HPE6-A88 HPE Aruba Networking ClearPass Practice Questions
Prepare for HPE6-A88 with more than an answer.
Unlock the full exam and previous versions
- v1HPE Aruba Networking ClearPass 225 questions Current
- ACCP_6.2Legacy Aruba Certified Clearpass Professional v6.2 140 questions Locked
- ACCP-V62Legacy Accp-V6.2 88 questions Locked
- Exam fee
- $250 USD
- Level
- Professional
- Valid for
- 3 years
Domains covered on the exam 8
- Identify Network Access Control and Security Features15%
- Identify HPE Aruba Networking ClearPass Modules and System Components10%
- Define Authentication, Authorization, and Accounting (AAA)10%
- Identify Service Configuration and Selection15%
- Define Guest Access Management and Captive Portal10%
- Identify Dynamic User Roles and Segmentation15%
- Define Onboard Provisioning and Posture Attribute Enforcement10%
- Define HPE Aruba Networking ClearPass Server Management15%
- 1
A financial firm is required to store all network authentication records for 7 years for auditing purposes. The built-in Insight database on their ClearPass cluster is configured to purge data after 180 days to maintain performance. What is the recommended approach to meet the long-term storage requirement?
Show answer details
Correct answer: C
The best practice for long-term retention is to forward data to a dedicated log management or SIEM (Security Information and Event Management) platform. This offloads the storage burden from ClearPass, allowing Insight to be tuned for short-term operational reporting and troubleshooting while the SIEM handles long-term storage, analysis, and compliance reporting.
- 2
An administrator needs to create a custom skin for the ClearPass Guest captive portal to match the company's branding. Which section of the ClearPass UI is used to upload logos, modify CSS, and edit the HTML structure of portal pages?
Show answer details
Correct answer: C
All customization of the look and feel of guest portals is managed within the ClearPass Guest module. The 'Manage Skins' section allows administrators to create new skins, upload custom header/footer HTML, modify the CSS, and manage other branding elements to create a fully customized user experience.
- 3
A service is configured with a Role Mapping policy that assigns roles based on Active Directory group membership. A user who is a member of the 'Contractors' AD group authenticates, but Access Tracker shows they are not assigned the '[Contractor]' role in ClearPass. The user's other AD attributes are visible in the request. What is a likely cause for this failure?
Show answer details
Correct answer: B
In the Active Directory Authentication Source configuration, an administrator must explicitly specify which attributes to fetch. For performance reasons, the 'memberOf' attribute (which contains group memberships) is not always fetched by default. If this attribute is missing from the list of attributes to fetch, the Role Mapping policy will have no group information to evaluate, causing the role assignment to fail.
- 4
When configuring a posture policy using Agentless OnGuard, what is the primary mechanism ClearPass uses to gather health information from an endpoint?
Show answer details
Correct answer: C
Agentless OnGuard works by performing a targeted network scan of the endpoint from a ClearPass appliance. It uses an integrated version of Nmap to probe the device for open ports, running services, and OS version information. This data is then compared against the configured posture policy to determine the health status without requiring any software to be installed on the endpoint.
- 5
A network administrator is reviewing the below authentication flow and notices that the NAD is not receiving the correct VLAN assignment for authenticated users. Based on the diagram, where is the most likely point of failure?
sequenceDiagram participant Client participant NAD as Switch participant CPPM as ClearPass participant AD as Active Directory Client->>NAD: EAPOL-Start NAD->>CPPM: RADIUS Access-Request CPPM->>AD: LDAP Bind/Search AD-->>CPPM: User Found, Group=Employees CPPM-->>NAD: RADIUS Access-Accept (Role=[Employee]) NAD-->>Client: EAP-SuccessShow answer details
Correct answer: C
The diagram shows a successful authentication flow where ClearPass assigns the [Employee] role. The assignment of a VLAN is an enforcement action. If the VLAN is not being applied, it means the Enforcement Profile that gets triggered by the [Employee] role is either missing or has an incorrectly configured RADIUS attribute for VLAN assignment (e.g., Tunnel-Private-Group-ID).
- 6
A hospital is deploying ClearPass to secure its wired network. The primary goal is to automatically identify and segment medical IoT devices, such as infusion pumps and heart monitors, based on their traffic patterns and communication protocols. These devices do not support 802.1X. Which ClearPass feature is most critical for achieving this requirement?
Show answer details
Correct answer: C
ClearPass Endpoint Profiling is the correct feature. It allows ClearPass to collect attributes about devices using methods like DHCP fingerprinting, MAC OUI, and other network traffic analysis to classify non-802.1X devices. Onboard is for BYOD certificate provisioning, OnGuard is for posture assessment of managed clients, and Guest is for managing temporary network access.
- 7
An administrator is troubleshooting a failed EAP-TLS authentication in Access Tracker. The error message is 'Outer EAP-Type not configured on the server'. The client is a corporate laptop configured via MDM, and the Aruba controller is configured to use ClearPass for 802.1X. What is the most likely misconfiguration in ClearPass?
Show answer details
Correct answer: B
The error 'Outer EAP-Type not configured on the server' specifically indicates that the EAP method being requested by the client (in this case, EAP-TLS) is not enabled or allowed within the service's authentication method configuration. The server is rejecting the request because it's not configured to handle that EAP type.
- 8
A university is implementing ClearPass OnGuard to ensure that only compliant devices can access sensitive research data. The security policy requires that devices must have a specific registry key present, be domain-joined, and have an approved antivirus application running. Which OnGuard agent type should be used to enforce these checks?
Show answer details
Correct answer: B
The Persistent Agent is required for these checks. It is an installed application that can perform deep health checks, such as verifying registry keys, running processes (antivirus), and system properties (domain-joined status). The Dissolvable Agent is temporary and has limited capabilities, while the Agentless approach can only check attributes visible from the network, not internal device state.
- 9
A consultant is designing a ClearPass cluster for a global corporation with offices in North America, Europe, and Asia. To ensure low-latency authentication and local survivability, the design includes subscriber appliances in each region. Which ClearPass feature is essential for directing authentication requests from a NAD to the geographically closest subscriber?
Show answer details
Correct answer: C
ClearPass Zones are designed for this exact purpose. By grouping subscribers into zones based on geographic location, NADs can be configured to prioritize authenticating to subscribers within their local zone. This minimizes WAN latency for AAA traffic and provides regional resilience if the connection to the publisher is lost.
- 10
A network administrator is configuring a new service for wired MAC authentication. They want to ensure this service only processes requests from devices connected to a specific set of switch ports. Which conditions should be configured in the service rules to achieve this? (Select TWO)
Show answer details
Correct answer: A, C
