nerdexam
HP

HPE7-A08 · Question #94

An existing AOS-10 wireless deployment is expanding its zero-trust wireless network to multiple locations. The requirement is to propagate role information to enforce group-based policies for…

The correct answer is B. Configure "use switch fabric for role propagation" under Security -> Client Roles in HPE Aruba. Enabling "use switch fabric for role propagation" in HPE Aruba's Security → Client Roles settings is the correct mechanism because it allows the AOS-10 gateway fabric to share client role assignments network-wide, ensuring group-based policies are consistently enforced across…

Implement and Troubleshoot HPE Aruba Networking CX Switch Solutions

Question

An existing AOS-10 wireless deployment is expanding its zero-trust wireless network to multiple locations. The requirement is to propagate role information to enforce group-based policies for wireless client traffic across all locations. To achieve this goal, which must be configured in this infrastructure?

Options

  • AConfigure the gateways to mobility type and configure the Roles under System -> Client Roles in
  • BConfigure "use switch fabric for role propagation" under Security -> Client Roles in HPE Aruba
  • COverlay campus switch fabric with CX switches
  • DTunneled SSIDs with gateways

How the community answered

(40 responses)
  • A
    20% (8)
  • B
    68% (27)
  • C
    8% (3)
  • D
    5% (2)

Explanation

Enabling "use switch fabric for role propagation" in HPE Aruba's Security → Client Roles settings is the correct mechanism because it allows the AOS-10 gateway fabric to share client role assignments network-wide, ensuring group-based policies are consistently enforced across all locations without re-authenticating clients at each site.

Why the distractors are wrong:

  • A is wrong because configuring gateways to "mobility type" addresses client roaming continuity, not role distribution across a multi-site zero-trust deployment, and the menu path (System → Client Roles) is incorrect for this function.
  • C is wrong because overlaying CX switches upgrades wired campus infrastructure but has no direct effect on propagating wireless client roles across locations.
  • D is wrong because tunneled SSIDs route wireless traffic through gateways (useful for centralized policy enforcement), but tunneling alone does not propagate role identity to other sites.

Memory tip: Think of the switch fabric as the "nervous system" that carries role identity signals across the whole network - if you want roles to travel everywhere, you tell the fabric to carry them. The setting lives under Security (where policies live) → Client Roles (what you're propagating).

Topics

#zero-trust#role propagation#AOS-10#group-based policy

Community Discussion

No community discussion yet for this question.

Full HPE7-A08 Practice