Aruba Certified Network Security Expert Free Sample Questions

Create a free account to browse all 17 sample questions. The full practice test includes 158 questions. Use the simulator for timed and flashcard mode.

Try Simulator

HPE6-A84 Sample Questions

  1. Question 1

    Q1

    You are designing an Aruba ClearPass Policy Manager (CPPM) solution for a customer. You learn that the customer has a Palo Alto firewall that filters traffic between clients in the campus and the data center.Which integration can you suggest? A.Sending Syslogs from the firewall to CPPM to signal CPPM to change the authentication status for misbehaving clientsB.Importing clients’ MAC addresses to configure known clients for MAC authentication more quicklyC.Establishing a double layer of authentication at both the campus edge and the data center DMZD.Importing the firewall's rules to program downloadable user roles for AOS-CX switches more quickly

    Show answer & explanation

    Correct answer: A

  2. Question 2

    Q2

    Refer to the scenario.A customer has an Aruba ClearPass cluster. The customer has AOS-CX switches that implement 802.1X authentication to ClearPass Policy Manager (CPPM).Switches are using local port-access policies.The customer wants to start tunneling wired clients that pass user authentication only to an Aruba gateway cluster. The gateway cluster should assign these clients to the “eth-internet" role. The gateway should also handle assigning clients to their VLAN, which is VLAN 20.The plan for the enforcement policy and profiles is shown below:The gateway cluster has two gateways with these IP addresses:• Gateway 1o VLAN 4085 (system IP) = 10.20.4.21o VLAN 20 (users) = 10.20.20.1o VLAN 4094 (WAN) = 198.51.100.14• Gateway 2o VLAN 4085 (system IP) = 10.20.4.22o VLAN 20 (users) = 10.20.20.2o VLAN 4094 (WAN) = 198.51.100.12• VRRP on VLAN 20 = 10.20.20.254The customer requires high availability for the tunnels between the switches and the gateway cluster. If one gateway falls, the other gateway should take over its tunnels. Also, the switch should be able to discover the gateway cluster regardless of whether one of the gateways is in the cluster.You are setting up the UBT zone on an AOS-CX switch.Which IP addresses should you define in the zone? A.Primary controller = 10.20.4.21; backup controller = 10.20.4.22B.Primary controller = 198.51.100.14; backup controller = 10.20.4.21C.Primary controller = 10.20.4.21; backup controller, not definedD.Primary controller = 10.20.20.254; backup controller, not defined

    Question 2 image
    Show answer & explanation

    Correct answer: A

  3. Question 3

    Q3

    Refer to the scenario.A customer requires these rights for clients in the “medical-mobile” AOS firewall role on Aruba Mobility Controllers (MCs):Permitted to receive IP addresses with DHCPPermitted access to DNS services from 10.8.9.7 and no other serverPermitted access to all subnets in the 10.1.0.0/16 range except denied access to 10.1.12.0/22Denied access to other 10.0.0.0/8 subnetsPermitted access to the InternetDenied access to the WLAN for a period of time if they send any SSH trafficDenied access to the WLAN for a period of time if they send any Telnet trafficDenied access to all high-risk websitesExternal devices should not be permitted to initiate sessions with “medical-mobile” clients, only send return traffic.The exhibits below show the configuration for the role.There are multiple issues with this configuration. What is one change you must make to meet the scenario requirements? (In the options, rules in a policy are referenced from top to bottom. For example, “medical-mobile” rule 1 is “ipv4 any any svc-dhcp permit,” and rule 8 is “ipv4 any any any permit”.) A.In the “medical-mobile” policy, move rules 2 and 3 between rules 7 and 8.B.In the “medical-mobile” policy, change the subnet mask in rule 3 to 255.255.248.0.C.Move the rule in the “apprf-medical-mobile-sacl” policy between rules 7 and 8 in the “medical-mobile” policy.D.In the “medical-mobile” policy, change the source in rule 8 to “user.”

