HP HPE6-A88 - HPE Networking ClearPass Exam
Page: 3 / 23
Total 111 questions
Question #11 (Topic: Topic 1, Identify Network Access Control and Security Features
)
A network engineer is configuring a policy enforcement service on a wired network to minimize deployment effort. They choose a non-AAA enforcement method.
What is the main benefit of this approach?
What is the main benefit of this approach?
A. It does not require client configuration and requires minimal configuration on the actual switches.
B. It enables advanced security protocols such as 802.1X.
C. It allows dynamic VLAN assignment based on user roles.
Answer: A
Question #12 (Topic: Topic 1, Identify Network Access Control and Security Features
)
In a network utilizing ClearPass and RADIUS CoA, a client initially connects without profile data and is assigned limited access.
How does ClearPass ensure that the client eventually gains full access?
How does ClearPass ensure that the client eventually gains full access?
A. ClearPass uses the initial connection data to grant full access without further profiling.
B. ClearPass profiles the client after receiving a DHCP request, terminates the session, and allows the client to re-authenticate with full access.
C. ClearPass immediately grants full access upon receiving the DHCP request without terminating the session.
Answer: B
Question #13 (Topic: Topic 1, Identify Network Access Control and Security Features
)
When a client device requests a webpage from a server, the server needs to determine the correct version of the webpage to send. How does ClearPass Guest utilize the information sent by the client’s browser to profile the device and update its database?
A. ClearPass Guest reads the HTTP User Agent information sent with the page request to profile the device automatically.
B. ClearPass Guest requires a separate plugin to read and profile the device based on HTTP User Agent information.
C. ClearPass Guest relies on the DHCP options to profile the device and update the database.
Answer: A
Question #14 (Topic: Topic 1, Identify Network Access Control and Security Features
)
A network engineer is tasked with creating enforcement profiles for a multi-vendor environment. They want to minimize the number of enforcement profiles they need to write.
Which approach should the engineer take?
Which approach should the engineer take?
A. Enable SNMP services on all network devices.
B. Utilize IETF attributes instead of vendor-specific attributes.
C. Write separate enforcement profiles for each device vendor type.
Answer: B
Question #15 (Topic: Topic 1, Identify Network Access Control and Security Features
)
In a corporate network following Zero Trust best practices, a security team notices unusual activity from a previously authenticated and authorized device.
What should the team do next to ensure the network’s security?
What should the team do next to ensure the network’s security?
A. Increase the device’s access privileges to monitor more closely.
B. Ignore the activity since the device was already authenticated.
C. Reduce the device’s privileges or quarantine it for further investigation.
Answer: C