (B) automatically assigns connecting clients a predefined access level instead of denying them - directly addressing the server reachability concern. The fallback role (D) handles the configuration mistake scenario by providing a default role when authentication cannot complete successfully for any reason, ensuring clients aren't locked out due to misconfiguration.

Why the distractors are wrong:

  • A (onboarding-method concurrent) controls how multiple authentication methods run simultaneously, not how failures are handled.
  • C (auth-mode multi-device) allows multiple devices on a single port to authenticate independently - it's about port behavior, not failure handling.
  • E (port-access radius-override) overrides RADIUS attributes on a port but doesn't provide a safety net for server outages or config errors.

Memory tip: Think "CF = Client Failsafe" - Critical role catches server connection failures (unreachable server), Fallback role catches auth failures (bad config). Together they form a two-layer safety net that keeps clients on the network even when AAA isn't working perfectly.

Topics

#AAA#critical role#fallback role#port-access resiliency

Community Discussion

No community discussion yet for this question.

Full HPE7-A08 Practice