HPE Aruba Network Security Expert Free Sample Questions

20 free sample questions214 in the full practice test

Try simulator

HPE7-A10 Sample Questions

  1. Question 1

    A financial services company is implementing a Zero Trust architecture using Aruba solutions. The primary requirement is to enforce micro-segmentation for servers and virtual machines in the data center, ensuring that workloads can only communicate with explicitly authorized clients and other servers. Which combination of Aruba technologies is BEST suited to enforce these granular, stateful east-west policies directly in the data center switching fabric?

    Answer and explanation

    Correct answer: B

    In the HPE Aruba Networking ESP data-center design, the CX 10000 Distributed Services Switch (DSS) 'enforces east-west traffic policy using an inline stateful firewall in hardware within the switch', so micro-segmentation is enforced at the top-of-rack switch port without hair-pinning server-to-server traffic through a centralized firewall. Aruba Fabric Composer, integrated with vCenter and AMD Pensando Policy Services Manager (PSM), manages the east-west policy centrally and lets VM administrators assign workloads to policy groups. Standard AOS-CX switches only support stateless ACLs (the stateful Policy Enforcement Firewall runs on Aruba gateways and APs); gateway IDS/IPS inspects only traffic that passes through the gateway; WIPS protects the RF environment; and EdgeConnect/OnGuard address SD-WAN and endpoint posture.

  2. Question 2

    A security analyst is investigating a suspected advanced persistent threat (APT) that has compromised a user's credentials. The analyst needs to trace where on the network the stolen credentials have been used. Which log source should be examined FIRST to identify the first network authentication that used those credentials and every subsequent authenticated session?

    Answer and explanation

    Correct answer: C

    ClearPass Policy Manager is the authentication server, so its authentication records (Monitoring > Live Monitoring > Access Tracker) list every RADIUS, TACACS+ and WebAuth request with the username, host MAC address, NAS IP/name, service, login status (Accept, Reject or Timeout), roles and enforcement profiles. Filtering on the compromised username over the investigation window shows the first network authentication with the stolen credentials and every later session, including the device and the network access device (switch/AP) used. Gateway firewall logs and switch syslog are keyed to traffic and IP addresses rather than to the credential, and CPDI classification data describes devices rather than user logins; they become useful pivots once the authenticated sessions have been identified.

  3. Question 3

    Multiple answers

    A university is deploying a new Public Key Infrastructure (PKI) to secure its wireless network via 802.1X EAP-TLS. The security team wants to ensure that if a student's laptop is lost or stolen, its certificate can be immediately invalidated to prevent network access. Which TWO PKI components or protocols are essential for implementing this real-time certificate validation check during the authentication process? (Select TWO).

    Answer and explanation

    Correct answers: A, C

    Both mechanisms let the RADIUS server check whether a client certificate has been revoked during EAP-TLS. A Certificate Revocation List (CRL) is a CA-signed list of revoked certificate serial numbers that the server downloads and refreshes (in ClearPass: Administration > Certificates > Revocation Lists, updated on a schedule or with Check Now). The Online Certificate Status Protocol (OCSP) queries a responder for the status (good, revoked or unknown) of an individual certificate at authentication time and is recommended because it gives real-time status (ClearPass EAP-TLS method: Verify Certificate using OCSP = Optional, Required or Required (CRL fallback)). A Registration Authority verifies requester identities, SCEP enrolls certificates and the root CA anchors trust; none of them checks revocation during authentication.

  4. Question 4

    True or False: After a Network Analytic Engine (NAE) script is successfully installed and validated on an AOS-CX switch, it will automatically begin monitoring the network and generating alerts based on its logic.

    Answer and explanation

    Correct answer: B

    This statement is false. Installing an NAE script only makes it available on the switch. To activate it, a network administrator must explicitly create an NAE agent based on that script. The agent is the running instance of the script that performs the actual monitoring and alerting. Without creating the agent, the script remains dormant.

  5. Question 5

    A multinational corporation is enhancing its security posture by integrating ClearPass Device Insight (CPDI) with its existing ClearPass Policy Manager (CPPM) deployment. The goal is to dynamically adjust access policies based on the real-time risk score of endpoints. An administrator observes that CPDI has flagged a corporate laptop with a high-risk score due to it communicating with a known command-and-control server. Which automated remediation action is the most effective and commonly implemented response within CPPM?

