Question 1
A financial services firm is architecting a new campus network and requires strict traffic separation between its Corporate, Guest, and high-frequency Trading user groups. The primary design goal is to enforce security policies at the network edge and ensure that traffic from one group cannot be snooped by another, even within the same physical switch. The solution must scale to hundreds of policies. Which HPE Aruba Networking technology is specifically designed to meet this requirement by creating encrypted tunnels from the access switch to the gateway cluster?
Answer and explanation
Correct answer: B
Dynamic Segmentation is the correct technology. It uses a centralized, policy-based approach to create secure GRE tunnels from the access device (switch or AP) to a Gateway Cluster. This encapsulates user traffic and enforces policies centrally, providing the required traffic isolation and security at the edge. VSX is for high availability, EVPN-VXLAN is a fabric technology, and VSF is for switch stacking; none provide this specific user-to-gateway tunneling mechanism for policy enforcement.