Big 11.11 Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70special

HP HPE7-A07 Aruba Certified Campus Access Mobility Expert Written Exam Exam Practice Test

Page: 1 / 13
Total 126 questions

Aruba Certified Campus Access Mobility Expert Written Exam Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$37.5  $124.99

PDF Study Guide

  • Product Type: PDF Study Guide
$33  $109.99
Question 1

Refer to the exhibit.

To which devices has AP-1 established tunnels?

Options:

A.

A pair of gateways within a cluster

B.

A pair of switches running VXLAN

C.

A single gateway within a cluster

D.

A pair of standalone gateways

Question 2

Exhibit.

A network administrator attempts to improve multicast traffic flow and performs some packet captures for validation What can the network administrator conclude from the results?

Options:

A.

The data rate increased from 6 Mops to 300 Mops because Broadcast Multicast optimization (BCMCO) was configured.

B.

The capture taken after optimization does not show a packet length because Multicast Transmission Optimization was configured.

C.

The type flew remains consistent because Dynamic Multicast Optimization (DMO) was configured.

D.

The data rate increased from 6 Mbps to 300 Mops because Dynamic Multicast Optimization (DMO) was configured.

Question 3

Based on the output above, what is required to associate the GBP policy with a user role?

Options:

A.

Configure a user role called GBP-EMPLOYEE instead of EMPLOYEE

B.

Associate the port-access role to the GBP role using the role ID

C.

Update the port-access GBP policies to reference the EMPLOYEE role

D.

Update the entries in the class maps to reference the EMPLOYEE role

Question 4

The ACME company has an AOS-CX 6200 switch stack with an uplink oversubscription ratio of 9.6:1. They are considering adding two more nodes to the stack without adding any additional uplinks due to cabling constraints One of their architects has expressed concerns that their critical UDP traffic from both wired and bridged AP clients will encounter packet drops. They have already applied the following configuration:

Which strategy will complement this solution to achieve their objective?

Options:

A.

edge mark lower priority TCP traffic with AF12

B.

edge mark critical UDP Traffic with CSS

C.

edge mark lower priority TCP traffic with AF11

D.

edge mark critical UDP traffic with AF42

Question 5

A customer is experiencing authentication failures when clients connect to a new EAP-TLS SSID.

Based on the logs and packet capture above, what is the cause of the failure?

Options:

A.

The client cannot validate the RADIUS server's certificate

B.

The MTU in the path between the AP and HPE Aruba Networking ClearPass is too small

C.

HPE Aruba Networking ClearPass cannot validate the user's certificate

D.

The access point doesn't have the correct root CA certificate installed

Question 6

Exhibit.

A customer is reporting mat connectivity is Tailing for some wireless client Devices. What are your conclusions from the capture? (Select two.)

Options:

A.

The client does not have an ARP entry for me default gateway.

B.

The network is using WPA2-PSK key management.

C.

The network is using WPA3-SAE key management.

D.

The client is not receiving an IP address.

E.

The client does not support beamforming.

Question 7

The output of the show LACP interfaces shows the following:

What is causing this issue?

Options:

A.

The AP is configured with LACP active.

B.

Each AP interface is connected to a routed-only interface on different networks.

C.

Spanning tree and loop protect are enabled on both AP uplink ports.

D.

e0 is connected to a smart rate interface, and e is connected to a non-smart rate interface.

Question 8

A university owns a campus with several buildings segmented into east and west wings, which are L3 separated. The east wing has 1600 APs. and the west wing has 1200 Aps. Each wing has a single gateway cluster managed by HPE Aruba Networking Central. Each cluster contains one 7210 mobility gateway The gateways are configured with DHCP relay and route all client VLANs. A new business-critical faculty real-time application requires users to roam within wings but not across wings without disconnections or delay increments.

Which changes must the network administrator make lo successfully meet the requirement without performance degradation matching best practices? (Select two.)

Options:

A.

Replace the 7210 mobility gateway in the west wing with a pair of 7030 mobility gateways.

B.

Add a single 7210 mobility gateway to each cluster.

C.

Remove the DHCP relay from the gateways and enable the DHCP server instead

D.

Replace me 7210 mobility gateway in the east wing with a pair or 9012 mobility gateways

E.

Run L2 for all SSIDs and permit the users' VLANs in the gateway's uplinks.

Question 9

A network administrator accesses HPE Aruba Networking Central and notices that visitors consume too much internet bandwidth starving employee traffic when accessing an external service. Therefore, the administrator wants to limit wireless bandwidth to 60 Mops in both directions among all users in the voice rote and no more than 10 Mops in both directions for YouTube traffic. Deep packet inspection, web content classification, and firewall visibility are enabled.

Which configurations are required to accomplish this task? (Select two.)

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 10

You are troubleshooting a WLAN deployment with APs and gateways set up with an 802.1X tunneled SSIO. End-users are complaining that they can’t connect to die enterprise SSID. Which possible AP tunnel states could be the cause of the Issue? (Select two.)

Options:

A.

SM_STATE_RE KEYING

B.

SM_STATE_SURVIVED

C.

SM_STATE_CONNECTED

D.

SM_STATE_SURVIVING

E.

SM_STATE_CONNECTING

Question 11

A customer is installing CX 6300 switches, mobility gateways, and AP-635s.

The customer's VoIP system uses both wired and wireless handsets.

The handsets are configured to mark voice traffic using a DSCP value of 46.

The wireless handsets connect to a bridged SSID using WPA3-SAE.

What will allow the switch to honor the QoS mark set by the handset?

Options:

A.

Configure Voice Wi-Fi Multimedia Share for DSCP 46 on the voice SSID

B.

Activate UCC for the HPE Aruba Networking Central Group managing the APs

C.

Enable QoS trust DSCP

D.

Enable WMM on the voice SSID

Question 12

A customer with a gateway connected to a device on gigabitethernet 0/0/3 configures an Asset ID TLV on the device for inventory management.

Refer to the exhibit.

The customer mentions the Asset ID is not shown. What is causing the issue?

Options:

A.

MTU size is too small.

B.

Unknown TLVs cannot be displayed.

C.

LLDP-MED needs to be enabled.

D.

LLDP TX is not enabled.

Question 13

A customer wan a gateway connected to a device on gigabitethernet 0/0/3 configures an Asset ID TLV on the device for inventory management.

Exhibit.

The customer mentions me Asset ID is not shown What is causing the issue?

Options:

A.

LLDP TX is not enabled.

B.

LLPD-MED needs to be enabled.

C.

MTU size is too small.

D.

Unknown TLVs cannot be displayed.

Question 14

An administrator is creating a fabric with NetConductor in HPE Aruba Networking Central Considering an EVPN VXLAN fabric, click on the most appropriate layer to be configured as a Rome-Reflector Persona.

Options:

Question 15

Match each Group Based Policy (GBP) role description to its respective role ID.

Options:

Question 16

You configured a WPA3-SAE with the following MAC Authentication Role Mapping in Cloud Authentication and Policy:

With further default settings assume a new Android phone is connected to the network. Which role will the client be assigned after connecting for the first time?

Options:

A.

byod

B.

client will be rejected network access

C.

lot-local

D.

unmatched-device

Question 17

Which statement is true given the following CLI output from a CX 6300?

Options:

A.

The underlay loopback addresses are in the 172 21 11 x range.

B.

There are two anycast addresses m me overlay fabric.

C.

Duplicate MAC addresses were detected in the overlay fabric

D.

There are three active client overlay VLANs in the overlay fabric

Question 18

What is me recommended configuration to ensure link aggregation is consistent in a campus topology using VSX with two aggregation switches and downlinks to access switches?

Options:

A.

Use a custom LACP hash algorithm for improved load Balancing.

B.

Keep the MTU values at the default setting for GRE and VXLAN communications

C.

Use the command "vsx-sync mclag-interfaces" under the VSX context.

D.

Use the command "vsx-sync active-gateways" under the VSX context.

Question 19

What should be defined on the Edge-1 to establish valid BGP routing between agg-sw1 and agg-sw2 using BGP protocol using the IP addresses above?

Options:

A.

OPTION A

B.

OPTION B

C.

OPTION C

D.

OPTION D

Question 20

Your customer added third-party USB dongles to the USB ports of their AOS 10 access points. The customer uses AP-615 and AP-635 Each AP is connected with a Cat 6A cable to a CX 6300F Class 4 PoE switch All APs are in the same group in HPE Aruba Networking Central and share the same configuration However, many of the dongles do not come up.

Which option will solve this issue?

Options:

A.

Replace the Class a PoE switches with Class 6 PoE switches.

B.

Create two separate service profiles in the loT tab of the Central configuration settings.

C.

Perform a "poe disable" followed by a "poe enable" for the switch ports which connect to the APs so that the APs reboot.

D.

