Weekend Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: suredis

HP HPE7-A07 Aruba Certified Campus Access Mobility Expert Written Exam Exam Practice Test

Page: 1 / 7
Total 70 questions

Aruba Certified Campus Access Mobility Expert Written Exam Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$42  $119.99

PDF Study Guide

  • Product Type: PDF Study Guide
$36.75  $104.99
Question 1

After onboarding three new AOS 10 gateways using the full-setup methodinto the same Central group, a customer cannot log in to one of the gateways using the HPE Aruba Networking Central remote console due to an incorrect password.

Options:

A.

The admin password created using full-setup does not match the global Central admin password.

B.

The admin password created during the run-setup process is not configured to allow me remote console access

C.

The admin password created during the full-setup process does not match the Central group admin password

D.

The admin password created at the Central group level has expired

Question 2

A Windows device attempts to connect to an 802.1X network but it is not receiving the correct role. TEAP has been configured asthe only authentication method in ClearPass.The wireless configuration is correct.

Exhibit.

What is me mostlikelycause?

Options:

A.

The Windows device needs 10 De configured tor TEAP.

B.

ClearPass requires a second authentication method.

C.

802.1X is not compatible with TEAP in windows device

D.

Only machine authentication should be configured on the Windows device

Question 3

A customer has interfering devices that are seen over the air. They contact you and ask you to configure RAPIDS to help identify interfering and rogue APs. HPE Aruba Networking Central identifies a rogue AP and displays the connected switch port.

How can HPE Aruba Networking Central identify which switch port the AP is connected to?

Options:

A.

device profiting on the switch

B.

from the AP MAC address table

C.

from the switch LLDP neighbors table

D.

from the switch MAC address table

Question 4

An AOS 10 multi-site deployment has sites with AP-only bridged SSlDs and other sites with APs and gateways operating tunneled SSiDs. Client session state sync errors exist between secure lab environments and public -facing areas at several sites.

What is causing the issues?

Options:

A.

The DTLS connections are down between APs in the lab and APs in public areas

B.

The affected clients are associated with an SSID with 11r and 11k disabled.

C.

The sites with issues are the overlay AP with gateway sites because the connection to HPE Aruba Networking central is interrupted

D.

The sites with issues are the AP-only deployments because the connection to HPE Aruba Networking Central is interrupted

Question 5

You are testing the use of the automated port-access role configuration process using RadSec authentication over VXLAN. During your testing you observed that the RadSec connection will fan during the digital certificate exchange

What would be the cause of this Issue?

Options:

A.

The RadSec server was defined on the switch using an IPv6 address that was unreachable

B.

Tracking mode was set to "dead-only", and the RadSec server was marked as unreachable.

C.

The switch is configured to establish a TLS connection with a proxy server, not the radius server.

D.

The RADIUS TCP packets are Being dropped and the TLS tunnel is not established.

Question 6

Based on best practices if an SSID is configured Tor a primary and secondary gateway cluster with cluster preemption enabled, which will decide if the APs move to the secondary gateway cluster if all of the nodes in the primary gateway cluster are down?

Options:

A.

tunnel orchestrator for LAN tunnel service in HPE Aruba Networking Central

B.

every AP individually

C.

cluster leader in the primary gateway cluster

D.

cluster leader in the secondary gateway cluster

Question 7

Match each Group Based Policy(GBP) rote description to its respective role ID.

Options:

Question 8

You configured a WPA3-SAE with the following MAC Authentication Role Mapping inCloud Authentication and Policy:

With further default settings assume a new Android phone is connected to the network. Which role will the client be assigned after connecting forthe first time?

Options:

A.

byod

B.

client will be rejected network access

C.

lot-local

D.

unmatched-device

Question 9

A network technician racked up two 9240 mobility gateways in a single cluster that will be terminating 1700 APs in a medium-sized branch office Next, the technician cabled the gateways with two SFP28 Direct Attach Copper (DAC) cables, distributed between a two-member core switching stack and powered them up.

What must the network administrator do next regarding the gateway configuration to ensure maximum wired bandwidth utilization?

Options:

A.

Map two physical ports to a port channel on each gateway.

B.

Make an ports trunk interfaces and permit data VLANs

C.

Disable the spanning tree and allocate unique VLANs to each port.

D.

Manually set 25Gbps speeds on all ports.

Question 10

A customer is running out of IP addresses in a network segment. What will happen If they add an additional IPsubnet to the same VLAN?

Options:

A.

Broadcasts for me two subnets win arrive on all ports in the same VLAN

B.

IGMP will not work in both of the subnets in the same VLAN

C.

This would result in a single SVI using two subinterfaces.

D.

Users can reach each other and establish PTP traffic without passing an L3 point in the same VLAN

Question 11

A customer’s infrastructure is set up to use both primary and secondary gateway clusters on the SSID profile based on best practices What is a valid cause tor having an equal spirt in APs connected to the primary and secondary gateway clusters?

Options:

A.

The secondary gateway cluster is heterogeneous

B.

The secondary gateway cluster is homogeneous

C.

The primary gateway cluster is up. out some APs are unable to reach the primary gateway cluster. These APs would connect to the secondary gateway cluster

D.

The primary gateway cluster is up. out some APs cannot reach the secondary gateway cluster. These APs would connect to the secondary gateway cluster

Question 12

You want to configure an MTU of 9198 for a routedlag interface on a CX 6300 switch.Which configuration achieves this?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 13

Exhibit.

Which statement is true given the following CLI output from a CX 6300?

Options:

A.

There are no active fabric clients on the CX switch with RD 172.16.10.1

B.

A wired client with IP address 10.203 1.100 is on a remote CX 6300 in the fabric with loopback IP address 172.21.11.2.

C.

A wired client with IP address 10 203 1 100 has a host route that is not being properly advertised

D.

The overlay loopbacK addresses are advertised in the faerie with 2d-bit subnet masks

Question 14

Exhibit.

An engineer has applied the above configuration to R1 and R2 However the routers OSPF adjacency never progresses past the "EXSTART-DR" slate as shown below.

Which configuration action on either router will allow R1 and R2 to progress past the "EXSTART/DR" state?

Options:

A.

Change R1 and R2 to a network type of point-to-point.

B.

Remove the layer 3 MTU configuration.

C.

Ensure the OSPF process is not configured with passive-interface default.

D.

Change the IP address and mask applied to interface 1/1/1.

Question 15

What is me recommended configuration to ensure link aggregation is consistent in a campus topology using VSX with two aggregation switches and downlinks to access switches?

Options:

A.

Use a custom LACP hash algorithm for improved load Balancing.

B.

Keep the MTU values at the default setting for GRE and VXLAN communications

C.

Use the command "vsx-sync mclag-interfaces" under the VSX context.

D.

Use the command "vsx-sync active-gateways" under the VSX context.

Question 16

A customer is evaluating device profiles on a CX 6300 switch. The test device has the following attributes:

• MAC address = 81:cd:93:13:ab:31

• LLDP sys-desc = iotcontroller

The test device is being assigned to the ‘’lot-dev’' role However, the customer requires the "lot-prod’’ role be applied.

Given the configuration, what is causing the "iot-dev" role to be applied to the device'?

Options:

A.

The test device does not support CDP.

B.

The device-profile precedence order is not configured.

C.

An external RADIUS server is unreachable.

D.

The LLDP system description matches the IIdp-group configuration.

Question 17

in a WLAN network with a tunneled SSID. you see the following events in HPE Aruba Networking Central:

The customer asks you to investigate log messages What should you tell them?

Options:

A.

This indicates a security issue. The client with a MAC address ending with 37 18;0d Is performing a Denial-of-Service attack on your network. You should track down the client and remove it from the network.

B.

This is normal, expected behavior. No further actions are needed.

C.

This indicates a client WLAN driver issue for the client with a MAC address ending with 37:18

:Od. You should upgrade the client WLAN driver.

D.

There is a roaming issue Enable Fast Roaming 802.11r and OKC to resolve the issue.

Question 18

An administrator is creating a fabric withNetConductor in HPE Aruba Networking Central Considering an EVPN VXLAN fabric, click on the most appropriate layer to be configured as a Rome-Reflector Persona.

Options:

Question 19

Exhibit.

Which user role will be assigned when a voice client tries to connect for the first time, but the RADIUS server is unavailable?

Options:

A.

CRITICAl_AUTH

B.

DEFAULT_AUTH

C.

CRIT1CAL_V0ICE

D.

PRE_AUTH

Question 20

A customer would like to allow their IT Helpdesk to configure loT devices to connect lo a single SSID using a unique PSK that other devices cannot use. Which solution would you recommend?

Options:

A.

MPSK AES with MAC Auth

B.

MPSK Local

C.

MPSK AES with Cloud Auth

D.

MPSK AES with ClearPass

Question 21

Which option shows the correct Banawidth Control for 1024 kbpsdown and 2048 Kops up for the SSID?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Page: 1 / 7
Total 70 questions