HP New 2022 HPE6-A77 Test Tutorial (Updated 60 Questions) [Q15-Q33]

Share

HP New 2022 HPE6-A77 Test Tutorial (Updated 60 Questions)

HPE6-A77 Exam Questions Dumps, Selling HP Products


HP HPE6-A77 Exam Syllabus Topics:

TopicDetails
Topic 1
  • ClearPass Admin Login service processing and profile mapping
  • Secure Access Services and Enforcement, Role Mapping
Topic 2
  • Implimenting Guest Access on both wired and wireless infrastructure
  • Understand Service Selection Rules
  • Guest Access Design and Implementation
Topic 3
  • TACACS authentication from Network Access Devices
  • Integration of Authorization Sources and External Context Servers into Enforcement
Topic 4
  • Integration of Posture results in secure service Enforcement
  • Authentication Methods and OCSP to insure proper Certificate revocation
Topic 5
  • Quarantine and remediation based on Posture Token and the status of the agent
  • Implimentation of both Server and Controller Initiated Captive Portal Authentication
Topic 6
  • High Availability and Redundancy Design, including Virtual IP addressing and Standby Publisher
  • Secure Access Design and Implementation
Topic 7
  • Customized Admin Privileges for the Policy Manager
  • Self-Registration both with and without sponsorship

 

NEW QUESTION 15
You have integrated ClearPass Onboard with Active Directory Certificate Services (ADCS) web enrollment to sign the final device TLS certificates. The customer wouldalso like to use ADCS for centralized management of TLS certificates including expiration, revocation, and deletion through ADCS.
What steps will you follow to complete the requirement?

  • A. Edit the [EAP-TLS with OSCP Enabled) authentication method and set the correct ADCS server OCSP URL. remove EAP-TLS and map the [EAP-TLS with OSCP Enabled) method to the Onboard Provisioning Service.
  • B. Copy the default [EAP-TLS with OSCP Enabled] authentication method and update the correct ADCS server OCSP URL. remove EAP-TLS and map the custom created method to the OnBoard Authorization Service.
  • C. Remove the EAP-TLS authentication method and add "EAP-TLS with OCSP Enabled' authentication method in the OnBoard Provisioning service. No other configuration changes are required.
  • D. Copy the [EAP-TLS with OSCP Enabled) authentication method and set the correct ADCS server OCSP URL, remove EAP-TLS and map the custom created method to the Onboard Provisioning Service.

Answer: C

 

NEW QUESTION 16
Which statements are true about Aruba downloadable user roles? (Select three.)

  • A. Aruba downloadable user role are universally available across the environment
  • B. Can use these roles for other authentication methods not involving ClearPass
  • C. Can be applied only on ports or WLAN users authenticated by ClearPass.
  • D. Aruba downloadable user role is a built in enforcementtemplate in ClearPass
  • E. Downloadable role names must be defined in Aruba switch or controller
  • F. Administering downloadable user roles can be difficult for a large enterprise

Answer: B,C,E

 

NEW QUESTION 17
Refer to the exhibit:



The customer created a new enforcement policy condition to allow VIP Users access without additional security compliance checks hut cannot gel it working. The customer has sent you the above screenshots.
How would you resolve the issue?

  • A. Include VIP User role along with the Healthy posture enforcement condition.
  • B. Modify the Enforcement Policy and re-order the VIPuser condition to the lop.
  • C. Set the Enforcement Policy rules evaluation algorithm to evaluate all.
  • D. Ask the VIP user to complete the one time webhealthcheck to get the VIP profile.

Answer: A

 

NEW QUESTION 18
Refer to the exhibit:



You are doing a ClearPass PoC at a customer site with a single Aruba Mobility Controller. The customer asked for a demonstration of a simple Web Login functionality. You used a service template to create the guest services. During testing, the usergets redirected back to the weblogin page with an Authentication failed message. The guest configurations on the Aruba Mobility Controller are configured correctly.
Why would the guest fail to authenticate successfully?

  • A. The Unique-Device-Count does not allow any Client devices.Update the Enforcement policy condition:
    Unique-Device-Count.
  • B. The authentication source mapped in the service is incorrect, it should be mapped as (Guest Device Repository] [Local SQL DB].
  • C. The username and/or password used for authentication is incorrect Re-enter the correct password on the weblogin page.
  • D. The username used for authentication does not exist in the Guest User Database Create a new user and authenticate again.

Answer: B

 

NEW QUESTION 19
A customer is planning to implement machine and user authentication on infrastructure with one Aruba Controller and a single ClearPass Server What should the customer consider while designing this solution?
(Select three.)

  • A. The Windows User must log off, restart or disconnect their machine to initiate a machine authentication before the cache expires.
  • B. The customer does not need to worry about Multi-Master Cache Survivability because the Controller will also cache the machine state.
  • C. Machine Authentication only uses EAP TLS, as such a PKI infrastructure should be in place for machine authentication.
  • D. Onboard must be used to install the Certificates on the personal devices to do the user and machine authentication.
  • E. The machine authentication status is written in the Multi-master cache on the ClearPass Server for 24 hrs.
  • F. The Customer should enable Multi-Master Cache Survivability as the Aruba Controller will not cache the machine state.

Answer: C,D,E

 

NEW QUESTION 20
A customer would like to allow only the AD users with the "Manager" title from the "HQ" location to Onboard their personal devices. Any other AD users should not be authorized to pass beyond the initial device provisioning page. Which Onboard service will you use to implement this requirement?

  • A. Onboard Authorization service
  • B. Onboard Pre-Auth service
  • C. Onboard Provisioning service
  • D. Onboard CP login service

Answer: D

 

NEW QUESTION 21

What are valid options for Network Access Device Settings? (Select two.)

  • A. In CLI settings, you can define the access credentials and the command templates that will be used.
  • B. On the Attributes tab. you can enable the service to write attributes like Location and Device type based on policy.
  • C. The OnConnect Enforcement allows you to enable specific ports that trigger Enforcement when any device connects.
  • D. You can configure SNMP Write Settings to send commands to the devices that do not support other methods.
  • E. You can configure SNMP Read Settings to monitor the load of a NAD in order not to overload it with the requests.

Answer: B,C

 

NEW QUESTION 22
Refer to the exhibit:




After the helpdesk revoked the certificate of a device reported to be lost oy an employee, the lost device was seen as connected successfully to the secure network. Further testing has shown that device revocation is not working.
What steps should you follow to make device revocations work?

  • A. copy the default [EAP-TLS with OSCP Enabled] authentication method and set the verify certificate using OSCP: option as "required" then configure the correct OSCF URL link for the OnBoard CA.
    Remove EAP-TLS and map the new [EAP-TLS with OSCP Enabled] method to the 802 1X Radius Service.
  • B. Edit the default [EAP-TLS with OSCP Enabled] authentication method and set the Verify certificate using OSCP option as required then update the correct OSCP URL link of the OnBoard CA Remove EAP-TLS and map the new [EAP-TLS with OSCP Enabled] method to the OnBoard Provisioning Service.
  • C. Copy the default [EAP-TLS with OSCP Enabled] authentication method and set The Verify certificate using OSCP option as required then update the correct OSCP URL link of the OnBoard CA. Remove EAP-TLS and map the custom created method to the OnBoard Authorization Service.
  • D. Remove the EAP-TLS authentication method configuration changes are required and add "EAP-TLS with OCSP Enabled" authentication method in the OnBoard Provisioning service.
    No other configuration changes are required.

Answer: D

 

NEW QUESTION 23
You have configured a Guest SSID with Captive-portal Web Authentication and MAC authentication The MAC caching expiry time set to 12 hours and the Guest Account expiration time is set to 8 hours. What will happen if the guest were to disconnect from the SSID and re-connect 9 hours later?

  • A. The client will tail the MAC authentication and be denied access to the Guest SSID.
  • B. The client will successfully pass the MAC authentication but still be redirected to captive portal page.
  • C. The client will successfully pass the mac authentication until the mac caching time expires.
  • D. The client will fail the MAC authentication and will be redirected to the Captive-portal login page.

Answer: B

 

NEW QUESTION 24
A customer is complaining that some ofthe devices, in their manufacturing network, are not getting profiled while other loT devices from the same subnet have been correctly profiled. The network switches have been configured for DHCP IP helpers and IF-MAP has been configured on the Aruba Controllers. What can the customer do to discover those devices as well? (Select two.)

  • A. Allow time for IF-MAP service on the controller to discover the new devices as well.
  • B. Update the Fingerprints Dictionary to the latest in case new devices have been added.
  • C. Open a TAC case to help you troubleshoot the DHCP device profile functionality.
  • D. Add the ClearPass Server IP as an IP helper address on the default gateway as well.
  • E. Manually create a new device fingerprint for the devices that are not being profiled.

Answer: A,E

 

NEW QUESTION 25
Refer to the exhibit:



Your customer configured a ClearPass server to process the Guest and Secure SSIDs broadcastingfrom both Aruba and Cisco WLAN controllers When an Employee connects to Aruba or Cisco secure SSID, the authentication hits the guest service causing the client to fail the connection to the network.
What change can be implemented to make both the secure and guest services created for Aruba and Cisco devices to work correctly?

  • A. Move the HS_Building Aruba 802.1x service to the second position in the service order.
  • B. Move the HS-Guest User Authentication with MAC Caching service to the first position.
  • C. Modify the service rule matching algorithm to ALLin HS-GuestUser Authentication service.
  • D. Disable HS-Guest User Authentication service and move HS-Guest MAC Authentication to seventh position.

Answer: B

 

NEW QUESTION 26
You are integrating a Postgres SQL server with the ClearPass Policy Manager What steps will you follow to complete the integration process? (Select three)

  • A. Specify a new filter with filter queries to fetch authentication and authorization attributes.
  • B. Create a new Endpoint context server andadd the SQL server IP, credentilas and the database name.
  • C. Click on the default filter name with pre-defined filter queries and check box to enable as role.
  • D. Alias Name under filter configuration must match one of the columns being requested from the database table.
  • E. Attribute Name under filter configuration must match one of the columns being requested from the database table.
  • F. Create a new authentication source and add the SQL server IP, credentials and the database name.

Answer: A,B,F

 

NEW QUESTION 27
Refer to the exhibit:





You configured the 802 1 x service enforcement conditions with the Endpoint profiling data. When the client connects to the network. ClearPass successfully profiles the client but the client always receives an incorrect enforcement profile The configurations in the Aruba controller are completed correctly.
What is the cause of the issue?

  • A. An additional authorization source should be configured for profiling to work.
  • B. The enforcement policy rules evaluation algorithm Is not configured correctly.
  • C. The enforcement policy conditions configured with profiling data are not correct.
  • D. The option, use cached roles and posture from previous sessions should be enabled.

Answer: C

 

NEW QUESTION 28
Refer to the Exhibit:


A customer wants to integrate posture validationinto an Aruba Wireless 802.1X authentication service During testing, the client connects to the Aruba Employee Secure SSID and is redirected to the Captive Portal page where the user can download the OnGuard Agent After the Agent is installed, the client receives the Healthy token the client remains connected to the Captive Portal page ClearPass is assigning the endpoint the following roles: T2-Staff-User. (Machine Authenticated! and T2-SOL-Device.
What could cause this behavior?

  • A. The Enforcement Policy conditions for rule 1 are not configured correctly.
  • B. RFC-3576 Is not configured correctly on the Aruba Controller and does not update the role.
  • C. The Enforcement Profile should bounce the connection instead of a Terminate session
  • D. Used Cached Results: has not been enabled In the Aruba 802.1X Wireless Service

Answer: D

 

NEW QUESTION 29
Refer to the exhibit:

The customer complains that the user shown cannot log into the ClearPass Server as an administrator using the
[Policy Manager Admin Network Login Service]. What could be the reason for this?

  • A. The local user authentication might be disabled
  • B. The account created does not fit this purpose.
  • C. The mapping on the role should be changed to [RADIUS Super Admin]
  • D. The user might be used for a TACACS authentication

Answer: B

 

NEW QUESTION 30
Refer to the exhibit:

A customer is deploying Guest Self-Registration with Sponsor Approval but does not like the format of the sponsor email. Where can you change the sponsor email?

  • A. in the Receipt Page - Actions
  • B. in the Sponsor Confirmation section
  • C. in the Configuration - Receipts - Templates
  • D. in me Configuration - Receipts - Email Receipts

Answer: B

 

NEW QUESTION 31
Refer to the exhibit:





You have configured Onboard andcannot get it working The customer has sentyouthe above screenshots How would you resolve the issue?

  • A. Copy the [EAP-TLS with OSCP Enabled] authentication method and set the correct OCSP URL
  • B. Install a public signed server authentication certificate on the ClearPass server for EAP
  • C. Re-provision the client by running the QuickConnect application as Administrator
  • D. Reconnect the client and select the correct certificate when prompted

Answer: C

 

NEW QUESTION 32
How does the RadSec improve the RADIUS message exchange? (Select two.)

  • A. It uses UDP to exchange the radius packets.
  • B. It builds a TTLS tunnel between the NAD and ClearPass.
  • C. It encrypts the entire RADIUS message.
  • D. Only the NAD needs to trust the ClearPass Certificate.
  • E. It can be used on an unsecured network or the Internet.

Answer: A,C

 

NEW QUESTION 33
......

HPE6-A77 Cert Guide PDF 100% Cover Real Exam Questions: https://www.dumpsquestion.com/HPE6-A77-exam-dumps-collection.html