    Answer and explanation

    Correct answer: C

    The integration between CPDI and CPPM is designed for dynamic, automated responses. When CPDI detects a high-risk device, it can signal CPPM to trigger a RADIUS Change of Authorization (CoA). This allows CPPM to instantly re-evaluate the device's session and apply a different enforcement policy, such as assigning a 'Quarantine' role that maps to a restricted VLAN. This contains the threat while allowing for further investigation, which is a core tenet of dynamic Zero Trust security.

  6. Question 6

    During a forensic investigation into a data breach, a security professional has collected disk images and log files from several Aruba systems. To ensure the admissibility of this evidence in legal proceedings, it is crucial to maintain a verifiable record that the collected data has not been altered. Which cryptographic process should be applied to each piece of evidence to create a unique digital fingerprint for integrity verification?

    Answer and explanation

    Correct answer: D

    Cryptographic hashing algorithms like SHA-256 are used to create a fixed-size, unique digital fingerprint (hash value) of a piece of data. Any change to the original data, no matter how small, will result in a completely different hash value. In digital forensics, hashing is fundamental for proving data integrity. The hash of the evidence is calculated upon collection and recorded in the chain of custody; it can be recalculated later to prove the evidence has not been tampered with.

  7. Question 7

    A retail company is using Aruba WIPS to protect its wireless environment. An alert is generated for a rogue AP operating on the same SSID as the corporate network. The security team needs to contain this threat immediately to prevent employees and customers from connecting to it. What is the most effective and direct containment technique available within the Aruba WIPS solution?

    Answer and explanation

    Correct answer: B

    Deauthentication containment is Aruba WIPS's direct, over-the-air containment method: Aruba APs and air monitors near the rogue disrupt its associations by sending spoofed 802.11 deauthentication frames - a broadcast deauthentication, followed by unicast deauthentication frames from the AP to the station and from the station to the AP - so clients cannot stay connected to it. (Tarpit and wired containment are Aruba's other containment methods; containment may be subject to regulatory restrictions such as FCC rules.) Blocking the rogue's MAC in the gateway firewall does not stop clients associating over the air, physically removing it is not immediate, and raising transmit power does not prevent association to the rogue.

  8. Question 8

    An administrator is creating an NAE script to monitor Control Plane Policing (CoPP) statistics on an AOS-CX switch to detect potential Denial of Service (DoS) attacks. After deploying the script and creating the agent, alerts are being generated. Which protocol traffic, when seen in excessive amounts hitting the control plane, is a primary indicator of a reconnaissance attempt or the precursor to a larger attack?

    Answer and explanation

    Correct answer: C

    Control Plane Policing (CoPP) is designed to protect the switch's CPU from being overwhelmed. A flood of Address Resolution Protocol (ARP) requests, often seen in an 'ARP scan,' is a common reconnaissance technique used by attackers to map out the active hosts on a subnet. An NAE agent monitoring CoPP would see a spike in the ARP queue, which is a strong indicator of a potential attack and should be alerted on.

  9. Question 9

    Multiple answers

    A hospital is deploying a secure network for its Internet of Medical Things (IoMT) devices, such as infusion pumps and patient monitors. The primary security goal is to enforce a strict Zero Trust policy where these devices can only communicate with their designated management server and nothing else. Which THREE Aruba security features are essential to build this solution? (Select THREE).

    Answer and explanation

    Correct answers: A, B, D

    The solution needs identification, policy and enforcement. (1) ClearPass Device Insight discovers and classifies the headless IoMT devices (active scans plus passive traffic analysis) and shares the classification and tags with ClearPass. (2) ClearPass Policy Manager uses that context in role mapping and enforcement policies to assign a restrictive role (for example, 'Infusion-Pump'). (3) The role is enforced in the network: the Policy Enforcement Firewall on the AP (bridged WLAN) or gateway (tunneled WLAN/UBT) applies stateful role-based rules, and AOS-CX switches apply the role's local or downloadable user-role policy (stateless ACLs), so the device can reach only its management server. EdgeConnect SD-WAN traffic shaping and NAE performance monitoring provide neither device identification nor segmentation.

  10. Question 10

    When designing a role-based access control (RBAC) policy in ClearPass for a large enterprise, a network architect wants to ensure that access privileges are determined by an employee's department, which is stored in Active Directory. What is the correct ClearPass component to configure to fetch this department attribute and use it for policy decisions?

    Answer and explanation

    Correct answer: C

    In ClearPass, the Authentication Source configuration is where you connect to external identity stores like Active Directory. Within this configuration, you define which attributes to fetch during the authentication process. By adding the 'department' attribute to the list of fetched attributes in the AD Authentication Source, it becomes available for use in subsequent Role Mapping and Enforcement policies.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 214 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon