Weekend Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: netbudy65

HPE6-A84 Aruba Certified Network Security Expert Written Exam Questions and Answers

Questions 4

Refer to the scenario.

A customer has an AOS10 architecture that is managed by Aruba Central. Aruba infrastructure devices authenticate clients to an Aruba ClearPass cluster.

In Aruba Central, you are examining network traffic flows on a wireless IoT device that is categorized as “Raspberry Pi” clients. You see SSH traffic. You then check several more wireless IoT clients and see that they are sending SSH also.

You want an easy way to communicate the information that an IoT client has used SSH to Aruba ClearPass Policy Manager (CPPM).

What step should you take?

Options:

A.

On CPPM create an Endpoint Context Server that points to the Central API.

B.

On CPPM enable Device Insight integration.

C.

On Central configure APs and gateways to use CPPM as the RADIUS accounting server.

D.

On Central set up CPPM as a Webhook application.

Buy Now
Questions 5

Refer to the scenario.

A customer has an Aruba ClearPass cluster. The customer has AOS-CX switches that implement 802.1X authentication to ClearPass Policy Manager (CPPM).

Switches are using local port-access policies.

The customer wants to start tunneling wired clients that pass user authentication only to an Aruba gateway cluster. The gateway cluster should assign these clients to the “eth-internet" role. The gateway should also handle assigning clients to their VLAN, which is VLAN 20.

The plan for the enforcement policy and profiles is shown below:

HPE6-A84 Question 5

The gateway cluster has two gateways with these IP addresses:

• Gateway 1

o VLAN 4085 (system IP) = 10.20.4.21

o VLAN 20 (users) = 10.20.20.1

o VLAN 4094 (WAN) = 198.51.100.14

• Gateway 2

o VLAN 4085 (system IP) = 10.20.4.22

o VLAN 20 (users) = 10.20.20.2

o VLAN 4094 (WAN) = 198.51.100.12

• VRRP on VLAN 20 = 10.20.20.254

The customer requires high availability for the tunnels between the switches and the gateway cluster. If one gateway falls, the other gateway should take over its tunnels. Also, the switch should be able to discover the gateway cluster regardless of whether one of the gateways is in the cluster.

Assume that you have configured the correct UBT zone and port-access role settings. However, the solution is not working.

What else should you make sure to do?

Options:

A.

Assign VLAN 20 as the access VLAN on any edge ports to which tunneled clients might connect.

B.

Create a new VLAN on the AOS-CX switch and configure that VLAN as the UBT client VLAN.

C.

Assign sufficient VIA licenses to the gateways based on the number of wired clients that will connect.

D.

Change the port-access auth-mode mode to client-mode on any edge ports to which tunneled clients might connect.

Buy Now
Questions 6

A customer needs you to configure Aruba ClearPass Policy Manager (CPPM) to authenticate domain users on domain computers. Domain users, domain computers, and domain controllers receive certificates from a Windows CA. CPPM should validate these certificates and verify that the users and computers have accounts in Windows AD. The customer requires encryption for all communications between CPPM and the domain controllers.

You have imported the root certificate for the Windows CA to the ClearPass CA Trust list.

Which usages should you add to it based on these requirements?

Options:

A.

Radec and Aruba infrastructure

B.

EAP and AD/LDAP Server

C.

EAP and Radsec

D.

LDAP and Aruba infrastructure

Buy Now
Questions 7

Refer to the scenario.

A customer requires these rights for clients in the “medical-mobile” AOS firewall role on Aruba Mobility Controllers (MCs):

HPE6-A84 Question 7Permitted to receive IP addresses with DHCP

HPE6-A84 Question 7Permitted access to DNS services from 10.8.9.7 and no other server

HPE6-A84 Question 7Permitted access to all subnets in the 10.1.0.0/16 range except denied access to 10.1.12.0/22

HPE6-A84 Question 7Denied access to other 10.0.0.0/8 subnets

HPE6-A84 Question 7Permitted access to the Internet

HPE6-A84 Question 7Denied access to the WLAN for a period of time if they send any SSH traffic

HPE6-A84 Question 7Denied access to the WLAN for a period of time if they send any Telnet traffic

HPE6-A84 Question 7Denied access to all high-risk websites

External devices should not be permitted to initiate sessions with “medical-mobile” clients, only send return traffic.

The line below shows the effective configuration for the role.

HPE6-A84 Question 7

There are multiple issues with this configuration. What is one change you must make to meet the scenario requirements? (In the options, rules in a policy are referenced from top to bottom. For example, “medical-mobile” rule 1 is “ipv4 any any svc-dhcp permit,” and rule 6 is “ipv4 any any any permit’.)

Options:

A.

Apply the "apprf-medical-mobile-sjcT policy explicitly to the 'medical-mobile' user-role under the 'medical-mobile" policy.

B.

In the "medical-mobile" policy, change the action for rules 2 and 3 to reject.

C.

In the "medical-mobile" policy, move rule 5 under rule 6.

D.

In the "medical-mobile* policy, change the subnet mask in rule 5 to 255.255.252.0.

Buy Now
Questions 8

Refer to the scenario.

# Introduction to the customer

You are helping a company add Aruba ClearPass to their network, which uses Aruba network infrastructure devices.

The company currently has a Windows domain and Windows CA. The Window CA issues certificates to domain computers, domain users, and servers such as domain controllers. An example of a certificate issued by the Windows CA is shown here.

HPE6-A84 Question 8

HPE6-A84 Question 8

The company is in the process of adding Microsoft Endpoint Manager (Intune) to manage its mobile clients. The customer is maintaining the on-prem AD for now and uses Azure AD Connect to sync with Azure AD.

# Requirements for issuing certificates to mobile clients

The company wants to use ClearPass Onboard to deploy certificates automatically to mobile clients enrolled in Intune. During this process, Onboard should communicate with Azure AD to validate the clients. High availability should also be provided for this scenario; in other words, clients should be able to get certificates from Subscriber 2 if Subscriber 1 is down.

The Intune admins intend to create certificate profiles that include a UPN SAN with the UPN of the user who enrolled the device.

# Requirements for authenticating clients

The customer requires all types of clients to connect and authenticate on the same corporate SSID.

The company wants CPPM to use these authentication methods:

HPE6-A84 Question 8EAP-TLS to authenticate users on mobile clients registered in Intune

HPE6-A84 Question 8TEAR, with EAP-TLS as the inner method to authenticate Windows domain computers and the users on them

To succeed, EAP-TLS (standalone or as a TEAP method) clients must meet these requirements:

HPE6-A84 Question 8Their certificate is valid and is not revoked, as validated by OCSP

HPE6-A84 Question 8The client’s username matches an account in AD

# Requirements for assigning clients to roles

After authentication, the customer wants the CPPM to assign clients to ClearPass roles based on the following rules:

HPE6-A84 Question 8Clients with certificates issued by Onboard are assigned the “mobile-onboarded” role

HPE6-A84 Question 8Clients that have passed TEAP Method 1 are assigned the “domain-computer” role

HPE6-A84 Question 8Clients in the AD group “Medical” are assigned the “medical-staff” role

HPE6-A84 Question 8Clients in the AD group “Reception” are assigned to the “reception-staff” role

The customer requires CPPM to assign authenticated clients to AOS firewall roles as follows:

HPE6-A84 Question 8Assign medical staff on mobile-onboarded clients to the “medical-mobile” firewall role

HPE6-A84 Question 8Assign other mobile-onboarded clients to the “mobile-other” firewall role

HPE6-A84 Question 8Assign medical staff on domain computers to the “medical-domain” firewall role

HPE6-A84 Question 8All reception staff on domain computers to the “reception-domain” firewall role

HPE6-A84 Question 8All domain computers with no valid user logged in to the “computer-only” firewall role

HPE6-A84 Question 8Deny other clients access

# Other requirements

Communications between ClearPass servers and on-prem AD domain controllers must be encrypted.