Move the AP-635 access points to a different group in Central to configure the dongles separately from the AP-615.

Question 21

A customer has deployed an AOS 10 mobility gateway cluster consisting of three controllers at a single site The WLAN is configured to tunnel wireless device traffic to the AOS 10 mobility cluster. The clients are authorized to use WPA2-Personal. An end-user has opened a ticket with the helpdesk stating they cannot connect their client device to the network. There are other devices currently associated with the SSID with no issues.

Reviewing the output, what Is the issue?

Options:

A.

The RADIUS response from the authentication server is

B.

The client device has an invalid certificate

C.

The client device has an invalid pre-shared key.

D.

transition mode is not enabled

Question 22

Which command would allow you to verity receipt of a CoA message on an AOS 10 GW?

Options:

A.

packet-capture datapath udp 3799

B.

packet-capture controipath udp 3799

C.

packet-capture interprocess udp 3799

D.

tcpdump host-port 3799

Question 23

You are tasked with developing a comprehensive, flexible, and survivable zero-trust wired access network using CX 6300 switching and HPE Aruba Networking ClearPass Policy Manager. Match the scenario to the special roles to achieve your objectives.

Options:

Question 24

Refer to the exhibit.

Given the log output, which statement is true?

Options:

A.

AP-01's tunnel to 192.168.1.92 is in a survived state.

B.

The gateway with IP address 192.168.1.92 is offline.

C.

AP-01 cannot communicate with the HPE Aruba Networking Central tunnel orchestrator.

D.

The gateway tunnel to the AP has a path MTU issue.

Question 25

After onboarding three new AOS-10 gateways using the full-setup method into the same HPE Aruba Networking Central group, a customer cannot log in to one of the gateways using the HPE Aruba Networking Central remote console due to an incorrect password.

What is causing this issue?

Options:

A.

The admin password created during the full-setup process is not configured to allow the remote console access

B.

The admin password created at the HPE Aruba Networking Central group level has expired

C.

The admin password created using full-setup does not match the global HPE Aruba Networking Central admin password

D.

The admin password created during the full-setup process does not match the HPE Aruba Networking Central group admin password

Question 26

A manufacturing company depends on FTP, email, and RDP services, which are accessed locally. On Monday morning, RDP sessions are not responsive when users on the employee WLAN download their email and large files from the FTP server simultaneously. The network administrator concludes that the mobility gateway's uplinks are congested when that happens.

Which would be the best option the network engineer can propose in the implementation plan to improve RDP responsiveness?

Options:

A.

Update the employee user role with an ACL on position 3 that puts RDP traffic to a high-priority queue and all other traffic to a low-priority queue

B.

Change the employee WLAN from tunneled to bridged so that the bottleneck in the mobility gateways is removed

C.

Set the WMM voice DSCP value on the employee WLAN to 56 and enable the RDP application layer gateway

D.

Update the spanning-tree configuration from enabled to disabled on the gateway's link aggregation to increase the available bandwidth and avoid congestion

Question 27

In a campus topology using VSX with two aggregation switches and downlinks to access switches, which LAG interface configuration at the aggregation layer is correct based on the parameters below?

    ZTP VLAN 1001

    access switch MGMT VLAN 2002

    access switch MGMT VLAN is tagged

    connectivity to the access switch should be maintained before and after the ZTP operation is complete

Options:

A.

B.

C.

D.

Question 28

A customer is evaluating device profiles on a CX 6300 switch. The test device has the following attribute:

• MAC address=81:cd:93:13:ab:31

The test device needs to be assigned the "lot-prod'' role, in addition the "lot-default" role must be applied for any other device connected lo interface 1/1/1. This is a lab environment with no configuration of any external authentication server for the test.

Given the configuration example, what is required to meet this testing requirement?

Options:

A.

Enter the command "pot-access device-profile mode block-until-profile-applied"" for interface 1/1/1.

B.

Enter the command "port-access fallback-role lot-default globally

C.

Enter the command "port-access onboarding-method precedence" to set device profiles with a lower precedence.

D.

Enter the command "port-access device-profile mode block-until-profile-applied" globally.

Question 29

You are testing the use of the automated port-access role configuration process using RadSec authentication over VXLAN. During your testing you observed that the RadSec connection will fan during the digital certificate exchange

What would be the cause of this Issue?

Options:

A.

The RadSec server was defined on the switch using an IPv6 address that was unreachable

B.

Tracking mode was set to "dead-only", and the RadSec server was marked as unreachable.

C.

The switch is configured to establish a TLS connection with a proxy server, not the radius server.

D.

The RADIUS TCP packets are Being dropped and the TLS tunnel is not established.

Question 30

You recently added ClearPass as an authentication server to an HPE Aruba Networking Central group. RADIUS authentication with Local User Roles (LUR) works fine Out the same access points cannot use Downloadable User Roles (DUR).

What should he corrected in this configuration to fa the issue with DUR?

Options:

A.

Add a new Enforcement Policy of type ‘’WEBAUTH’’ on ClearPass and associate it with the matching service on ClearPass

B.

Add the correct IP addresses or IP subnets of the Network Access Devices (NADs) under the "Devices" tab on ClearPass

C.

Replace the AP's expiree digital certificate using the "crypto pki-import pem serverCert" command.

D.

Add the correct values for "CPPM username" and "CPPM Password" m the authentication server configuration on HPE Aruba Networking Central

Question 31

Refer to the exhibits.

What is the effect when you add the statement neighbor 10.2.0.3 send-community both to the IPv4 address family? (Select two)

Options:

A.

It causes R1 to negotiate for the ability to import and export all type-1 and type-2 communities with R2

B.

It causes R1 to allow the exchange of communities with NLRI records in both inbound and outbound directions

C.

It will cause the existing BGP peering between R1 and R2 to bounce

D.

It causes R1 to negotiate the ability to send and receive standard and extended communities with R2

Question 32

A client connecting to a tunneled open network is receiving the wrong VLAN Your customer has a gateway and has sent over a packet capture from a switch port mirror taken from the upstream switch with a packet capture from the IPsec tunnel and the GRE tunnel to help Identify the VLAN being sent from the controller to the AP.

Where will you see the VLAN assignment?

Options:

A.

The GRE tunnel will include the VLAN lag assignment

B.

VLAN tag assignment win not he captured in any of the packet captures

C.

IPsec tunnel will include the VLAN tag assignment

D.

VLAN tag assignment win be included in the port mirror

Question 33

A customer deployed AP-535s for IoT devices that send many small packets. They want to reduce congestion and allow simultaneous transmission to or from multiple users.

Options:

A.

UL MU-MIMO

B.

DL MU-MIMO

C.

HE TXBF

D.

OFDMA

Question 34

Your customer recently decided to build a new wireless network based on AOS-10. The following legacy settings still exist:

    The DHCP server still sends option 60 "ArubaInstantAP" and option 43 including the IP address of the AirWave server in the ZTP VLAN.

    The DNS server has an entry for "aruba-airwave" pointing to the AirWave server.

The customer purchased new AP-655 access points and HPE Aruba Networking Central subscriptions. Each AP is assigned to the “ACX-Group” in the Device Pre-provisioning section of Central, and the external firewall allows HTTPS traffic between APs and the Internet.

What will happen when the new factory default APs are connected to the customer's network for the first time?

Options:

A.

The new APs will contact the IP address of AirWave from DHCP option 43

B.

The new APs will contact the IP address of AirWave learned from the DNS entry "aruba-airwave"

C.

The new APs will contact the cloud and get the “ACX-Group” configuration in HPE Aruba Networking Central

D.

The new APs will contact the cloud and will be pointed to the IP address of AirWave

Question 35

You are troubleshooting a WLAN deployment with APs and gateways set up with an 802.1X tunneled SSID. End-users are complaining that they can't connect to the enterprise SSID. Which possible AP tunnel states could be the cause of the issue? (Select two.)

Options:

A.

SM_STATE_CONNECTING

B.

SM_STATE_SURVIVED

C.

SM_STATE_SURVIVING

D.

SM_STATE_CONNECTED

E.

SM_STATE_REKEYING

Question 36

What is the recommended configuration to ensure link aggregation is consistent in a campus topology using VSX with two aggregation switches and downlinks to access switches?

Options:

A.

Use the command "vsx-sync active-gateways" under the VSX context.

B.

Use a custom LACP hash algorithm for improved load balancing.

C.

Use the command "vsx-sync mclag-interfaces" from the global context.

D.

Use the command "vsx-sync mclag-interfaces" under the VSX context.

Question 37

Refer to the CLI output below:

What statement about the output above is correct?

Options:

A.

The port-access role was configured with gateway-role visitor

B.

The secondary tunnel endpoint IP is 10.10-10.151.

C.

The client authenticated using dot1x.

D.

The UBT zone was configured to use a user-defined VRF

Page: 1 / 13
Total 126 questions