option
Questions
ayuda
daypo
search.php

A.C.P.C.A

COMMENTS STATISTICS RECORDS
TAKE THE TEST
Title of test:
A.C.P.C.A

Description:
Pro Campus

Creation Date: 2026/04/27

Category: Others

Number of questions: 119

Rating:(0)
Share the Test:
Nuevo ComentarioNuevo Comentario
New Comment
NO RECORDS
Content:

Which feature supported by SNMPv3 provides an advantage over SNMPv2c?. Transport mapping. Community strings. GetBulk. Encryption.

You are doing tests in your lab and with the following equipment specifications AP1 has a radio that generates a 10 dBm signal AP2 has a radio that generates a 11 dBm signal AP1 has an antenna with a gain of 9 dBi AP2 has an antenna with a gain of 12 dBi. The antenna cable for AP1 has a 2 dB loss The antenna cable for AP2 has a 3 dB loss What would be the calculated Equivalent Isotropic Radiated Power (EIRP) for AP1?. 26 dBm. 30 dBm. 17 dBm. -12 dBm.

With Aruba CX 6300. how do you configure ip address 10 10 10 1 for the interface in default state for interface 1/1/1?. int 1/1/1. switching, ip address 10 10 10 1/24. int 1/1/1. no switching, ip address 10 10 10.1/24. int 1/1/1. ip address 10.10.10.1/24. int 1/1/1. routing, ip address 10.10.10 1/24.

A system engineer needs to preconfigure several Aruba CX 6300 switches that will be sent to a remote office An untrained local field technician will do the rollout of the switches and the mounting of several AP-515s and AP-575. Cables running to theAPs are not labeled. The VLANs are already preconfigured to VLAN 100 (mgmt), VLAN 200 (clients), and VLAN 300 (guests) What is the correct configuration to ensure that APs will work properly?. A. B. C. D.

Your Director of Security asks you to assign AOS-CX switch management roles to new employees based on their specific job requirements After the configuration was complete, it was noted that a user assigned with the administrators role did not have the appropriate level of access on the switch. The user was not limited to viewing nonsensitive configuration information and a level of 1 was not assigned to their role Which default management role should have been assigned for the user?. sysadmin. operators. helpdesk. config.

A new network design is being considered to minimize client latency in a high density environment. The design needs to do this by eliminating contention overhead by dedicating subcarriers to clients. Which technology is the best match for this use case?. OFDMA. MU-MIMO. QWMM. Channel Bonding.

Your manufacturing client is having installers deploy seventy headless scanners and fifty IP cameras in their warehouse These new devices do not support 802 1X authentication. How can HPE Aruba reduce the IT administration overhead associated with this deployment while maintaining a secure environment using MPSK?. Have the installers generate keys with ClearPass Self Service Registration. Have the MPSK gateway derive the unique pre-shared keys based on the MAC OUI. Use MPSK Local to automatically provide unique pre-shared keys for devices. MPSK Local will allow the cameras to share a key and the scanners to share a different key.

Which component is used by the Aruba Network Analytics Engine (NAE)?. JSON-based scripts. Lisp-based agents. Ruby-based scripts. Current State Database.

You need to have different routing-table requirements with Aruba CX 6300 VSF configuration Assuming the correct layer-2 VLAN already exists how would you create a new OSPF configuration for a separate routing table?. Create a new OSPF area, and attach VRF name. Create a new OSPF process ID with vrf name. Attach a new OSFP process ID with a custom routing table. Attach OSPF process ID in the VRF configuration.

With the Aruba CX switch configuration, what is the first-hop protocol feature that is used for VSX L3 gateway as per Aruba recommendation?. Active Gateway. Active-Active VRRP. SVI with vsx-sync. VRRP.

You are deploying a bonded 40 MHz wide channel What is the difference in the noise floor perceived by a client using this bonded channel as compared to an unbonded 20MHz wide channel?. 2dB. 3dB. 8dB. 4dB.

When setting up an Aruba CX VSX pair, which information does the Inter-Switch Link Protocol configuration use in the configuration created?. QSVI. MAC tables. UDLD. RPVST+.

What is true regarding 802.11k?. It extends radio measurements to define mechanisms for wireless network management of stations. It reduces roaming delay by pre-authenticating clients with multiple target APs before a client roams to an AP. It provides mechanisms for APs and clients to dynamically measure the available radio resources. It considers several metrics before it determines if a client should be steered to the 5GHz band, including client RSSI.

Your customer is interested in hearing more about how roles can help keep consistent policy enforcement in a distributed overlay fabric How would you explain this concept to them?. Group Based Policy ID is applied on egress VTEP after device authentication and policy is enforced on ingress VTEP. Role-based policies are tied to IP addresses which have an advantage over IP-based policies and role names are sent between VTEPs. Group Based Policy ID is applied on ingress VTEP after device authentication and policy is enforced on egress VTEP. Role-based policies enhance User Based Tunneling across the campus network and the policy traffic is protected with iPsec.

How is Multicast Transmission Optimization implemented in an HPE Aruba wireless network?. The optimal rate for sending multicast frames is based on the highest broadcast rate across all associated clients. When this option is enabled the minimum default rate for multicast traffic is set to 12 Mbps for 5GHz. The optimal rate for sending multicast frames is based on the lowest broadcast rate across all associated clients. The optimal rate for sending multicast frames is based on the lowest unicast rate across all associated clients.