    Question 3 image
    Show answer & explanation

    Correct answer: B

  4. Question 4

    Q4

    A company has an Aruba ClearPass server at 10.47.47.8, FQDN radius.acnsxtest.local. This exhibit shows ClearPass Policy Manager's (CPPM's) settings for an Aruba Mobility Controller (MC).The MC is already configured with RADIUS authentication settings for CPPM, and RADIUS requests between the MC and CPPM are working. A network admin enters and commits this command to enable dynamic authorization on the MC: aaa rfc-3576-server 10.47.47.8But when CPPM sends CoA requests to the MC, they are not working. This exhibit shows the RFC 3576 server statistics on the MC:How could you fix this issue? A.Change the UDP port in the MCs’ RFC 3576 server config to 3799.B.Enable RadSec on the MCs’ RFC 3676 server config.C.Configure the MC to obtain the time from a valid NTP server.D.Make sure that CPPM is using an ArubaOS Wireless RADIUS CoA enforcement profile.

    Question 4 image
    Show answer & explanation

    Correct answer: A

  5. Question 5

    Q5

    A large enterprise is deploying User-Based Tunneling (UBT) using AOS-CX switches at the edge and a cluster of Aruba Gateways at the core. The security architect mandates that all guest traffic must be tunneled to the DMZ gateways, while corporate traffic is tunneled to the Data Center gateways. Both traffic types originate from the same physical switch ports. Which architectural component allows the AOS-CX switch to direct traffic to different gateway clusters based on the user role derived from ClearPass?

    Show answer & explanation

    Correct answer: A

    In advanced UBT deployments on AOS-CX, you can define multiple UBT zones. Each zone points to a different Primary Controller (Gateway Cluster). By mapping the user role to a specific UBT zone ID, the switch knows which tunnel destination to use for that specific user session.

  6. Question 6

    Q6

    You are troubleshooting a Downloadable User Role (DUR) failure on an AOS-CX switch. The switch successfully authenticates the user via ClearPass, but the role fails to download, placing the port in a generic reject state. You verify that the switch has the correct ClearPass root CA certificate installed. A packet capture reveals the switch is attempting to contact ClearPass on port 443 but receiving a reset. Which configuration on the ClearPass Policy Manager is most likely missing?

    Show answer & explanation

    Correct answer: B

    When AOS-CX switches download a DUR, they often use the IP address returned in the RADIUS response to initiate the HTTPS connection. If the ClearPass HTTPS server certificate does not contain this IP address in the SAN field, the TLS handshake may fail or be rejected depending on strict validation settings, or the connection might be reset if the service is unreachable due to certificate validation errors on the client side.

  7. Question 7

    Q7

    An organization requires a highly secure authentication flow for their finance department. The requirements are:

    1. Users must authenticate using EAP-TLS with a machine certificate.
    2. The machine must pass a health check (OnGuard) before full access is granted.
    3. If the health check is pending, the user sits in a quarantine role.

    Which combination of ClearPass Service configurations best achieves this workflow using a single service where possible?

    Show answer & explanation

    Correct answer: B

    OnGuard agents communicate via HTTP/HTTPS (WebAuth) to ClearPass, while the network access is RADIUS (802.1X). These are distinct flows. The WebAuth service updates the endpoint's posture status. The 802.1X service then checks this cached endpoint attribute (Posture Status) during re-authentication/CoA to determine the enforcement profile.

  8. Question 8

    Q8

    A network administrator needs to implement a 'Headless Device' onboarding process for printers and IoT devices that do not support 802.1X. The goal is to profile them accurately and allow them onto the network only if they match specific device fingerprints. Which set of ClearPass features should be combined to achieve this most securely?

    Show answer & explanation

    Correct answer: A

    The standard flow for unknown IoT devices is: 1. Device connects via MAC Auth. 2. If unknown, allow temporarily with limited access (or use Allow-All-Mac-Auth). 3. ClearPass collects DHCP fingerprints/SPAN data. 4. Once profiled, ClearPass sends a Change of Authorization (CoA) to bounce the port. 5. Device reconnects, matches the new specific Profile/Attribute in the policy, and gets full access.

Register free to unlock 9 more sample questions

Create a free account to continue with the rest of the HPE6-A84 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 158 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon