Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dumps65

HP HPE7-A07 Dumps

Page: 1 / 7
Total 70 questions

Aruba Certified Campus Access Mobility Expert Written Exam Questions and Answers

Question 1

A client connecting to a tunneled open network is receiving the wrong VLAN Your customer has a gateway and has sent over a packet capture from a switch port mirror taken from the upstream switch with a packet capture from the IPsec tunnel and the GRE tunnel to help Identify the VLAN being sent from the controller to the AP.

Where will you see the VLAN assignment?

Options:

A.

The GRE tunnel will include the VLAN lag assignment

B.

VLAN tag assignment win not he captured in any of the packet captures

C.

IPsec tunnel will include the VLAN tag assignment

D.

VLAN tag assignment win be included in the port mirror

Question 2

Exhibit.

as

Which statement is true?

Options:

A.

The SSID supports RC4 encryption.

B.

The SSID supports 802.11nac clients.

C.

The SSID supports implicit beamforming.

D.

The SSID supports sending neighbor reports.

Question 3

An administrator is creating a fabric withNetConductor in HPE Aruba Networking Central Considering an EVPN VXLAN fabric, click on the most appropriate layer to be configured as a Rome-Reflector Persona.

as

Options:

Question 4

You configured" a bridgedmode SSID with WPA3-Enterprise and EAP-TLS security. When you connect an Active Directory joined client that has valid client certificates. ClearPass shows the following error.

as

What is needed to resolve this issue?

Options:

A.

Enable authorization in your Authentication Method.

B.

Recreate the SSID m tunneled mode.

C.

Modify your ACX-AD authentication source to include the UPN in the search.

D.

Configure ClearPass to trust the client certificate.

Question 5

Exhibit.

as

Which would explain this issue?

Options:

A.

HTTPS wildcard certificates are not supported

B.

HTTPS certificate is not required in ClearPass Guest.

C.

captiveportal-login aruba-training com needs to be entered m the Address field for the ClearPass Guest

D.

".aruba-training com needs to be entered in the Address field for the ClearPass Guest

Question 6

You created a new SSID with the security settings shown in the exhibit.

as

Some, but not all users complain that client devices are unable to connect to this SS1D. What is the reason for this?

Options:

A.

The WPA3 Enterprise GCM-2S6 mode does not support transition mode.

B.

WPA3 Enterprise is not backward compatible with WPA2 Enterprise.

C.

MAC authentication after a failed 802. ix authentication is not possible as the option "MAC Authentication Fall-Through" is disabled.

D.

The primary servers shared key differs from the shared key configured for this server on HPE Aruba Networking Central.

Question 7

A customer would like to allow their IT Helpdesk to configure loT devices to connect lo a single SSID using a unique PSK that other devices cannot use. Which solution would you recommend?

Options:

A.

MPSK AES with MAC Auth

B.

MPSK Local

C.

MPSK AES with Cloud Auth

D.

MPSK AES with ClearPass

Question 8

A BGP routing tablecontains multiple routes to the same destination prefix.

Referring to the table below whichroutewould be marked with a ">" symbol?

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

E.

Option E

Question 9

You deployed UBT tosecurely tunnel traffic from user desktop PCs connected behind VOIP phones Ail other non-UBT dents are connected to a different network. After the deployment users reported interruptions lo their phone service

Options:

A.

The VLAN on which UBT clients are placed is not configured on the switch uplink and traffic from the VoIP phones is being dropped

B.

You tailed to correctly configure a user-defined VRF to support the UBT clients behind the VoIP phones, causing traffic to drop.

C.

Broadcast/multicast packets are copied to both the tunnel and locally, causing duplicate packets and network instability

D.

The UBT client broadcast/multicast packets returned to the same switch port and corrupted the phones IMC table

Question 10

Your customer added third-party USB dongles to the USB ports of their AOS 10 access points. The customer uses AP-615 and AP-635 Each AP is connected with a Cat 6A cable to a CX 6300F Class 4 PoE switch All APs are in the same group in HPE Aruba Networking Central and share the same configuration However, many of the dongles do not come up.

Which option will solve this issue?

Options:

A.

Replace the Class a PoE switches with Class 6 PoE switches.

B.

Create two separate service profiles in the loT tab of the Central configuration settings.

C.

Perform a "poe disable" followed by a "poe enable" for the switch ports which connect to the APs so that the APs reboot.

D.

Move the AP-635 access points to a different group in Central to configure the dongles separately from the AP-615.

Question 11

A customer’s infrastructure is set up to use both primary and secondary gateway clusters on the SSID profile cased on best practices. Why do they have an equal split of their 120 APs across the primary and secondary gateway clusters?

Options:

A.

The primary gateway cluster is a heterogeneous cluster with six nodes.

B.

The primary and secondary gateway clusters are up. and the cluster preemption is enabled

C.

The secondary gateway cluster is a homogeneous cluster with six nodes.

D.

The primary and secondary gateway clusters are up. but the cluster preemption Is not enabled

Question 12

Match each Group Based Policy(GBP) rote description to its respective role ID.

as

Options:

Question 13

After onboarding three new AOS 10 gateways using the full-setup methodinto the same Central group, a customer cannot log in to one of the gateways using the HPE Aruba Networking Central remote console due to an incorrect password.

Options:

A.

The admin password created using full-setup does not match the global Central admin password.

B.

The admin password created during the run-setup process is not configured to allow me remote console access

C.

The admin password created during the full-setup process does not match the Central group admin password

D.

The admin password created at the Central group level has expired

Question 14

An AOS 10 multi-site deployment has sites with AP-only bridged SSlDs and other sites with APs and gateways operating tunneled SSiDs. Client session state sync errors exist between secure lab environments and public -facing areas at several sites.

What is causing the issues?

Options:

A.

The DTLS connections are down between APs in the lab and APs in public areas

B.

The affected clients are associated with an SSID with 11r and 11k disabled.

C.

The sites with issues are the overlay AP with gateway sites because the connection to HPE Aruba Networking central is interrupted

D.

The sites with issues are the AP-only deployments because the connection to HPE Aruba Networking Central is interrupted

Question 15

Exhibit.

as

You updated your gateway to me most recent firmware However after the firmware was updated, the gateway could no longer connect to HPE Aruba Networking Central. Your corporate ITIL procedures require you to implement your backout plan. You connected a console cable to your gateway and saw the following prompt.

Cpxload#

in what order, do you need to execute the following commands to return to the previous firmware version?

as

Options:

Question 16

Your customer is requesting a4-ciass LAN queuing model tor QoS. Following best practices, match the PHB/DSCP values to the application types.

as

Options:

Question 17

A customer has recently deployed a wireless system using AP-535S to provide connectivity for their employees who are responsible tor uploading large video files for review. The customer wants to use features that provide throughput gains for large data uploads.

Which feature can be enabled to meet the requirement and simultaneously allow spatially separated clients access to the channel?

Options:

A.

Ul-TXBF

B.

OFOMA

C.

DL MU-MIMO

D.

UL MU-MIMO

Question 18

You recently added ClearPass as an authentication server to an HPE Aruba Networking Central group. RADIUS authentication with Local User Roles (LUR) works fine Out the same access points cannot use Downloadable User Roles (DUR).

What should he corrected in this configuration to fa the issue with DUR?

Options:

A.

Add a new Enforcement Policy of type ‘’WEBAUTH’’on ClearPass and associate it with the matching service on ClearPass

B.

Add the correct IP addresses or IP subnets of the Network Access Devices(NADs) under the "Devices" tabon ClearPass

C.

Replace the AP's expiree digital certificate using the "crypto pki-import pem serverCert" command.

D.

Add the correct values for "CPPM username" and "CPPM Password" m the authentication server configuration on HPEAruba Networking Central

Question 19

Exhibit.

as

Which statement is true given the following CLI output from a CX 6300?

Options:

A.

There are no active fabric clients on the CX switch with RD 172.16.10.1

B.

A wired client with IP address 10.203 1.100 is on a remote CX 6300 in the fabric with loopback IP address 172.21.11.2.

C.

A wired client with IP address 10 203 1 100 has a host route that is not being properly advertised

D.

The overlay loopbacK addresses are advertised in the faerie with 2d-bit subnet masks

Question 20

You are troubleshooting a WLAN deployment with APs and gateways set up with an 802.1X tunneled SSIO. End-users are complaining that they can’t connect to die enterprise SSID. Which possible AP tunnel states could be the cause of the Issue? (Select two.)

Options:

A.

SM_STATE_RE KEYING

B.

SM_STATE_SURVIVED

C.

SM_STATE_CONNECTED

D.

SM_STATE_SURVIVING

E.

SM_STATE_CONNECTING

Question 21

You are testing the use of the automated port-access role configuration process using RadSec authentication over VXLAN. During your testing you observed that the RadSec connection will fan during the digital certificate exchange

What would be the cause of this Issue?

Options:

A.

The RadSec server was defined on the switch using an IPv6 address that was unreachable

B.

Tracking mode was set to "dead-only", and the RadSec server was marked as unreachable.

C.

The switch is configured to establish a TLS connection with a proxy server, not the radius server.

D.

The RADIUS TCP packets are Being dropped and the TLS tunnel is not established.

Page: 1 / 7
Total 70 questions