You are setting up a customer's 15 headless loT devices that do not support 802.1X. What should you use?. Multiple Pre-Shared Keys (MPSK) Local. Clearpass with WPA3-PSK. Clearpass with WPA3-AES. Multiple Pre-Shared Keys (MPSK) with WPA3-AES.

How do you allow a new VLAN 100 between VSX pair inter-switch-link 256 for port 1/45 and 2/45?. vlan trunk allowed 100 for ports 1/45 and 1/46. vlan trunk add 100 in LAG256. vlan trunk allowed 100 in LAG256. vlan trunk add 100 in MLAG256.

Two AOS-CX switches are configured with VSX at the the Access-Aggregation layer where servers to them An SVI interface is configured for VLAN 10 and serves as the default gateway for VLAN 10. The ISL link between the switches fails, but the keepalive interface functions. Active gateway has been configured on the VSX switches. What is correct about access from the servers to the Core? (Select two.). Server 1 can access the core layer via the keepalrve link. Server 2 can access the core layer via the keepalive link. Server 2 cannot access the core layer. Server 1 can access the core layer via both uplinks. Server 1 and Server 2 can communicate with each other via the core layer. Server 1 can access the core layer on only one uplink.

A large retail client is looking to generate a rich set of contextual data based on the location information of wireless clients in their stores Which standard uses Round Trip Time (RTT) and Fine Time Measurements (FTM) to calculate the distance a client is from an AP?. 802.11ah. 802.11mc. 802.11be. 802.11V.

You need to create a keepalive network between two Aruba CX 8325 switches for VSX configuration How should you establish the keepalive connection?. SVI, VLAN trunk allowed all on ISL in default VRF. routed port in custom VRF. loopback 0 and OSPF area 0 in default VRF. SVI, VLAN trunk allowed all on ISL in custom VRF.

Which method is used to onboard a new UXI in an existing environment with 802 1X authentication? (The sensor has no cellular connection). Use the UXI app on your smartphone and connect the UXI via Bluetooth. Use the Aruba installer app on your smartphone to scan the barcode. Connect the new UXI from an already installed one and adjust the initial configuration. Use the CLI via the serial cable and adjust the initial configuration.

A customer is using a legacy application that communicates at layer-2. The customer would like to keep this application working to a remote site connected via layer-3 All legacy devices are connected to a dedicated Aruba CX 6200 switch at each site. What technology on the Aruba CX 6200 could be used to meet this requirement?. Inclusive Multicast Ethernet Tag (IMET). Ethernet over IP (EolP). Generic Routing Encapsulation (GRE). Static VXLAN.

Your customer is complaining of weak Wi-Fi coverage in their office. They mention that the office on the other side of the hall has much better signal What is the likely cause of this issue?. The AP is a remote access point. The AP is using a directional antenna. The AP is an outdoor access point. The AP is configured in Mesh mode.

Your customer has asked you to assign a switch management role for a new user The customer requires the user role to only have Web Ul access to the System > Log page and only have access to the GET method for REST API for the /logs/event resource Which default AOS-CX user role meets these requirements?. administrators. auditors. sysops. operators.

You are configuring Policy Based Routing (PBR) for a subnet that will be used to test a new default route for your network Traffic originating from 10.2.250.0 should use a new default route to 10.1.1.253. Other non-default routes for this subnet should not be affected by this change. What are two parts of the solution for these requirements? (Select two.). A: pbr-action list def_route_test default-nexthop 10.1.1.253/24. B: class ip test_subnet 10 match any 10.2.250.0/24 any policy def_route_test_policy 10 class ip test_subnet action pbr def_route_test interface vlan 100 ip address 10.2.250.0/24 apply policy pbr_test routed in. C: class ip test_subnet 10 match any 10.2.250.0 255.255.255.0 any policy def_route_test_policy 10 class ip ip_test_subnet action pbr def_route_test interface vlan 100 ip address 10.2.250.0/24 apply policy pbr_test routed out. D: pbr-action-list def_route_test default-nexthop 10.1.1.253 interface null. E: pbr-action-list def_route_test nexthop 10.1.1.253 interface null.

With Core-1. what is the default value for config-revision?. A: 0. B. 1. C. 1-0. D. 0. 0.

What are the requirements to ensure that WMM is working effectively? (Select two). The APs and the controller are Wi-Fi CERTIFIED for WMM which is enabled. All APs need to be from the Axx series and Axx series which are Wi-Fi CERTIFIED 6. The Client must be Wi-Fi CERTIFIED for WMM and configured for WMM marking. The Aruba AOS10 APs installed have to be converted to controlled mode. The AP needs to be connected via a tagged VLAN to the wired port.

You are troubleshooting an issue with a 10 102.39 0 subnet which is also VLAN 1000 used For wireless clients on a pair of Aruba CX 8360 switches The subnet SVI is configured on the 8360 pair, and the DHCP server is a Microsoft Windows Server 2022 Standard with an IP address of 10 200.1.100. The 10.102.250.0 subnet is used for switch management. A large number of DHCP requests are failing You are observing sporadic DHCP behavior across clients attached to the CX 6100 switch. Which action may help fix the issue?. A: Enter the following commands on the VSX Primary Switch: vsx vsx-sync dhcp-relay exit. B: Enter the following commands on the VSX secondary switch: vlan 1000 ip relay-address 10.200.1.100 exit. C: add an SVI in the 10.102.39.0/24 subnet on the Aruba CX 6100 switch that the APs are connected to. D: Enter the following commands on the Aruba CX 6100 Switch: interface vlan 1000 ip helper-address 10.200.1.100 exit.

In an ArubaOS 10 architecture using an AP and a gateway, what happens when a client attempts to join the network and the WLAN is configured with OWE?. Authentication information is not exchanged. The Gateway will not respond. No encryption is applied. RADIUS protocol is utilized.

Which Aruba AP mode is sending captured RF data to Aruba Central for waterfall plot?. Hybrid Mode. Air Monitor. Spectrum Monitor. Dual Mode.

What is a primary benefit of BSS coloring?. BSS color tags improve performance by allowing clients on the same channel to share airtime. BSS color tags are applied to client devices and can reduce the threshold for interference. BSS color tags are applied to Wi-Fi channels and can reduce the threshold for interference. BSS color tags improve security by identifying rogue APs and removing them from the network.

What is the best practice for handling voice traffic with dynamic segmentation on AOS-CX switches?. Switch authentication and local forwarding of the voice traffic. Switch authentication and user-based tunneling of the voice traffic. Central authentication and port-based tunneling of the voice traffic. Controller authentication and port-based tunneling of all traffic.

A network administrator is attempting to troubleshoot a connectivity issue between a group of users and a particular server The administrator needs to examine the packets over a period of time from their desktop; however, the administrator is not directly connected to the AOS-CX switch involved with the traffic flow. What statements are correct regarding the ERSPAN session that needs to be established on an AOSCX switch'? (Select two ). On the source AOS-CX switch, the destination specified is the switch to which the administrator's desktop is connected. The encapsulation protocol used is GRE. The encapsulation protocol used is VXLAN. The encapsulation protocol is UDP. On the source AOS-CX switch, the destination specified is the administrators desktop.

On AOS10 Gateways, which device persona is only available when configuring a Gateway-only group'?. Edge. Mobility. Branch. VPN Concentrator.

A company deployed Dynamic Segmentation with their CX switches and Gateways After performing a security audit on their network, they discovered that the tunnels built between the CX switch and the Aruba Gateway are not encrypted. The company is concerned that bad actors could try to insert spoofed messages on the Gateway to disrupt communications or obtain information about the network. Which action must the administrator perform to address this situation?. Enable Secure Mode Enhanced. Enable Enhanced security. Enable Enhanced PAPI security. Enable GRE security.

What is an Aruba-recommended best practice for hardening that only applies to Aruba CX 6300 series switches with dedicated management ports?. Implement a control plane ACL to limit access to approved IPs and/or subnets. Manually enable Enhanced Security Mode from a console session. Disable all management services on the default VRF. Create a dedicated management VRF, and assign the management port to it.

What is enabled by LLDP-MED? (Select two.). Voice VLANs can be automatically configured for VoIP phones. APs can request power as needed from PoE-enabled switch ports. iSCSl client devices can request to have flow control enabled. GVRP VLAN information can be used to dynamically add VLANs to a trunk. iSCSl client devices can set the required MTU setting for the port.

You need to ensure that voice traffic sent through an ArubaOS-CX switch arrives with minimal latency What is the best scheduling technology to use for this task?. Strict queuing. Rate limiting. QoS shaping. DWRR queuing.

You are helping an onsite network technician bring up an Aruba 9004 gateway with ZTP for a branch office The technician was to plug in any port for the ZTP process to start Thirty minutes after the gateway was plugged in new users started to complain they were no longer able to get to the internet. One user who reported the issue stated their IP address is 172.16 0.81 However, the branch office network is supposed to be on 10.231 81.0. What should the technician do to alleviate the issue and get the ZTP process started correctly?. Turn off the DHCP scope on the gateway, and set DNS correctly on the gateway to reach Aruba Activate. Move the cable on the gateway from port G0/1 to port G0/0. Move the cable on the gateway to G0/0 and add the device's MAC and Serial number in Central. Factory default and reboot the gateway to restart the process.

A company recently deployed new Aruba Access Points at different branch offices Wireless 802.1X authentication will be against a RADIUS server in the cloud. The security team is concerned that the traffic between the AP and the RADIUS server will be exposed. What is the appropriate solution for this scenario?. Enable EAP-TLS on all wireless devices. Configure RadSec on the AP and Aruba Central. Enable EAP-TTLS on all wireless devices. Configure RadSec on the AP and the RADIUS server.

A customer is using stacked Aruba CX 6200 and CX 6300 switches for access and a VSX pair of Aruba CX 8325 as a collapsed core 802.1X is implemented for authentication. Due to the lack of cabling, some unmanaged switches are still in use Sometimes devices behind these switches cause network outages The switch should send a warning to the helpdesk when the problem occurs You have been asked to implement an effective solution to the problem What is the solution for this?. Configure spanning tree on the Aruba CX 8325 switches Set the trap option. Configure loop protection on all edge ports of the Aruba CX 6200 and CX 6300 switches No trap option is needed. Configure loop protection on all edge ports of the Aruba CX 6200 and CX 6300 switches Set up the trap-option. Configure spanning tree on the Aruba CX 6200 and CX 6300 switches No trap option is needed.

A customer wants to enable wired authentication across all their CX switches One of the requirements is that the switch must be able to authenticate a single computer connected through a VoIP phone. Which feature should be enabled to support this requirement?. Multi-Domain Authentication. Device-Based Mode. MAC Authentication. Multi-Auth Mode.

A company has deployed 200 AP-635 access points. To but is not working as expected What would be the correct action to fix the issue?. Change the SSID to WPA3-Enhanced Open. Change the SSID to WPA3-Enterprise (CCM). Change the SSID to WPA3-Personal. Change the SSID to WPA3-Enterpnse (CNSA).

A customer is using Aruba Cloud Guest, but visitors keep complaining that the captive portal page keeps coming up after devices go to sleep Which solution should be enabled to deal with this issue?. MAC Caching under the splash page. MAC Caching under the user-role. Wireless Caching under the splash page. MAC Caching under the WLAN.

Your customer is having connectivity issues with a newly deployed Microbranch group The access points in this group are online in Aruba Central, but no VPN tunnels are forming. What is the most likely cause of this issue?. There is a time difference between the AP and the gateways The gateways should have NTP added. The SSL certificate on the gateway used to encrypt the connection has not been added to the APs trust list. There may be a firewall blocking GRE tunneling between the AP and the gateway. The gateway group is running in automatic cluster mode and should be in manual cluster mode.

Which statements regarding OSPFv2 route redistribution are true for Aruba OS CX switches? (Select two.). The "redistribute connected" command will redistribute all connected routes for the switch including local loopback addresses. The "redistribute ospf" command will redistribute routes from all OSPF V2 and V3 processes. The "redistribute static route-map connected-routes" command will redistribute all static routes without a matching deny in the route map "connected-routes". The "redistribute connected" command will redistribute all connected routes for the switch except local loopback addresses. The "redistribute static route-map connected-routes" command will redistribute all static routes with a matching permit in the route map "connected-routes.

You are configuring an SVI on an Aruba CX switch that needs to have the following characteristics: VLANID = 25 IPv4 address 10 105 43 1 with mask 255 255 255.0 IPv6 address fd00:5708::f02d:4df6 with a 64 bit prefix length member of VRF eng VRF eng and VLAN 25 have not yet been created Which command lists will satisfy the requirements with the least number of commands?. vrf eng vlan 25 interface vlan 25 ip address 10.105.43.1 255.255.255.0 ipv6 address fd00:5708::f02d:4df6/64 vrf attach eng. interface vlan 25 vrf attach eng ip address 10.105.43.1/24 ipv6 address fd00:5708::f02d:4df6/64. interface vlan 25 vrf attach eng ip address 10.105.43.1/24 ipv6 address fd00:5708::f02d:4df6/64. vrf eng vlan 25 interface vlan 25 ip address 10.105.43.1/24 ipv6 address fd00:5708::f02d:4df6/64 vrf attach eng.

Match the solution components of NetConductor (Options may be used more than once or not at all.). Client Insight. Cloud Auth. The Fabric Wizard. Policy Manager.

What is one advantage of using OCSP vs CRLs for certificate validation?. reduces latency between the time a certificate is revoked and validation reflects this status. less complex to implement. higher availability for certificate validation. supports longer certificate validity periods.

A customer wants to provide wired security as close to the source as possible The wired security must meet the following requirements: - allow ping from the IT management VLAN to the user VLAN - deny ping sourcing from the user VLAN to the IT management VLAN The customer is using Aruba CX 6300s What is the correct way to implement these requirements?. Apply an outbound ACL on the user VLAN allowing temp echo-reply traffic toward the IT management VLAN. Apply an inbound ACL on the user VLAN allowing icmp echo-reply traffic toward the IT management VLAN. Apply an inbound ACL on the user VLAN denying icmp echo traffic toward the IT management VLAN. Apply an outbound ACL on the user VLAN denying icmp echo traffic toward the IT management VLAN.

In AOS 10. which session-based ACL below will only allow ping from any wired station to wireless clients but will not allow ping from wireless clients to wired stations"? The wired host ingress traffic arrives on a trusted port. ip access-list session pingFromWired any user any permit. ip access-list session pingFromWired user any svc-icmp deny any any svc-icmp permit. ip access-list session pingFromWired any any svc-icmp permit user any svc-icmp deny. ip access-list session pingFromWired any any svc-icmp deny any user svc-icmp permit.

The administrator notices that wired guest users that have exceeded their bandwidth limit are not being disconnected Access Tracker in ClearPass indicates a disconnect CoA message is being sent to the AOS-CX switch. An administrator has performed the following configuration What is the most likely cause of this issue?. Change of Authorization has not been globally enabled on the switch. The SSL certificate for CPPM has not been added as a trust point on the switch. There is a mismatch between the RADIUS secret on the switch and CPPM. There is a time difference between the switch and the ClearPass Policy Manager.

What is the order of operations tor Key Management service for a wireless client roaming from AP1to AP2?. 1. 2. 3. 4. 5.

A customer is looking for a wireless authentication solution for all of their loT devices that meet the following requirements -The wireless traffic between the IoT devices and the Access Points must be encrypted -Unique passphrase per device -Use fingerprint information to perform role-based access Which solutions will address the customer's requirements? (Select two.). MPSK and an internal RADIUS server. MPSK Local with MAC Authentication. ClearPass Policy Manager. MPSK Local with EAP-TLS. Local User Derivation Rules.

You are troubleshooting an issue with a pair of Aruba CX 8360 switches configured with VSX Each switch has multiple VRFs. You need to find the IP address of a particular client device with a known MAC address You run the "show arp" command on the primary switch in the pair but do not find a matching entry for the client MAC address. The client device is connected to an Aruba CX 6100 switch by VSX LAG. Which action can be used to find the IP address successfully?. Run the following commande on the CX 6100 Switch "show mac-address-table". Run the following commande on the VSX primary switch "show arp all-vrfs". Run the following commande on the VSX primary switch "show mac-address-table". Run the following commande on the CX 6100 Switch "show arp all-vrfs".

Which statements regarding Aruba NAE agents are true? (Select two ). A single NAE script can be used by multiple NAE agents. NAE agents are active at all times. NAE agents will never consume more than 10% of switch processor resources. NAE scripts must be reviewed and signed by Aruba before being used. A single NAE agent can be used by multiple NAE scripts.

What is an OSPF transit network?. a network that uses tunnels to connect two areas. a special network that connects two different areas. a network on which a router discovers at least one neighbor. a network that connects to a different routing protocol.

Describe the difference between Class of Service (CoS) and Differentiated Services Code Point (DSCP). CoS has much finer granularity than DSCP. CoS is only contained in VLAN Tag fields DSCP is in the IP Header and preserved throughout the IP packet flow. They are similar and can be used interchangeably. CoS is only used to determine CLASS of traffic DSCP is only used to differentiate between different Classes.

A network administrator is troubleshooting some issues guest users are having when connecting and authenticating to the network The access switches are AOS-CX switches. What command should the administrator use to examine information on which role the guest user has been assigned?. show aaa authentication port-access interface all client-status. show port-access captiveportal profile. show port-access role. diag-dump captiveportal client verbose.

Using Aruba best practices what should be enabled for visitor networks where encryption is needed but authentication is not required?. Wi-Fi Protected Access 3 Enterprise. Opportunistic Wireless Encryption. Wired Equivalent Privacy. Open Network Access.

Which statements are true about VSX LAG? (Select two.). The total number of configured links may not exceed 8 for the pair or 4 per switch. Outgoing traffic is switched to a port based on a hashing algorithm which may be either switch in the pair. LAG traffic is passed over VSX ISL links only while upgrading firmware on the switch pair. Outgoing traffic is preferentially switched to local members of the LAG. Up to 255 VSX lags can be configured on all 83xx and 84xx model switches.

What steps are part of the Key Management workflow when a wireless device is roaming from AP1 to AP2? (Select two.). AP1 will cache the client's information and send it to the Key Management service. The Key Management service receives from AirMatch a list of all AP2's neighbors. The Key Management service receives a list of all AP1 s neighbors from AirMatch. The Key Management service then generates R1 keys for AP2's neighbors. A client associates and authenticates with the AP2 after roaming from AP1.

What are two advantages of splitting a larger OSPF area into a number of smaller areas? (Select two ). It extends the LSDB. It increases stability. it simplifies the configuration. It reduces processing overhead. It reduces the total number of LSAs.

Your Aruba CX 6300 VSF stack has OSPF adjacency over SVI 10 with LAG 1 to a neighboring device The following configuration was created on the switch: A. Vlan 20,30,40 ospf passive. B. interface vlan 20,30,40 ip ospf passive. C. router ospf 1 area 0 passive-interface 20,30,40. D. router ospf 1 area 0 redistribute local.

Which feature allows the device to remain operational when a remote link failure occurs between a Gateway cluster and a RADIUS server that is either in the cloud or a datacenter?. MAC caching. MAC Authentication. Authentication survivability. Opportunistic key caching.

The customer needs a network hardware refresh to replace an aging Aruba 5406R core switch pair using spanning tree configuration with Aruba CX 8360-32YC switches What is the benefit of VSX clustering with the new solution?. Stacked data-plane. faster MSTP converge processing. dual Aruba AP LAN port connectivity for PoE redundancy. dual control plane provides better resiliency.

A customer has a large number of food-producing machines All machines are connected via Aruba CX6200 switches in VLANs 100.110. and 120 Several external technicians are maintaining this special equipment What are the correct commands to ensure that no rogue DHCP server will impact the network?. dhcp-snooping enable no dhcp-snooping option 82 dhcp-snooping vlan 100-120 vlan 100 name cornflakes vlan 110 name cornmill vlan 120 name packaging interface lag 1 no shutdown description Uplink-to-Core no routing vlan trunk native 1 vlan trunk allowed all lacp mode active dhcp-snooping trust. dhcp snooping enable no dhcp-snooping option 82 vlan 100 name cornflakes dhcp-snooping vlan 110 name cornmill dhcp-snooping vlan 120 name packaging dhcp-snooping interface lag 1 no shutdown description Uplink-to-Core no routing vlan trunk native 1 vlan trunk allowed all lacp mode active dhcp snooping trust. dhcpv4-snooping all vlans no dhcpv4-snooping option 82 interface lag 1 no shutdown description Uplink-to-Core no routing vlan trunk native 1 vlan trunk allowed all lacp mode active dhcpv4-snooping trust. dhcpv4-snooping no dhcpv4-snooping option 82 vlan 100 name cornflakes dhcpv4-snooping vlan 110 name cornmill dhcpv4-snooping vlan 120 name packaging dhcpv4-snooping interface lag 1 no shutdown description Uplink-to-Core no routing vlan trunk native 1 vlan trunk allowed all lacp mode active dhcpv4-snooping trust.

For the Aruba CX 6400 switch, what does virtual output queueing (VOQ) implement that is different from most typical campus switches?. Large ingress packet buffers. Large egress packet buffers. per port ASICs. VSX.

Which statement best describes QoS?. Determining which traffic passes specified quality metrics. Scoring traffic based on the quality of the contents. Identifying specific traffic for special treatment. Identifying the quality of the connection.

Select the Aruba stacking technology matching each option (Options may be used more than once or not at all.). VSF. VSX.

A network engineer recently identified that a wired device connected to a CX Switch is misbehaving on the network To address this issue, a new ClearPass policy has been put in place to prevent this device from connecting to the network again. Which steps need to be implemented to allow ClearPass to perform a CoA and change the access for this wired device? (Select two.). Confirm that NTP is configured on the switch and ClearPass. Configure dynamic authorization on the switch. Bounce the switchport. Use Dynamic Segmentation. Configure dynamic authorization on the switchport.

A customer is using a legacy application that communicates at layer-2. The customer would like to keep this application working across the campus which is connected via layer-3. The legacy devices are connected to Aruba CX 6300 switches throughout the campus. Which technology minimizes flooding so the legacy application can work efficiently?. Generic Routing Encapsulation (GRE). EVPN-VXLAN. Ethernet over IP (EolP). Static VXLAN.

Match the terms below to their characteristics (Options may be used more than once or not at all.). A device with IP address 10.1.3.7 in a network wants to send the traffic stream to a device with IP address 10.13.4.2 in the other network. One/more senders and one/more recipients participate in data transfer traffic. Sent to all hosts on a remote network. Sent to all NICs on the same network segment as the source NIC.

Due to a shipping error, five (5) HPE Aruba Networking AP-515s and one (1) CX 6300 were sent directly to your new branch office. You have configured a new group persona for the new branch office devices in HPE Aruba Networking Central, but you do not know their MAC address or serial numbers. The office manager is instructed via text message on their smartphone to onboard all the new hardware into Aruba Central. What application must the office manager use on their phone to complete this task?. Aruba Onboard App. Aruba Central App. Aruba CX Mobile App. Aruba installer App.

List the WPA 4-Way Handshake functions in the correct order. Proves knowledge of the PMK. Exchanges messages for generating PTK. Distributes an encrypted GTK to the client. Sets first initialization vector (IV).

What is used to retrieve data stored in a Management Information Base (MIS)?. SNMPv3. DSCP. TLV. CDP.

you need to have different routing-table requirements With Aruba CX 6300 VSF configuration. Assuming the correct layer-2 VLAN already exists, how would you create a new SVI for a separate routing table?. Create a new VLAN, and attach the VRF to it. Create a new routing table, and attach VLANS to it. Create a new SVI and use attach command. Create a new VLAN. and attach the routing table to it.

With Access-1, What needs to be identically configured With MSTP to load-balance VLANS?. Spanning-tree bpdu-guard setting. Spanning-tree instance vlan mapppjng. spanning-tree Cist mapping. Spanning-tree root-guard setting.

Your customer has asked you to assign a switch management role for a new user The customer requires the user role to View switch configuration information and have access to the PUT and POST methods for REST API. Which default AOS-CX user role meets these requirements?. administrators. auditors. sysops. helpdesk.

How is Dynamic Multicast Optimization (DMO) implemented in an HPE Aruba wireless network?. DMO is configured globally for each SSID in use in the network. DMO is configured individually for each SSID in use in the network. The controller converts multicast streams into unicast streams. The AP uses QoS to provide equal air time for multicast traffic.

With the Aruba CX switch configuration, what is the Active Gateway feature that is used for and is unique to VSX configuration?. Sixteen different VMACs are supported total as shared. Active Gateway can once MSTP instances are created for VLAN load sharing. Sixteen different VMACS are supported for each IPV4 and IPV6 stack simultaneously. copied over the ISL link for an optimized path.

What is a primary benefit of BSS coloring?. BSS color tags improve performance by allowing APS on the same channel to be farther apart. BSS color tags improve security by identifying rogue APS and tagging them as threats. BSS color tags are applied on the wireless controllers and can reduce the threshold for interference. BSS color tags are applied to WI-Fi channels and can reduce the threshold tor interference.

Your Director of Security asks you to assign AOS-CX switch management roles to new employees based on their specific job requirements. After the configuration was complete, it was noted that a user assigned with the auditors role did not have the appropriate level of access on the switch. The user was not allowed to perform firmware upgrades and a privilege level of 15 was not assigned to their role. Which default management role should have been assigned for the user?. sysadmin. sysops. administrators. config.

With the Aruba CX 6000 24G switch with uplinks of 1 and what does the switch do when a client port detects a loop and the do-not-disable parameter is used?. Port status will be validated once status is cleared. An event log message is created. The network analytics engine is triggered. Port status led blinks in amber with 100hz.

You must ensure the HPE Aruba network you are configuring for a client is capable of plug-and-play provisioning of access points. What enables this capability?. UCC Service. LLDP-MED. SRTP. CSMA.

Which standard supported by some Aruba APs can enable a customer to accurately locate wireless client devices within a few meters?. 802.11mc. 802.11W. 802.11k. 802.11r.

A customer wants to deploy a Gateway and take advantage of all the SD-WAN features. Which persona role option should be selected?. ArubaOS 10 Branch. ArubaOS 10 VPN Concentrator. ArubaOS 10 Wireless. ArubaOS 10 Mobility.

Refer to Exhibit: A company has deployed 200 AP-635 access points. To take advantage of the 6 GHz band, the administrator has attempted to configure a new WPA3-OWE SSID in Central but is not working as expected. What would be the correct action to fix the issue?. Change the SSID to WPA3-Enterprise (CNSA). Change the SSID to WPA3-Personal. Change the SSID to WPA3-Enhanced Open. Change the SSID to WPA3-Enterprise (CCM).

Your manufacturing client is deploying two hundred wireless IP cameras and fifty headless scanners in their warehouse. These new devices do not support 802.1X authentication. How can HPE Aruba enhance security for these new IP cameras in this environment?. Use MPSK Local to automatically provide unique pre-shared Keys for devices. Aruba ClearPass performs the 802.1X authentication and installs a certificate. MPSK provides for each device in the WLAN to have its own unique pre-shared Key. MPSK Local will allow the cameras to share a rey and the scanners to share a different.

Match the appropriate QoS concept with its definition. (Options may be used more than once or not at all). Best Effort Service. Differentiated Services. Class of Service. WMM.

You are doing tests in your lab and with the following equipment specifications: AP1 has a radio that generates a 20 dBm signal AP2 has a radio that generates a 8 dBm signal AP1 has an antenna with a gain of 7 dBI. AP2 has an antenna with a gain of 12 dBI. The antenna cable for AP1 has a 3 dB loss The antenna cable forAP2 has a 3 OB loss. What would be the calculated Equivalent Isotropic Radiated Power (EIRP) for AP1?. 2dBm. 8 dBm. 22 dBm. 24 dBm.

With the Aruba CX 6200 24G switch with uplinks or 1/1/25 and 1/1/26, how do you protect client ports from forming layer-2 loops?. int 1/1/1-1/1/24, loop-protect. int 1/1/1-1/1/28. loop-protect. int 1/1/1-1/1/28. loop-guard. int 1/1/1-1/1/24. loop-guard.

You are working on a network where the customer has a dedicated router with redundant Internet connections Tor outbound high-importance real-time audio streams from their datacenter All of this traffic. originates from a single subnet uses a unique range of UDP ports is required to be routed to the dedicated router All other traffic should route normally The SVI for the subnet containing the servers originating the traffic is located on the core routing switch in the datacenter What should be configured?. Configure a new OSPF area including both the core routing switch and the dedicated router. Configure a BGP link between the core routing switch and the dedicated router and route filtering. Configure Policy Based Routing (PBR) on the core routing switch for the VRF with the servers SVI. Configure a dedicated VRF on the core routing switch and make the dedicated router the default route.

you are implementing ClearPass Policy Manager with EAP-TLS for authenticating all corporate-owned devices. What are two possible solutions to the problem of deploying client certificates to corporate MacBooks that are joined to a Windows domain? (Select two.). ClearPass OnBoard. Windows Server PKl and a GPO. Apple Configurator and a GPO. ClearPass OnGuard. Mobile Device Manager.

A customer just upgraded aggregation layer switches and noticed traffic dropping for 120 seconds after the aggregation layer came online again. What is the best way to avoid having this traffic dropped given the topology below?. Configure the linkup delay timer to 240 seconds to double the amount of lime for the initial phase to sync. Configure the linkup delay timer to exclude LAGS 101 and 102, which will allow time for routing adjacencies to form and to learn upstream routes. Configure the linkup delay timer to include LAGs 101 and 102, which will allow time for routing adjacencies lo form and to learn upstream routes. Configure the linkup delay timer to 120 seconds, which will allow the right amount of time for the initial phase to sync.

When setting up an Aruba CX VSX pair, which information does the Inter-Switch Link Protocol configuration use in the configuration created?. hello interval is disabled by default. hello interval is based on the value set by dead interval. hello interval 100ms by default. hello interval is 1s by default.

Your customer has four (4) Aruba 7200 Series Gateways and two (2) 7000 Series Gateways. The customer wants to form a cluster with these Gateways. What design consideration would prevent you from using all of those Gateways?. Multiple versions between Gateways in the same cluster profile are not allowed AOS 10.x. A heterogeneous cluster is not supported in AOS 10.x. The AP load should be lowest value of worst-case scenario load. A combination of 7200 series and 7000 series gateways supports up to 4 nodes.

Match the topics of an AOS10 Tunneled mode setup between an AP and a Gateway. (Options may be used more than once or not at all.). Authenticator. Negotiate IPSEC phase 1. Negotiate IPSEC phase 2. Radius Proxy.

Match each PoE power class to Its corresponding 802.3 standard. (Options may he used more than once or not at all). 802.3af. 802.3at. 802.3bt.

Match the topics with the underlying technologies (Options may be used more than once or not at all.). EVPN-VXLAN. User Based Tunneling (UBT).

By default, Best Effort is higher priority than which priority traffic type?. All queues. Background. Internet Control. Network Control.

Your customer has an Aruba CX 6200F VSF stack with two switches. A third member (JL726A) needs to be added to the VSF configuration. What e the configuration that enables the new devices to join the VSF?. On the new switch issue: vsf member 1 link 1 1/1/50 link 2 1/1/49 vsf renumber-to 3. On the new switch issue: vsf member 3 type jl726a. On the existing VSF issue: vsf member 3 stack join type jl726a. On the new switch issue: vsf member 1 type jl726a link 1 3/1/50 link 2 3/1/49.

You need to drop excessive broadcast traffic on an ingress port or an ArubaOS-CX switch. What is the best feature to use for this task?. DWRR queuing. Strict queuing. Rate limiting. QoS shaping.

A company recently upgraded its campus switching infrastructure with Aruba 6300 CX switches. They have implemented 802.1X authentication on edge ports where laptop and loT devices typically connect An administrator has noticed that for PoE devices the pons are delivering the maximum wattage instead of what the device actually needs Upon connecting the loT devices, the devices request their specific required wattage through information exchange. Concerned about this waste of electricity, what should the administrator implement to solve this problem?. Enable AAA authentication to exempt LLDP and/or CDP information. Globally enable the QoS trust setting for LLDP and/or CDP. Create device profiles with the correct power definitions. implement a classifier policy with the correct power definitions.

