Aruba Campus Access Mobility Expert (Written) Free Sample Questions

20 free sample questions176 in the full practice test

Try simulator

HPE7-A07 Sample Questions

  1. Question 1

    A financial services firm is deploying an EVPN-VXLAN fabric using Aruba CX switches. The network architect has designed the fabric with a two-tier spine-and-leaf topology. To ensure optimal and loop-free forwarding for Layer 2 broadcast, unknown unicast, and multicast (BUM) traffic within a VNI, which mechanism is the Aruba-recommended best practice to implement in the underlay network?

    Answer and explanation

    Correct answer: B

    The recommended best practice for handling BUM traffic in an EVPN-VXLAN fabric is to use multicast in the underlay network, specifically PIM-SM. This allows VTEPs to join multicast groups corresponding to VNIs, ensuring BUM traffic is efficiently forwarded only to VTEPs that need it, rather than flooding it across the entire underlay. Static replication is not scalable, ingress replication relies on the control plane which can be less efficient for high BUM rates, and IGMP snooping operates at Layer 2 within a VLAN, not in the Layer 3 underlay for VXLAN.

  2. Question 2

    Multiple answers

    A university is implementing Dynamic Segmentation with Aruba Gateways and Aruba CX switches. A security policy must be enforced where authenticated users are assigned a 'Student' role. This role should allow access to the internet and university portal servers, but explicitly deny any traffic to the 'Faculty_Research' subnet. Which components are required to build and enforce this policy? (Select TWO)

    Answer and explanation

    Correct answers: A, B

    Dynamic Segmentation relies on a centralized policy engine (ClearPass) to assign roles and a network device (Aruba Gateway) to enforce them. ClearPass authenticates the user and, based on its own policies, returns the 'Student' role name via a RADIUS enforcement profile. The Aruba Gateway, having received this role, applies its locally configured 'Student' user role, which contains the specific ACLs to permit internet/portal access and deny access to the research subnet. VSX provides redundancy but doesn't define the policy, and NetConductor is for fabric orchestration.

  3. Question 3

    A consultant is troubleshooting a newly configured VSX pair of Aruba CX 8360 switches. The ISL link is up and the keepalive is successful over the management network. However, the secondary switch continually fails to synchronize its configuration and reports a 'sync-loss' state. The consultant verifies that vsx-sync is enabled for the necessary features. What is the most likely cause of this synchronization failure?

    Answer and explanation

    Correct answer: B

    For VSX synchronization to function correctly, both switches in the pair must be running the exact same ArubaOS-CX software version. A mismatch in firmware will prevent the configuration synchronization protocol from working, leading to a persistent 'sync-loss' state even if the ISL and keepalive links are healthy. While NTP is a best practice, minor time drifts won't block synchronization. The ISL uses LACP which negotiates link parameters, and the keepalive should not be routed through the ISL.

  4. Question 4

    True or False: In an Aruba EVPN-VXLAN fabric, the Distributed Anycast Gateway functionality requires each VTEP participating in a given VNI to be configured with the exact same IP and MAC address for its SVI.

    Answer and explanation

    Correct answer: A

    This statement is true. The core principle of a Distributed Anycast Gateway (DAG) is that every leaf switch (VTEP) that serves as a gateway for a particular subnet (VNI) presents the identical default gateway IP and MAC address to the connected hosts. This allows hosts to send traffic to their local leaf for routing, enabling optimal egress traffic paths and seamless host mobility within the fabric.

  5. Question 5

    A hospital is deploying EAP-TLS for its corporate wireless network to achieve the highest level of security. The network team is using Aruba ClearPass as the RADIUS server. During testing, corporate-issued laptops are failing to connect. A packet capture on the client shows the ClearPass server is sending a RADIUS Access-Reject message immediately after the client sends its Client Hello message. What is the most probable misconfiguration in ClearPass?

    Answer and explanation

    Correct answer: C

    In EAP-TLS, the RADIUS server must trust the Certificate Authority (CA) that issued the client's certificate. If the root or intermediate CA certificate is not imported into the ClearPass Trust List, ClearPass cannot validate the client's certificate chain and will reject the authentication attempt. The rejection happening immediately after the Client Hello suggests the server cannot even begin to validate the client's presented identity, which points directly to a trust list issue. An expired client certificate or untrusted server certificate would cause failure at a later stage of the TLS handshake.

  6. Question 6

    A network administrator is configuring a BGP peering between an Aruba CX switch at the campus edge and an ISP router. The administrator needs to prevent routes learned from other internal BGP peers from being advertised to the ISP. Which BGP attribute or mechanism should be used in an outbound route map to achieve this?

    Answer and explanation

    Correct answer: B

    Routes originated locally within the BGP process on the Aruba CX switch will have an empty AS-Path. Routes learned from other internal BGP (iBGP) peers or external BGP (eBGP) peers will have one or more AS numbers in the path. To advertise only locally originated routes, the administrator should create a route map that permits routes matching an empty AS-Path (often represented by the regex ^$) and denies all others. MED and Local Preference are used for influencing inbound traffic, and weight is for local path selection.

  7. Question 7

    A large retail company is migrating its campus core from a traditional Layer 2 design to a more resilient architecture using two Aruba CX 8400 switches. The primary goals are to provide active-active forwarding for all VLANs, eliminate STP, and ensure sub-second failover. Which ArubaOS-CX technology is specifically designed to meet all these requirements?

    Answer and explanation

    Correct answer: B

    Virtual Switching Extension (VSX) is Aruba's virtualization technology that allows two supported switches to appear as a single logical device to the rest of the network. It provides active-active forwarding paths, enabling the use of all available bandwidth and eliminating the need for Spanning Tree Protocol (STP) between the core and access layers through multi-chassis link aggregation (MC-LAG). VSX is designed for high availability with sub-second failover. VRF is for network segmentation, VRRP is for active-standby gateway redundancy, and VSF is a stacking technology for different switch models.

  8. Question 8

    While configuring an Aruba wireless network using AirWave, a network engineer needs to ensure that all configuration changes are validated against a set of corporate security standards before being pushed to devices. For example, no AP group should be allowed to use WPA2-Personal (PSK). Which AirWave feature should be used to enforce this policy?

    Answer and explanation

    Correct answer: C

    AirWave's Configuration Audit and Compliance feature is specifically designed for this purpose. It allows administrators to define a 'golden' or desired configuration template and then audit devices against it. The compliance engine can flag any deviations, such as the use of a forbidden authentication method like PSK, and can be configured to automatically remediate the configuration. Triggers and Alerts are for monitoring device status, VisualRF is for location and heatmaps, and RAPIDS is for rogue AP detection.

  9. Question 9

    A solutions architect is designing a campus network using a distributed overlay with EVPN-VXLAN. The design includes multiple VNIs that need to communicate with each other. Which EVPN route type is responsible for advertising the IP prefixes that enable inter-VNI (Layer 3) routing?

    Answer and explanation

    Correct answer: D

    The EVPN Type 5 route, or IP Prefix Route, is specifically used to advertise IP prefixes (routes) between different VNIs, enabling Layer 3 routing across the fabric. Type 2 routes advertise MAC and IP addresses of hosts within a single VNI for Layer 2 forwarding. Type 3 routes are used for BUM traffic handling. Type 1 routes are for auto-discovery and multihoming. Therefore, Type 5 is the correct answer for inter-VNI routing.

  10. Question 10

    Multiple answers

    A technician is using the Aruba Central dashboard to troubleshoot a connectivity issue for a specific wireless client. The client is connected but reports extremely slow speeds. The technician navigates to the client details page. Which THREE of the following metrics are most critical to examine first to diagnose a potential RF-related performance problem? (Select THREE)

    Answer and explanation

    Correct answers: A, C, E

    When diagnosing RF performance issues, SNR, PHY Rate, and Retransmission Rate are the most critical metrics. A low SNR indicates a poor quality signal. A low PHY (data) rate indicates the client and AP have negotiated a slow connection speed, often due to poor signal. A high Retransmission Rate (Retries) indicates that frames are being corrupted in transit, usually due to interference or weak signal, which severely impacts throughput. Association Time and IP address are relevant for connectivity but not primary indicators of RF performance.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 176 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon