HP HPE7-A02 - Aruba Certified Network Security Professional Exam
Page: 3 / 24
Total 118 questions
Question #11 (Topic: Exam A)
Refer to the exhibit.

All of the switches in the exhibit are AOS-CX switches.
What is the preferred configuration on Switch-2 for preventing rogue OSPF routers in this network?

All of the switches in the exhibit are AOS-CX switches.
What is the preferred configuration on Switch-2 for preventing rogue OSPF routers in this network?
A. Configure OSPF authentication on VLANs 10-19 is password mode.
B. Configure OSPF authentication on Lag 1 in MD5 mode.
C. Disable OSPF entirely on VLANs 10-19.
D. Configure passive-interface as the OSPF default and disable OSPF passive on Lag 1.
Answer: D
Question #12 (Topic: Exam A)
Which issue can an HPE Aruba Networking Secure Web Gateway (SWG) solution help customers address?
A. The organization needs a faster way to quarantine clients that have generated threats, as detected by third-party firewalls.
B. Hybrid workers are exposing their computers to risky internet sites and infection by malware when they work from home.
C. Remote workers need access to private data center applications without exposing those applications to unauthorized users.
D. The organization currently has no way to prevent users from exfiltrating sensitive data from SaaS applications.
Answer: B
Question #13 (Topic: Exam A)
A company has several use cases for using its AOS-CX switches’ HPE Aruba Networking Analytics Engine (NAE).
What is one guideline to keep in mind as you plan?
What is one guideline to keep in mind as you plan?
A. Each switch model has a maximum number of supported monitors, and one agent might have multiple monitors.
B. You can install multiple scripts on a switch, but you can deploy only one agent per script.
C. The switch will permit you to deploy as many NAE agents as you want, but they might degrade the switch functionality.
D. When you use custom scripts, you can create as many agents from each script as you want.
Answer: A
Question #14 (Topic: Exam A)
A company has been running Gateway IDS/IPS on its gateways in IDS mode for several weeks. The company wants to transition to IPS mode.
What is one step you should recommend?
What is one step you should recommend?
A. Disable traffic inspection and reboot before re-enabling traffic inspection with the new mode.
B. Change the mode on one gateway at a time to establish a smoother transition period.
C. Consider applying a stricter IPS policy to minimize issues during the transition period.
D. Check for legitimate traffic that has been flagged as a threat and allow list the associated rules.
Answer: D
Question #15 (Topic: Exam A)
A ClearPass Policy Manager (CPPM) service includes these settings:
Role mapping policy:
Evaluate: Select first
Rule 1 conditions: Authorization:AD:Groups EQUALS Managers AND Authentication:TEAP-Method-1-Status EQUALS Success
Rule 1 role: manager
Rule 2 conditions: Authentication:TEAP-Method-1-Status EQUALS Success
Rule 2 role: domain-comp
Default role: [Other]
Enforcement policy:
Evaluate: Select first
Rule 1 conditions: Tips Role EQUALS manager AND Tips Role EQUALS domain-comp
Rule 1 profile list: domain-manager
Rule 2 conditions: Tips Role EQUALS manager
Rule 2 profile list: manager-only
Rule 3 conditions: Tips Role EQUALS domain-comp
Rule 3 profile list: domain-only
Default profile: [Deny access]
A client is authenticated by the service. CPPM collects attributes indicating that the user is in the Contractors group, and the client passed both TEAP methods.
Which enforcement policy will be applied?
Role mapping policy:
Evaluate: Select first
Rule 1 conditions: Authorization:AD:Groups EQUALS Managers AND Authentication:TEAP-Method-1-Status EQUALS Success
Rule 1 role: manager
Rule 2 conditions: Authentication:TEAP-Method-1-Status EQUALS Success
Rule 2 role: domain-comp
Default role: [Other]
Enforcement policy:
Evaluate: Select first
Rule 1 conditions: Tips Role EQUALS manager AND Tips Role EQUALS domain-comp
Rule 1 profile list: domain-manager
Rule 2 conditions: Tips Role EQUALS manager
Rule 2 profile list: manager-only
Rule 3 conditions: Tips Role EQUALS domain-comp
Rule 3 profile list: domain-only
Default profile: [Deny access]
A client is authenticated by the service. CPPM collects attributes indicating that the user is in the Contractors group, and the client passed both TEAP methods.
Which enforcement policy will be applied?
A. [Deny Access Profile]
B. manager-only
C. domain-manager
D. domain-only
Answer: D