A customer has a site with 200 AP-515 access points 75 AP-565 access points installed. The customer is rolling out new mobile phones with Wi-Fi-calling. 802.1X is in use for authentication What should be enabled to ensure the best roaming experience?. 802.1X. 802.11r. 802.11W. 802 .11h.

You are deploying Aruba CX 6300's with the customers requirement to only allow one (1) VoIP phone and one (1) device. The following local role gets assigned to the phone port-access rote VoIP device-traffic-class voice What set of commands best fits this requirement?. interface 1/1/1 aaa authentication port-access client-limit 2 aaa authentication port-access auth-mode client-mode. interface 1/1/1 aaa authentication port-access auth-mode multi domain. interface 1/1/1 aaa authentication port-access client-limit multi-domain 2 aaa authentication port-access auth-mode multi-domain. interface 1/1/1 aaa authentication port-access client-limit 1 aaa authentication port-access auth-mode device mode.

For an Aruba AOS10 AP in mixed mode, which factors can be used to determine the forwarding role assigned to a client? (Select two.). Client IP address. 802.1X authentication result. Client MAC address. Client SSID. Client VLAN.

You are building a configuration in Central that will be used for a standardized network design for small sites for your company, you want to use GUI configuration for gateways and APs, while template configuration for switches. You need to align with Aruba best practices. Which set of actions will satisfy these requirements?. Create one group in Central for switches a second group for APs. and a third group for gateways Create a unique site for each location, and assign devices to the appropriate site. Create one group in Central for switches and a second group for APs and gateways. Create a unique site for each location, and assign devices to the appropriate site. Create a single group in Central. Create a unique site for each location, and assign devices to the appropriate site. Create a single group in Central. Create a unique site for each type of device, and assign devices to the appropriate site.

Which statements are true regarding a VXLAN implementation on Aruba Switches? (Select two.). MTU size must be increased beyond the default. VNIs encapsulate and decapsulate VXLAN traffic. VTEPs encapsulate and decapsulate VXLAN traffic. They are only available for datacenter switches (CX 8k, 9k,10k). All Aruba CX switches support VXLAN.

A customer is concerned about me unprotected traffic between an AOS-CX switch and a gateway, running on AOStO. What is a feasible option to protect this traffic?. Implement an IPSec tunnel to protect PAPI between the AOS-CX switches and the gateway. Implement an MD5 HMAC function lo protect PAPI between the AOS-CX switches and the gateway. Implement a GRE tunnel to protect PAPI between the AOS-CX switches and the gateway. no action is needed, an RSA certificate already encrypts the traffic.

What does the 802.3bz standard describe?. 2.5Gb and 5Gb Ethernet ports. 60 W and 90W PoE. AP directed roaming between APs. 60 GHz P2P Wi-Fi.

When configuring UBT on a switch what will happen when a gateway role is not specified?. The switch will put the client on the access VLAN. The gateway will assign a default role to the client. The switch will assign the default deny role to the client. The gateway will send back the deny role to the client.

Your customer is having issues with Wi-Fi 6 clients staying connected to poor-performing APs when a higher throughput APs are closer. Which technology should you implement?. Clearpass. ClientMatch. Airmatch. ARM.

A client is connecting to 802.1X SSID that has been configured in tunnel mode with the default APgroup settings. After receiving Access-Accept from the RADIUS server, the Aruba Gateway will send Access-Accept to the AP through which tunnel?. IPsec tunnel. Split tunnel. GRE tunnel. PAR tunnel.

List the firewall role derivation flow in the correct order. Server derived role. User derived role. Authentication default role. Initiation role assigned.

You are are doing tests in your lab and with the following equipment specifications: AP1 has a radio that generates a 16 dBm signal. AP2 has a radio that generates a 13 dBm signal. AP1 has an antenna with a gain of 8 dBi. AP2 has an antenna with a gain of 12 dBi. The antenna cable for AP1 has a 4 dB loss. The antenna cable for AP2 has a 3 dB loss. What would be the calculated Equivalent Isotropic Radiated Power (EIRP) for AP1?. -9 dBm. 20 dBm. 40 dBm. 15 dBm.

With the Aruba CX switch configuration, what is the Active Gateway feature that is used for and is unique to VSX configuration?. VRRP and Active gateway are mutually exclusive on a VLAN. VRID is set automatically as SVI vlan id. VRIDs need to be non-overlapping with VRRP. VRRP and Active Gateway can be configured on a single VLAN for interoperability.

Your customer currently has Iwo (2) 5406 modular switches with MSTP configured as their core switches. You are proposing a new solution. What would you explain regarding the Aruba CX VSX switch pair when the Primary VSX node is replaced and the system MAC is replaced?. VSX will select the MAC address from a node that is the lower ID. Configure vMAC on the Primary VSX node under VSX to retain MAC after hardware replacement. VSX will select the MAC address from a node that is a higher ID. During the initial VSX configuration, the system-mac is assigned with a fixed MAC based on VSX ID.

With the Aruba CX 6100 48G switch with uplinks of 1/1/47 and 1/1/48. how do you automate the process of resuming the port operational state once a loop on a client port is cleared?. Configure int 1/1/1-1/1/52 loop-protect disable timer. Configure global loop-protect disable timer. Configure int 1/1/1-1/1/46 loop-protect re-enable-timer. Configure global loop-protect re-enable-timer.

Report abuse