Aruba ACNSA HPE6-A78 Practice Test Engine Try These 62 Exam Questions [Q19-Q41]

Share

Aruba ACNSA HPE6-A78 Practice Test Engine: Try These 62 Exam Questions

Guaranteed Success in Aruba ACNSA HPE6-A78 Exam Dumps

NEW QUESTION # 19
You have been instructed to look in the ArubaOS Security Dashboard's client list Your goal is to find clients mat belong to the company and have connected to devices that might belong to hackers Which client fits this description?

  • A. MAC address d8:50:e6:f3;TO;ab; Client Classification Interfering. AP Classification Rogue
  • B. MAC address d8:50:e6:f3;6d;a4; Client Classification Authorized; AP Classification, interfering
  • C. MAC address d8:50:e6 f3;6e;c5; Client Classification Interfering. AP Classification Neighbor
  • D. MAC address d8:50:e6:f3;6e;60; Client Classification Interfering. AP Classification Interfering

Answer: D


NEW QUESTION # 20
A company with 382 employees wants to deploy an open WLAN for guests. The company wants the experience to be as follows:

The company also wants to provide encryption for the network for devices mat are capable, you implement Tor the WLAN?
Which security options should

  • A. WPA3-Personal and MAC-Auth
  • B. Captive portal and WPA3-Personai
  • C. Captive portal and Opportunistic Wireless Encryption (OWE) in transition mode
  • D. Opportunistic Wireless Encryption (OWE) and WPA3-Personal

Answer: C


NEW QUESTION # 21
What is one difference between EAP-Tunneled Layer security (EAP-TLS) and Protected EAP (PEAP)?

  • A. EAP-TLS creates a TLS tunnel for transmitting user credentials securely while PEAP protects user credentials with TKIP encryption.
  • B. EAP-TLS creates a TLS tunnel for transmitting user credentials, while PEAP authenticates the server and supplicant during a TLS handshake.
  • C. EAP-TLS requires the supplicant to authenticate with a certificate, hut PEAP allows the supplicant to use a username and password.
  • D. EAP-TLS begins with the establishment of a TLS tunnel, but PEAP does not use a TLS tunnel as part of Its process

Answer: C


NEW QUESTION # 22
What is a Key feature of me ArubaOS firewall?

  • A. The firewall is stateful which means that n can track client sessions and automatically allow return traffic for permitted sessions
  • B. The firewall Includes application layer gateways (ALGs). which it uses to filter Web traffic based on the reputation of the destination web site.
  • C. The firewall is designed to fitter traffic primarily based on wireless 802.11 headers, making it ideal for mobility environments
  • D. The firewall examines all traffic at Layer 2 through Layer 4 and uses source IP addresses as the primary way to determine how to control traffic.

Answer: B


NEW QUESTION # 23
Refer to the exhibit.

This Aruba Mobility Controller (MC) should authenticate managers who access the Web Ul to ClearPass Policy Manager (CPPM) ClearPass admins have asked you to use RADIUS and explained that the MC should accept managers' roles in Aruba-Admin-Role VSAs Which setting should you change to follow Aruba best security practices?

  • A. Clear the MSCHAP check box
  • B. Change the local user role to read-only
  • C. Disable local authentication
  • D. Change the default role to "guest-provisioning"

Answer: D


NEW QUESTION # 24
From which solution can ClearPass Policy Manager (CPPM) receive detailed information about client device type OS and status?

  • A. ClearPass Onboard
  • B. ClearPass Guest
  • C. ClearPass Access Tracker
  • D. ClearPass OnGuard

Answer: D


NEW QUESTION # 25
Your Aruba Mobility Master-based solution has detected a rogue AP Among other information the ArubaOS Detected Radios page lists this Information for the AP SSID = PubllcWiFI BSSID = a8M27 12 34:56 Match method = Exact match Match type = Eth-GW-wired-Mac-Table The security team asks you to explain why this AP is classified as a rogue. What should you explain?

  • A. The AP has been detected as launching a DoS attack against your company's default gateway. This qualities it as a rogue which needs to be contained with wireless association frames immediately
  • B. The ap has a BSSID mat matches authorized client MAC addresses. This indicates that the AP is spoofing the MAC address to gam unauthorized access to your company's wireless services, so It is a rogue
  • C. The AP is spoofing a routers MAC address as its BSSID. This indicates mat, even though WIP cannot determine whether the AP is connected to your LAN. it is a rogue.
  • D. The AP Is connected to your LAN because It is transmitting wireless traffic with your network's default gateway's MAC address as a source MAC Because it does not belong to the company, it is a rogue

Answer: C


NEW QUESTION # 26
You have been asked to rind logs related to port authentication on an ArubaOS-CX switch for events logged in the past several hours But. you are having trouble searching through the logs What is one approach that you can take to find the relevant logs?

  • A. Add the "-C and *-c port-access" options to the "show logging" command.
  • B. Enable debugging for "portaccess" to move the relevant logs to a buffer.
  • C. Specify a logging facility that selects for "port-access" messages.
  • D. Configure a logging Tiller for the "port-access" category, and apply that filter globally.

Answer: A


NEW QUESTION # 27
Refer to the exhibit.

You are deploying a new ArubaOS Mobility Controller (MC), which is enforcing authentication to Aruba ClearPass Policy Manager (CPPM). The authentication is not working correctly, and you find the error shown In the exhibit in the CPPM Event Viewer.
What should you check?

  • A. that the MC has valid admin credentials configured on it for logging into the CPPM
  • B. that the snared secret configured for the CPPM authentication server matches the one defined for the device on CPPM
  • C. that the IP address that the MC is using to reach CPPM matches the one defined for the device on CPPM
  • D. that the MC has been added as a domain machine on the Active Directory domain with which CPPM is synchronized

Answer: C


NEW QUESTION # 28
You configure an ArubaOS-Switch to enforce 802.1X authentication with ClearPass Policy Manager (CPPM) denned as the RADIUS server Clients cannot authenticate You check Aruba ClearPass Access Tracker and cannot find a record of the authentication attempt.
What are two possible problems that have this symptom? (Select two)

  • A. CPPM does not have a network device defined for the switch's IP address.
  • B. Clients are not configured to trust the root CA certificate for CPPM's RADIUS/EAP certificate.
  • C. Clients are configured to use a mismatched EAP method from the one In the CPPM service.
  • D. users are logging in with the wrong usernames and passwords or invalid certificates.
  • E. The RADIUS shared secret does not match between the switch and CPPM.

Answer: B,D


NEW QUESTION # 29
What is one way that WPA3-PerSonal enhances security when compared to WPA2-Personal?

  • A. WPA3-Personai is more resistant to passphrase cracking Because it requires passphrases to be at least 12 characters
  • B. WPA3-Personal is more complicated to deploy because it requires a backend authentication server
  • C. WPA3-Perscn3i is more secure against password leaking Because all users nave their own username and password
  • D. WPA3-Personai prevents eavesdropping on other users' wireless traffic by a user who knows the passphrase for the WLAN.

Answer: C


NEW QUESTION # 30
Which attack is an example or social engineering?

  • A. A user visits a website and downloads a file that contains a worm, which sell-replicates throughout the network.
  • B. An attack exploits an operating system vulnerability and locks out users until they pay the ransom.
  • C. An email Is used to impersonate a Dank and trick users into entering their bank login information on a fake website page.
  • D. A hacker eavesdrops on insecure communications, such as Remote Desktop Program (RDP). and discovers login credentials.

Answer: C


NEW QUESTION # 31
You are deploying an Aruba Mobility Controller (MC). What is a best practice for setting up secure management access to the ArubaOS Web UP

  • A. Change the default 4343 port tor the web UI to TCP 443.
  • B. Make sure to enable HTTPS for the Web UI and select the self-signed certificate Installed in the factory.
  • C. Install a CA-signed certificate to use for the Web UI server certificate.
  • D. Avoid using external manager authentication tor the Web UI.

Answer: C


NEW QUESTION # 32
You are configuring ArubaOS-CX switches to tunnel client traffic to an Aruba Mobility Controller (MC).
What should you do to enhance security for control channel communications between the switches and the MC?

  • A. install certificates on the switches, and make sure that CPsec is enabled on the MC
  • B. Create one UBT zone for control traffic and a second UBT zone for clients.
  • C. Make sure that the UBT client vlan is assigned to the interface on which the switches reach the MC and only that interface.
  • D. Configure a long, random PAPI security key that matches on the switches and the MC.

Answer: A


NEW QUESTION # 33
A company has an ArubaOS controller-based solution with a WPA3-Enterprise WLAN. which authenticates wireless clients to Aruba ClearPass Policy Manager (CPPM). The company has decided to use digital certificates for authentication A user's Windows domain computer has had certificates installed on it However, the Networks and Connections window shows that authentication has tailed for the user. The Mobility Controllers (MC's) RADIUS events show that it is receiving Access-Rejects for the authentication attempt.
What is one place that you can you look for deeper insight into why this authentication attempt is failing?

  • A. the reports generated by Aruba ClearPass Insight
  • B. the packets captured on the MC control plane destined to UDP 1812
  • C. the RADIUS events within the CPPM Event Viewer
  • D. the Alerts tab in the authentication record in CPPM Access Tracker

Answer: D


NEW QUESTION # 34
What is one way a noneypot can be used to launch a man-in-the-middle (MITM) attack to wireless clients?

  • A. it uses ARP poisoning to disconnect wireless clients from the legitimate wireless network and force clients to connect to the hacker's wireless network instead.
  • B. it runs an NMap scan on the wireless client to And the clients MAC and IP address. The hacker then connects to another network and spoofs those addresses.
  • C. it uses a combination or software and hardware to jam the RF band and prevent the client from connecting to any wireless networks
  • D. it examines wireless clients' probes and broadcasts the SSlDs in the probes, so that wireless clients will connect to it automatically.

Answer: A


NEW QUESTION # 35
What is one of the roles of the network access server (NAS) in the AAA framewonx?

  • A. It negotiates with each user's device to determine which EAP method is used for authentication
  • B. It enforces access to network services and sends accounting information to the AAA server
  • C. It determines which resources authenticated users are allowed to access and monitors each users session
  • D. It authenticates legitimate users and uses policies to determine which resources each user is allowed to access.

Answer: D


NEW QUESTION # 36
Refer to the exhibit, which shows the current network topology.

You are deploying a new wireless solution with an Aruba Mobility Master (MM). Aruba Mobility Controllers (MCs). and campus APs (CAPs). The solution will Include a WLAN that uses Tunnel for the forwarding mode and Implements WPA3-Enterprise security What is a guideline for setting up the vlan for wireless devices connected to the WLAN?

  • A. Assign the WLAN to a named VLAN which specified 100-150 as the range of IDs.
  • B. Assign the WLAN to a single new VLAN which is dedicated to wireless users
  • C. Use wireless user roles to assign the devices to a range of new vlan IDs.
  • D. Use wireless user roles to assign the devices to different VLANs in the 100-150 range

Answer: D


NEW QUESTION # 37
Your ArubaoS solution has detected a rogue AP with Wireless intrusion Prevention (WIP). Which information about the detected radio can best help you to locate the rogue device?

  • A. the match type
  • B. the detecting devices
  • C. the confidence level
  • D. the match method

Answer: D


NEW QUESTION # 38
What are the roles of 802.1X authenticators and authentication servers?

  • A. The authenticator makes access decisions and the server communicates them to the supplicant.
  • B. The authenticator is a RADIUS client and the authentication server is a RADIUS server.
  • C. The authenticator stores the user account database, while the server stores access policies.
  • D. The authenticator supports only EAP, while the authentication server supports only RADIUS.

Answer: A


NEW QUESTION # 39
What is a benefit or Protected Management Frames (PMF). sometimes called Management Frame Protection (MFP)?

  • A. PMF ensures trial traffic between APs and Mobility Controllers (MCs) is encrypted.
  • B. PMF prevents hackers from capturing the traffic between APs and Mobility Controllers.
  • C. PMF helps to protect APs and MCs from unauthorized management access by hackers.
  • D. PMF protects clients from DoS attacks based on forged de-authentication frames

Answer: C


NEW QUESTION # 40
What is symmetric encryption?

  • A. It uses the same key to encrypt plaintext as to decrypt ciphertext.
  • B. It simultaneously creates ciphertext and a same-size MAC.
  • C. It uses a Key that is double the size of the message which it encrypts.
  • D. It any form of encryption mat ensures that thee ciphertext Is the same length as the plaintext.

Answer: A


NEW QUESTION # 41
......


Earning the HPE6-A78 certification demonstrates the candidate's commitment to professional development and enhances their career opportunities. Aruba Certified Network Security Associate Exam certification validates the candidate's skills and knowledge in network security and makes them eligible for various job roles such as network security engineer, security consultant, and security analyst. The HPE6-A78 certification is a valuable asset for IT professionals who want to advance their career in network security.

 

Test Engine to Practice HPE6-A78 Test Questions: https://www.real4prep.com/HPE6-A78-exam.html

HP HPE6-A78 Daily Practice Exam New 2023 Updated 62 Questions: https://drive.google.com/open?id=1z_iJcrYxIqEXxAglSQgJ-tGUIxFR0huX