HPE Campus Access Switching Expert (Written) Free Sample Questions

20 free sample questions215 in the full practice test

Try simulator

HPE7-A06 Sample Questions

  1. Question 1

    A financial institution is implementing a multi-VRF environment on their ArubaOS-CX core switches to segment traffic between corporate, trading, and guest networks. A network architect needs to ensure that specific high-priority trading data from the trading VRF can be routed to a shared monitoring service located in the corporate VRF, without leaking all routes between the VRFs. Which routing feature is the most precise and secure method to achieve this specific inter-VRF communication?

    Answer and explanation

    Correct answer: C

    The most scalable, secure, and precise method for controlled inter-VRF routing on ArubaOS-CX switches is using Multi-Protocol BGP (MP-BGP) with route targets (RTs). By configuring specific RTs for export on one VRF and for import on another, an administrator can selectively leak only the required routes (e.g., the monitoring service prefix) without merging the entire routing tables. Static routes are less dynamic, and PBR is more for path selection than inter-VRF routing. Merging VRFs into a global table is insecure and defeats the purpose of segmentation.

  2. Question 2

    Multiple answers

    A network engineer is troubleshooting an ArubaOS-CX switching environment where an NAE agent designed to monitor BGP neighbor states is not generating expected alerts. The agent's script is syntactically correct and the NAE engine is running. What are the most likely reasons for the agent's failure to trigger alerts? (Select TWO)

    Answer and explanation

    Correct answers: B, C

    A common failure point for NAE agents is an incorrect resource URI. If the script's monitor is trying to access a path like /rest/v10.04/system/bgp/neighbors but the path is wrong, misspelled, or unsupported in the current firmware, the agent cannot retrieve data and will not trigger alerts. Another likely issue is that the condition being checked in the script logic is never met, so the alert action is never called.

    Even if the agent is monitoring the correct URI, the Python logic that evaluates the data might be flawed. For example, if the script checks for neighbor_state == 'down' but the state is actually reported as 'Idle' or 'Connect', the condition will never evaluate to true, and the alert action will not be triggered. This is a common issue in script-based monitoring.

  3. Question 3

    True or False: In an ArubaOS-CX VSX environment, the VSX keepalive link is mandatory for detecting a dual-active scenario, and it must be a direct Layer 3 connection between the primary and secondary switches.

    Answer and explanation

    Correct answer: A

    This statement is true. The VSX keepalive connection is a critical component for split-brain detection (dual-active scenario). It operates at Layer 3 and is used as a heartbeat mechanism when the Inter-Switch Link (ISL) fails. A direct point-to-point connection is the recommended and most reliable design, although routing it through an OOB management network is a possible, though less ideal, alternative.

  4. Question 4

    A university is deploying a large campus network with Aruba CX switches and ClearPass. The security policy requires that devices connecting to wired ports are dynamically assigned to different VLANs based on their type (e.g., IP phones, printers, corporate laptops). A network engineer has configured 802.1X and MAB, and is now creating enforcement policies in ClearPass. Which ClearPass feature is essential for identifying the device type and returning the correct VLAN to the switch?

    Answer and explanation

    Correct answer: C

    ClearPass Profiling is the feature designed for device identification. It collects attributes from network traffic and authentication requests (like DHCP fingerprints, MAC OUI, and LLDP data) to classify endpoints. Once a device is profiled (e.g., identified as a 'Polycom IP Phone'), enforcement policies can use this profile information as a condition to return specific RADIUS attributes, such as Tunnel-Private-Group-ID, which instructs the switch to place the device in the correct VLAN.

  5. Question 5

    A hospital is upgrading its campus core with a pair of Aruba 8360 switches running in a VSX pair. They have a requirement for multicast video streaming for medical imaging, which relies on PIM-SM. The network administrator needs to ensure multicast routing functions correctly and efficiently across the VSX pair. What is the recommended approach for configuring PIM in this VSX environment?

    Answer and explanation

    Correct answer: B

    In a VSX environment, PIM must be configured on both switches. The pim active-forwarding command should be enabled on the SVIs within the VSX pair. This allows both switches to actively forward multicast traffic, preventing traffic from being dropped and enabling efficient load balancing. PIM state is not synchronized via VSX; each switch maintains its own PIM neighbor relationships and state tables. Disabling PIM on one switch would break multicast routing.

  6. Question 6

    During a network audit, a security analyst discovers that switches in the access layer are vulnerable to STP manipulation attacks, such as a rogue device claiming to be the root bridge. To mitigate this, the administrator decides to implement STP protection features on edge ports connected to end-user devices. Which ArubaOS-Switch feature should be configured on these ports to prevent them from becoming STP root or designated ports?

    Answer and explanation

    Correct answer: D

    Root Guard is the specific feature designed for this purpose. When enabled on a port, it prevents that port from becoming an STP root port. If the port receives a superior BPDU (Bridge Protocol Data Unit), Root Guard will place the port into a 'root-inconsistent' state, effectively ignoring the rogue BPDU and protecting the integrity of the STP topology. BPDU Guard would disable the port entirely, which might be too aggressive, and Loop Guard is for preventing loops when BPDUs are no longer received.

  7. Question 7

    An e-commerce company is experiencing intermittent packet loss and high latency for its critical application servers connected to a VSF stack of Aruba 5406R switches. A network analysis reveals that a high volume of broadcast and unknown unicast traffic from a misconfigured server is flooding a large VLAN, consuming significant switch CPU and link bandwidth. What is the most effective feature to limit the impact of this traffic on the VSF stack?

    Answer and explanation

    Correct answer: C

    Broadcast-traffic rate limiting (often called storm control) is specifically designed to mitigate this issue. By setting a threshold (e.g., in packets-per-second or percentage of bandwidth) for broadcast traffic on switch ports, the feature can drop excessive broadcast packets, preventing them from overwhelming the switch's CPU and fabric. This directly addresses the root cause of the performance degradation. QoS would help prioritize good traffic but wouldn't stop the flood, and IGMP snooping only affects multicast traffic.

  8. Question 8

    A consultant is designing a resilient network for a manufacturing plant using ArubaOS-CX switches. The design uses two core switches and multiple access layer switch stacks. To provide redundant uplinks from an access stack to the two core switches, the consultant configures a multi-chassis link aggregation group (MC-LAG). Which underlying technology on the core switches is required to support this MC-LAG configuration?

    Answer and explanation

    Correct answer: C

    Virtual Switching Extension (VSX) is the ArubaOS-CX technology that enables two separate switches to appear as a single logical switch to downstream devices. This is the foundation for creating a multi-chassis LAG (MC-LAG). The downstream access stack forms a standard LACP LAG, with its physical members connected to each of the VSX-paired core switches. VSX ensures the two core switches coordinate to handle the LAG traffic as a single entity.

  9. Question 9

    An administrator is configuring 802.1X with EAP-TLS on an ArubaOS-CX switch for wired authentication against a ClearPass server. Corporate clients are issued certificates from an internal Certificate Authority (CA). When a client connects, the authentication fails. The ClearPass access tracker shows the error 'TLS session error'. The switch configuration is correct, and the client has a valid certificate. What is a common cause for this specific error in an EAP-TLS deployment?

    Answer and explanation

    Correct answer: B

    In EAP-TLS, mutual authentication occurs. The client must trust the server's certificate, and the server must trust the client's. A 'TLS session error' often indicates a failure in establishing this trust. If the RADIUS server certificate presented by ClearPass is not signed by a CA that the client trusts, the client will terminate the TLS handshake, resulting in this error. The client's supplicant must be configured to trust the CA that issued the ClearPass RADIUS certificate.

  10. Question 10

    A large enterprise is designing a campus network using an EVPN-VXLAN fabric with ArubaOS-CX switches. The goal is to provide Layer 2 and Layer 3 segmentation for multiple tenants. Which statement accurately describes the role of the BGP EVPN control plane in this architecture?

    Answer and explanation

    Correct answer: C

    The primary function of the BGP EVPN control plane is to replace the traditional flood-and-learn mechanism of Ethernet. VTEPs (VXLAN Tunnel Endpoints) use BGP to advertise learned MAC addresses (and optionally IP addresses for ARP suppression) to other VTEPs. This allows for a more scalable and efficient fabric, as unicast traffic can be routed directly to the destination VTEP without prior flooding. Encapsulation is the role of the VXLAN data plane, not the EVPN control plane.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 215 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon