Skip to content

HPE6-A78 HPE Aruba Networking Certified Associate - Network Security Practice Questions

Prepare for HPE6-A78 with more than an answer.

156 questions in the full set12 sample questionsUpdated Mar 12, 2026
Exam fee
$260 USD
Level
Associate
Valid for
3 years
Domains covered on the exam 3
  1. Protect and Defend70%
  2. Analyze24%
  3. Investigate6%
  1. 1

    Case Study: University Network Upgrade

    A large university is upgrading its network security. They have separate user groups: Students, Faculty, and IoT devices.

    Current Situation:

    • Students use personal devices (BYOD).
    • Faculty use university-issued laptops.
    • IoT devices (temperature sensors, door locks) support WPA2-PSK only.
    • A dedicated guest network is needed for visitors.

    Requirements:

    • Faculty must be authenticated using their Active Directory credentials and machine certificates.
    • Students should authenticate with credentials but do not have certificates.
    • IoT devices must be isolated from student/faculty data.
    • Visitors should register via a web portal.

    Question:
    Which wireless security standard and authentication method is MOST appropriate for the Faculty network to ensure maximum security?

    Show answer details

    Correct answer: A

    Faculty use managed devices with machine certificates. WPA3-Enterprise with EAP-TLS provides the strongest security by requiring mutual certificate-based authentication and 192-bit encryption support (in CNSA mode), fitting the 'maximum security' requirement for managed assets.

  2. 2

    Case Study: University Network Upgrade (Part 2)

    Refer to the University Network scenario.

    For the IoT devices (temperature sensors, locks) that only support WPA2-PSK, the university wants to prevent a shared password from being distributed to all users and minimize the impact if one device is compromised.

    Which feature in ClearPass and ArubaOS should be implemented to secure these devices?

    Show answer details

    Correct answer: B

    MPSK (Multi Pre-Shared Key) allows each device (or group of devices) to have a unique passphrase while connecting to the same SSID. ClearPass can manage these keys, ensuring that if one device is compromised, only its key needs to be revoked, not the entire SSID password.

  3. 3

    Case Study: University Network Upgrade (Part 3)

    Refer to the University Network scenario.

    A student reports they cannot access the 'Student-Secure' SSID. You check ClearPass Access Tracker and see the request is being REJECTED. The alert tab shows: "Error Code: 209 - RADIUS shared secret mismatch".

    Where must the configuration be corrected to resolve this issue? (Select TWO)

    Show answer details

    Correct answer: A, C

    The shared secret must match on both ends.

    A shared secret mismatch means the password used to encrypt RADIUS traffic differs between the client (Controller) and server (ClearPass). You must correct it in ClearPass (under Network Devices) AND on the Controller (under RADIUS Server configuration).

    sequenceDiagram participant Controller participant ClearPass Controller->>ClearPass: Access-Request (Secret A) ClearPass--xController: Silent Discard or Reject (Expects Secret B) Note right of ClearPass: Mismatch causes decryption failure
  4. 4

    A network administrator is designing a Dynamic Segmentation solution for a branch office using Aruba AOS-CX switches and Aruba Gateways. The goal is to tunnel specific user traffic back to the Gateway for centralized Policy Enforcement Firewall (PEF) inspection while keeping other traffic local. Which architecture component allows the switch to establish this tunnel dynamically based on the user's role assignment from ClearPass?

    Show answer details

    Correct answer: B

    User-Based Tunneling (UBT) is the feature on AOS-CX switches that allows traffic to be tunneled to a Gateway based on the user role assigned by ClearPass. This enables centralized policy enforcement (PEF) for specific users or devices.

    graph LR Client((Client)) -->|Access| Switch[AOS-CX Switch] Switch -->|GRE Tunnel| GW[Aruba Gateway] GW -->|PEF Inspection| Core[Core Network] Switch -.->|Local Traffic| Core
  5. 5

    An organization requires a wireless security standard that provides forward secrecy and protection against offline dictionary attacks for personal devices that cannot support 802.1X. Which security method should be deployed to meet these requirements?

    Show answer details

    Correct answer: C

    WPA3-Personal uses Simultaneous Authentication of Equals (SAE) instead of the 4-way handshake used in WPA2. SAE provides forward secrecy (if a key is compromised later, past sessions remain secure) and is resistant to offline dictionary attacks.

  6. 6

    While troubleshooting an authentication issue in ClearPass Access Tracker, an administrator sees a request status of 'Timeout'. The Access Tracker details show no response from the authentication source. What is the most likely cause of this error?

    Show answer details

    Correct answer: B

    A 'Timeout' status in Access Tracker typically indicates that ClearPass received the RADIUS request but timed out waiting for a response from the configured Authentication Source (e.g., Active Directory/LDAP) or an external RADIUS token server.

Create an account to continue.