# Network topology

For the network infrastructure, this customer has Aruba APs and Aruba gateways, which are managed by Central. APs use tunneled WLANs, which tunnel traffic to the gateway cluster. The customer also has AOS-CX switches that are not managed by Central at this point.

HPE6-A84 Question 8

# ClearPass cluster IP addressing and hostnames

A customer’s ClearPass cluster has these IP addresses:

HPE6-A84 Question 8Publisher = 10.47.47.5

HPE6-A84 Question 8Subscriber 1 = 10.47.47.6

HPE6-A84 Question 8Subscriber 2 = 10.47.47.7

HPE6-A84 Question 8Virtual IP with Subscriber 1 and Subscriber 2 = 10.47.47.8

The customer’s DNS server has these entries

HPE6-A84 Question 8cp.acnsxtest.com = 10.47.47.5

HPE6-A84 Question 8cps1.acnsxtest.com = 10.47.47.6

HPE6-A84 Question 8cps2.acnsxtest.com = 10.47.47.7

HPE6-A84 Question 8radius.acnsxtest.com = 10.47.47.8

HPE6-A84 Question 8onboard.acnsxtest.com = 10.47.47.8

The customer needs a secure way for users to enroll their new wireless clients in Intune. You are recommending a new WLAN that will provide the users with limited access for the enrollment.

You have set up captive portal for clients on this WLAN to a web page with instructions for enrolling devices. You will need to add several hostnames to the captive portal allowlist manually.

What is one of those hostnames?

Options:

A.

The hostname used by ClearPass Policy ManaGer's RADIUS services

B.

The ClearPass Onboard hostname referenced in an Onboard provisioninG profile

C.

The ClearPass Onboard hostname referenced in Intune SCEP profiles

D.

The hostname used by the on-prem domain controllers

Buy Now
Questions 9

Refer to the scenario.

An organization wants the AOS-CX switch to trigger an alert if its RADIUS server (cp.acnsxtest.local) rejects an unusual number of client authentication requests per hour. After some discussions with other Aruba admins, you are still not sure how many rejections are usual or unusual. You expect that the value could be different on each switch.

You are helping the developer understand how to develop an NAE script for this use case.

The developer explains that they plan to define the rule with logic like this:

monitor > value

However, the developer asks you what value to include.

What should you recommend?

Options:

A.

Checking one of the access switches' RADIUS statistics and adding 10 to the number listed for rejects

B.

Defining a baseline and referring to it for the value

C.

Using 10 (per hour) as a good starting point for the value

D.

Defining a parameter and referring to it (self ^ramsfname]) for the value

Buy Now
Questions 10

Refer to the scenario.

A customer has asked you to review their AOS-CX switches for potential vulnerabilities. The configuration for these switches is shown below:

HPE6-A84 Question 10

What is one recommendation to make?

Options:

A.

Let the RADIUS server confiqure VLANs on LAG 1 dynamically.

B.

Use MDS instead of SHA1 for the NTP authentication key.

C.

Encrypt the certificate in the TA-profile.

D.

Create a control plane ACL to limit the sources that can access the switch with SSH.

Buy Now
Questions 11

Refer to the scenario.

A hospital has an AOS10 architecture that is managed by Aruba Central. The customer has deployed a pair of Aruba 9000 Series gateways with Security licenses at each clinic. The gateways implement IDS/IPS in IDS mode.

The Security Dashboard shows these several recent events with the same signature, as shown below:

HPE6-A84 Question 11

Which step could give you valuable context about the incident?

Options:

A.

View firewall sessions on the APs and record the threat sources' type and OS.

B.

View the user-table on APs and record the threat sources' 802.11 settings.

C.

View the RAPIDS Security Dashboard and see if the threat sources are listed as rogues.

D.

Find the Central client profile for the threat sources and note their category and family.

Buy Now
Questions 12

Refer to the scenario.

A customer requires these rights for clients in the “medical-mobile” AOS firewall role on Aruba Mobility Controllers (MCs):

HPE6-A84 Question 12Permitted to receive IP addresses with DHCP

HPE6-A84 Question 12Permitted access to DNS services from 10.8.9.7 and no other server

HPE6-A84 Question 12Permitted access to all subnets in the 10.1.0.0/16 range except denied access to 10.1.12.0/22

HPE6-A84 Question 12Denied access to other 10.0.0.0/8 subnets

HPE6-A84 Question 12Permitted access to the Internet

HPE6-A84 Question 12Denied access to the WLAN for a period of time if they send any SSH traffic

HPE6-A84 Question 12Denied access to the WLAN for a period of time if they send any Telnet traffic

HPE6-A84 Question 12Denied access to all high-risk websites

External devices should not be permitted to initiate sessions with “medical-mobile” clients, only send return traffic.

The exhibits below show the configuration for the role.

HPE6-A84 Question 12

What setting not shown in the exhibit must you check to ensure that the requirements of the scenario are met?

Options:

A.

That denylisting is enabled globally on the MCs’ firewalls

B.

That stateful handling of traffic is enabled globally on the MCs’ firewalls and on the medical-mobile role.

C.

That AppRF and WebCC are enabled globally and on the medical-mobile role

D.

That the MCs are assigned RF Protect licenses

Buy Now
Questions 13

Refer to the scenario.

A customer requires these rights for clients in the “medical-mobile” AOS firewall role on Aruba Mobility Controllers (MCs):

HPE6-A84 Question 13Permitted to receive IP addresses with DHCP

HPE6-A84 Question 13Permitted access to DNS services from 10.8.9.7 and no other server

HPE6-A84 Question 13Permitted access to all subnets in the 10.1.0.0/16 range except denied access to 10.1.12.0/22

HPE6-A84 Question 13Denied access to other 10.0.0.0/8 subnets

HPE6-A84 Question 13Permitted access to the Internet

HPE6-A84 Question 13Denied access to the WLAN for a period of time if they send any SSH traffic

HPE6-A84 Question 13Denied access to the WLAN for a period of time if they send any Telnet traffic

HPE6-A84 Question 13Denied access to all high-risk websites

External devices should not be permitted to initiate sessions with “medical-mobile” clients, only send return traffic.

The exhibits below show the configuration for the role.

HPE6-A84 Question 13

There are multiple issues with the configuration.

What is one of the changes that you must make to the policies to meet the scenario requirements? (In the options, rules in a policy are referenced from top to bottom. For example, “medical-mobile” rule 1 is “ipv4 any any svc-dhcp permit,” and rule 8 is “ipv4 any any any permit’.)

Options:

A.

In the “medical-mobile” policy, change the source in rule 1 to “user.”

B.

In the “medical-mobile” policy, change the subnet mask in rule 3 to 255.255.248.0.

C.

In the “medical-mobile” policy, move rules 6 and 7 to the top of the list.

D.

Move the rule in the “apprf-medical-mobile-sacl” policy between rules 7 and 8 in the “medical-mobile” policy.

Buy Now
Questions 14

Refer to the scenario.

A customer has an Aruba ClearPass cluster. The customer has AOS-CX switches that implement 802.1X authentication to ClearPass Policy Manager (CPPM).

Switches are using local port-access policies.

The customer wants to start tunneling wired clients that pass user authentication only to an Aruba gateway cluster. The gateway cluster should assign these clients to the “eth-internet" role. The gateway should also handle assigning clients to their VLAN, which is VLAN 20.

The plan for the enforcement policy and profiles is shown below:

HPE6-A84 Question 14

The gateway cluster has two gateways with these IP addresses:

• Gateway 1

o VLAN 4085 (system IP) = 10.20.4.21

o VLAN 20 (users) = 10.20.20.1

o VLAN 4094 (WAN) = 198.51.100.14

• Gateway 2

o VLAN 4085 (system IP) = 10.20.4.22

o VLAN 20 (users) = 10.20.20.2

o VLAN 4094 (WAN) = 198.51.100.12

• VRRP on VLAN 20 = 10.20.20.254

The customer requires high availability for the tunnels between the switches and the gateway cluster. If one gateway falls, the other gateway should take over its tunnels. Also, the switch should be able to discover the gateway cluster regardless of whether one of the gateways is in the cluster.

Assume that you are using the “myzone” name for the UBT zone.

Which is a valid minimal configuration for the AOS-CX port-access roles?

Options:

A.

port-access role eth-internet gateway-zone zone myzone gateway-role eth-user

B.

port-access role internet-only gateway-zone zone myzone gateway-role eth-internet

C.

port-access role eth-internet gateway-zone zone myzone gateway-role eth-internet vlan access 20

D.

port-access role internet-only gateway-zone zone myzone gateway-role eth-internet vlan access 20

Buy Now
Questions 15

Refer to the exhibit.

HPE6-A84 Question 15

Aruba ClearPass Policy Manager (CPPM) is using the settings shown in the exhibit. You reference the tag shown in the exhibit in enforcement policies related to NASes of several types, including Aruba APs, Aruba gateways, and AOS-CX switches.

What should you do to ensure that clients are reclassified and receive the correct treatment based on the tag?

Options:

A.

Change the RADIUS action to [Aruba Wireless -Terminate Session] which is supported by all the NASes in question.

B.

Change the RADIUS action to [Aruba Wireless - Bounce Switch Port] which is supported by all the NASes in question.

C.

Enable profiling in each service using one of these enforcement profiles. Set the profiling action to the correct one for the NASes using that service.

D.

Set the Tags Update Action to No Action. Then instead enable the RADIUS CoAs using enforcement profiles in the rules that match clients with the tag shown in the exhibit.

Buy Now
Questions 16

Refer to the scenario.

# Introduction to the customer

You are helping a company add Aruba ClearPass to their network, which uses Aruba network infrastructure devices.

The company currently has a Windows domain and Windows CA. The Window CA issues certificates to domain computers, domain users, and servers such as domain controllers. An example of a certificate issued by the Windows CA is shown here.

HPE6-A84 Question 16

HPE6-A84 Question 16

The company is in the process of adding Microsoft Endpoint Manager (Intune) to manage its mobile clients. The customer is maintaining the on-prem AD for now and uses Azure AD Connect to sync with Azure AD.

# Requirements for issuing certificates to mobile clients

The company wants to use ClearPass Onboard to deploy certificates automatically to mobile clients enrolled in Intune. During this process, Onboard should communicate with Azure AD to validate the clients. High availability should also be provided for this scenario; in other words, clients should be able to get certificates from Subscriber 2 if Subscriber 1 is down.

The Intune admins intend to create certificate profiles that include a UPN SAN with the UPN of the user who enrolled the device.

# Requirements for authenticating clients

The customer requires all types of clients to connect and authenticate on the same corporate SSID.

The company wants CPPM to use these authentication methods:

HPE6-A84 Question 16EAP-TLS to authenticate users on mobile clients registered in Intune

HPE6-A84 Question 16TEAR, with EAP-TLS as the inner method to authenticate Windows domain computers and the users on them

To succeed, EAP-TLS (standalone or as a TEAP method) clients must meet these requirements:

HPE6-A84 Question 16Their certificate is valid and is not revoked, as validated by OCSP

HPE6-A84 Question 16The client’s username matches an account in AD

# Requirements for assigning clients to roles

After authentication, the customer wants the CPPM to assign clients to ClearPass roles based on the following rules:

HPE6-A84 Question 16Clients with certificates issued by Onboard are assigned the “mobile-onboarded” role

HPE6-A84 Question 16Clients that have passed TEAP Method 1 are assigned the “domain-computer” role

HPE6-A84 Question 16Clients in the AD group “Medical” are assigned the “medical-staff” role

HPE6-A84 Question 16Clients in the AD group “Reception” are assigned to the “reception-staff” role

The customer requires CPPM to assign authenticated clients to AOS firewall roles as follows:

HPE6-A84 Question 16Assign medical staff on mobile-onboarded clients to the “medical-mobile” firewall role

HPE6-A84 Question 16Assign other mobile-onboarded clients to the “mobile-other” firewall role

HPE6-A84 Question 16Assign medical staff on domain computers to the “medical-domain” firewall role

HPE6-A84 Question 16All reception staff on domain computers to the “reception-domain” firewall role

HPE6-A84 Question 16All domain computers with no valid user logged in to the “computer-only” firewall role

HPE6-A84 Question 16Deny other clients access

# Other requirements

Communications between ClearPass servers and on-prem AD domain controllers must be encrypted.

# Network topology

For the network infrastructure, this customer has Aruba APs and Aruba gateways, which are managed by Central. APs use tunneled WLANs, which tunnel traffic to the gateway cluster. The customer also has AOS-CX switches that are not managed by Central at this point.

HPE6-A84 Question 16

# ClearPass cluster IP addressing and hostnames

A customer’s ClearPass cluster has these IP addresses:

HPE6-A84 Question 16Publisher = 10.47.47.5

HPE6-A84 Question 16Subscriber 1 = 10.47.47.6

HPE6-A84 Question 16Subscriber 2 = 10.47.47.7

HPE6-A84 Question 16Virtual IP with Subscriber 1 and Subscriber 2 = 10.47.47.8

The customer’s DNS server has these entries

HPE6-A84 Question 16cp.acnsxtest.com = 10.47.47.5

HPE6-A84 Question 16cps1.acnsxtest.com = 10.47.47.6

HPE6-A84 Question 16cps2.acnsxtest.com = 10.47.47.7

HPE6-A84 Question 16radius.acnsxtest.com = 10.47.47.8

HPE6-A84 Question 16onboard.acnsxtest.com = 10.47.47.8

You have started to create a CA to meet the customer’s requirements for issuing certificates to mobile clients, as shown in the exhibit below.

HPE6-A84 Question 16

What change will help to meet those requirements and the requirements for authenticating clients?

Options:

A.

Change the EST authentication method to use an external validator.

B.

Change the EST Digest Algorithm to SHA-512.

C.

Recreate the CA as a registration authority under Azure AD.

D.

Specify an OCSP responder, setting the hostname to localhost.

Buy Now
Questions 17

Several AOS-CX switches are responding to SNMPv2 GET requests for the public community. The customer only permits SNMPv3. You have asked a network admin to fix this problem. The admin says, “I tried to remove the community, but the CLI output an error.”

What should you recommend to remediate the vulnerability and meet the customer’s requirements?

Options:

A.

Enabling control plane policing to automatically drop SNMP GET requests

B.

Setting the snmp-server settings to “snmpv3-only”

C.

Adding an SNMP community with a long random name

D.

Enabling SNMPv3, which implicitly disables SNMPv1/v2

Buy Now
Questions 18

Refer to the scenario.

An organization wants the AOS-CX switch to trigger an alert if its RADIUS server (cp.acnsxtest.local) rejects an unusual number of client authentication requests per hour. After some discussions with other Aruba admins, you are still not sure how many rejections are usual or unusual. You expect that the value could be different on each switch.

You are helping the developer understand how to develop an NAE script for this use case.

You are helping the developer find the right URI for the monitor.

Refer to the exhibit.

HPE6-A84 Question 18

You have used the REST API reference interface to submit a test call. The results are shown in the exhibit.

Which URI should you give to the developer?

Options:

A.

/rest/v1/system/vrfs/mgmt/radius/servers/cp.acnsxtest.local/2083/tcp?attributes=authstatistics

B.

/rest/v1/system/vrfs/mgmt/radius/servers/cp.acnsxtest.local/2083/tcp?attributes=authstatistics?attributes=access_rejects

C.

/rest/v1/system/vrfs/mgmt/radius/_servers/cp.acnsxtest.local/2083/tcp

D.

/rest/v1/system/vrfs/mgmt/radius/servers/cp.acnsxtest.local/2083/tcp?attributes=authstatistics.access_rejects

Buy Now
Exam Code: HPE6-A84
Exam Name: Aruba Certified Network Security Expert Written Exam
Last Update: Oct 15, 2025
Questions: 60

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99