Question 1
A financial services company is implementing a Zero Trust architecture using Aruba solutions. The primary requirement is to enforce micro-segmentation for servers and virtual machines in the data center, ensuring that workloads can only communicate with explicitly authorized clients and other servers. Which combination of Aruba technologies is BEST suited to enforce these granular, stateful east-west policies directly in the data center switching fabric?
Answer and explanation
Correct answer: B
In the HPE Aruba Networking ESP data-center design, the CX 10000 Distributed Services Switch (DSS) 'enforces east-west traffic policy using an inline stateful firewall in hardware within the switch', so micro-segmentation is enforced at the top-of-rack switch port without hair-pinning server-to-server traffic through a centralized firewall. Aruba Fabric Composer, integrated with vCenter and AMD Pensando Policy Services Manager (PSM), manages the east-west policy centrally and lets VM administrators assign workloads to policy groups. Standard AOS-CX switches only support stateless ACLs (the stateful Policy Enforcement Firewall runs on Aruba gateways and APs); gateway IDS/IPS inspects only traffic that passes through the gateway; WIPS protects the RF environment; and EdgeConnect/OnGuard address SD-WAN and endpoint posture.