HP HPE7-A10 - HPE Network Security Expert Exam
Page: 3 / 15
Total 74 questions
Question #11 (Topic: Exam A)
# Introduction to the customer
You are helping a company add HPE Aruba Networking ClearPass to their network, which uses HPE Aruba Networking network infrastructure devices.
The company currently has a Windows domain and Windows CA. The Window CA issues certificates to domain computers, domain users, and servers such as domain controllers. An example of a certificate issued by the Windows CA is shown here.


# ClearPass cluster IP addressing and hostnames
A customer's ClearPass cluster has these IP addresses:
• Publisher = 10.47.47.5
• Subscriber 1 = 10.47.47.6
• Subscriber 2 = 10.47.47.7
• Virtual IP with Subscriber 1 and Subscriber 2 = 10.47.47.8
The customer's DNS server has these entries
• cp.acnsxtest.com = 10.47.47.5
• cps1.acnsxtest.com = 10.47.47.6
• cps2.acnsxtest.com = 10.47.47.7
• radius.acnsxtest.com = 10.47.47.8
• onboard.acnsxtest.com = 10.47.47.8
Refer to the scenario.
You need to configure HPE Aruba Networking ClearPass Onboard to issue client certificates for Azure AD joined devices.
Which step is required to achieve this objective?
You are helping a company add HPE Aruba Networking ClearPass to their network, which uses HPE Aruba Networking network infrastructure devices.
The company currently has a Windows domain and Windows CA. The Window CA issues certificates to domain computers, domain users, and servers such as domain controllers. An example of a certificate issued by the Windows CA is shown here.


# ClearPass cluster IP addressing and hostnames
A customer's ClearPass cluster has these IP addresses:
• Publisher = 10.47.47.5
• Subscriber 1 = 10.47.47.6
• Subscriber 2 = 10.47.47.7
• Virtual IP with Subscriber 1 and Subscriber 2 = 10.47.47.8
The customer's DNS server has these entries
• cp.acnsxtest.com = 10.47.47.5
• cps1.acnsxtest.com = 10.47.47.6
• cps2.acnsxtest.com = 10.47.47.7
• radius.acnsxtest.com = 10.47.47.8
• onboard.acnsxtest.com = 10.47.47.8
Refer to the scenario.
You need to configure HPE Aruba Networking ClearPass Onboard to issue client certificates for Azure AD joined devices.
Which step is required to achieve this objective?
A. Create an HTTP authentication source that references an Intune extension.
B. Recreate the CA as a registration authority under Azure AD.
C. Create a CPPM policy that authenticates guest users to Azure AD.
D. Install the Intune SCEP extension on the ClearPass subscribers.
Answer: D
Question #12 (Topic: Exam A)
# Introduction to the customer
You are helping a company add HPE Aruba Networking ClearPass to their network, which uses HPE Aruba Networking network infrastructure devices.
The company currently has a Windows domain and Windows CA. The Window CA issues certificates to domain computers, domain users, and servers such as domain controllers. An example of a certificate issued by the Windows CA is shown here.


# ClearPass cluster IP addressing and hostnames
A customer's ClearPass cluster has these IP addresses:
• Publisher = 10.47.47.5
• Subscriber 1 = 10.47.47.6
• Subscriber 2 = 10.47.47.7
• Virtual IP with Subscriber 1 and Subscriber 2 = 10.47.47.8
The customer's DNS server has these entries
• cp.acnsxtest.com = 10.47.47.5
• cps1.acnsxtest.com = 10.47.47.6
• cps2.acnsxtest.com = 10.47.47.7
• radius.acnsxtest.com = 10.47.47.8
• onboard.acnsxtest.com = 10.47.47.8
Refer to the scenario.
The Onboard CA is using the settings shown in the exhibits below.


Microsoft Entra ID (Azure AD) admins need help setting up the app registration for integrating with ClearPass Onboard.
Which URL should you tell them to use?
You are helping a company add HPE Aruba Networking ClearPass to their network, which uses HPE Aruba Networking network infrastructure devices.
The company currently has a Windows domain and Windows CA. The Window CA issues certificates to domain computers, domain users, and servers such as domain controllers. An example of a certificate issued by the Windows CA is shown here.


# ClearPass cluster IP addressing and hostnames
A customer's ClearPass cluster has these IP addresses:
• Publisher = 10.47.47.5
• Subscriber 1 = 10.47.47.6
• Subscriber 2 = 10.47.47.7
• Virtual IP with Subscriber 1 and Subscriber 2 = 10.47.47.8
The customer's DNS server has these entries
• cp.acnsxtest.com = 10.47.47.5
• cps1.acnsxtest.com = 10.47.47.6
• cps2.acnsxtest.com = 10.47.47.7
• radius.acnsxtest.com = 10.47.47.8
• onboard.acnsxtest.com = 10.47.47.8
Refer to the scenario.
The Onboard CA is using the settings shown in the exhibits below.


Microsoft Entra ID (Azure AD) admins need help setting up the app registration for integrating with ClearPass Onboard.
Which URL should you tell them to use?
A. https://clearpass.acnsxtest.com/.well-known/est/ca:2
B. https://onboard.acnsxtest.com/onboard/mdps_scep.php/2
C. https://cps1.acnsxtest.com/.well-known/est/ca:2
D. https://localhost.acnsxtest.com/onboard/mdps_scep.php/2
Answer: B
Question #13 (Topic: Exam A)
A hospital has an AOS-10 architecture that is managed by HPE Aruba Networking Central. The customer has deployed a pair of HPE Aruba Networking 9000 Series gateways with Security licenses at each clinic. The gateways implement IDS/IPS in IDS mode.
The Security Dashboard shows these several recent events with the same signature, as shown below:

Refer to the scenario.
You have learned that the source of the events is nurse call stations.
What can you conclude?
The Security Dashboard shows these several recent events with the same signature, as shown below:

Refer to the scenario.
You have learned that the source of the events is nurse call stations.
What can you conclude?
A. These devices are unlikely to use TOR legitimately, but malware often does. You and the security team should investigate these stations.
B. This event is a common false positive for clients using video streaming, but you should still investigate it further to comply with best practices.
C. The nurses are making their devices vulnerable by contacting unsafe websites. You should educate them about safe browsing practices.
D. The threat destination has an internal IP address, and it is likely a DNS server. You should verify that this server is patched and uncompromised.
Answer: A
Question #14 (Topic: Exam A)
A hospital has an AOS-10 architecture that is managed by HPE Aruba Networking Central. The customer has deployed a pair of HPE Aruba Networking 9000 Series gateways with Security licenses at each clinic. The gateways implement IDS/IPS in IDS mode.
The Security Dashboard shows these several recent events with the same signature, as shown below:

Refer to the scenario.
Which step could give you valuable context about the incident?
The Security Dashboard shows these several recent events with the same signature, as shown below:

Refer to the scenario.
Which step could give you valuable context about the incident?
A. View firewall sessions on the APs and record the threat sources' type and OS.
B. View the RAPIDS Security Dashboard and see if the threat sources are listed as rogues.
C. Find the HPE Aruba Networking Central client profile for the threat sources and note their category and family.
D. View the user-table on APs and record the threat sources' 802.11 settings.
Answer: C
Question #15 (Topic: Exam A)
A hospital has an AOS-10 architecture that is managed by HPE Aruba Networking Central. The customer has deployed a pair of HPE Aruba Networking 9000 Series gateways with Security licenses at each clinic. The gateways implement IDS/IPS in IDS mode.
The Security Dashboard shows these several recent events with the same signature, as shown below:

Refer to the scenario.
You would like a record of the specific traffic that triggered the threat event.
What should you do?
The Security Dashboard shows these several recent events with the same signature, as shown below:

Refer to the scenario.
You would like a record of the specific traffic that triggered the threat event.
What should you do?
A. Search for 10.1.36.150 and 10.1.36.152 in HPE Aruba Networking Central. Then, use live monitoring to obtain a packet capture on these devices.
B. From the Threats List, view the details for one of the threats. Then, download the packet.
C. Find the HPE Aruba Networking APs to which the threat sources are connected and archive those APs’ security logs.
D. Search the DNS logs on the server at 10.254.1.21.
Answer: B