HPE6-A85 HPE Network Campus Access Associate Practice Questions
Prepare for HPE6-A85 with more than an answer.
Unlock the full exam and previous versions
- v1HPE Network Campus Access Associate 256 questions Current
- HPE6-A44Legacy Scalable WLAN Design and Implementation (SWDI) 8 163 questions Locked
- Exam fee
- $260 USD
- Level
- Associate
- Valid for
- 3 years
Domains covered on the exam 11
- Network Stack7%
- Connectivity10%
- Network Resiliency and Virtualization8%
- Switching19%
- WLAN18%
- Routing9%
- Security9%
- Authentication/Authorization6%
- Management and Monitoring7%
- Troubleshooting4%
- Performance Optimization3%
- 1
An administrator is reviewing the
show spanning-treeoutput on an Aruba CX switch and sees that a port's role is 'Alternate'. What does this indicate about the port's state and function in the network?Show answer details
Correct answer: C
In Rapid Spanning Tree Protocol (RSTP), an 'Alternate' port is a port that provides a redundant, secondary path toward the root bridge. It is currently in a discarding (blocking) state to prevent a loop but is ready to transition immediately to a forwarding state if the primary path (the Root Port) fails. This is a key enhancement of RSTP over legacy STP for faster convergence.
- 2
A network administrator at a manufacturing plant needs to implement a basic Quality of Service (QoS) policy on an Aruba CX switch. The goal is to ensure that traffic from the SCADA control system (VLAN 50) is prioritized over general data traffic (VLAN 100). Which QoS mechanism should be used to achieve this?
Show answer details
Correct answer: C
To prioritize traffic from a specific VLAN, the first step is to classify it. An administrator would create a policy that identifies traffic belonging to VLAN 50. Then, that traffic would be marked with a higher priority value (e.g., a specific CoS or DSCP value). Subsequent queuing mechanisms on the switch will then use this marking to give the SCADA traffic preferential treatment over the lower-priority data traffic, especially during periods of congestion.
- 3
A technician is troubleshooting a connectivity issue using the
pingcommand from a Windows PC. The commandping 10.1.1.1is successful, butping server1.example.comfails, even though the technician knowsserver1.example.comresolves to10.1.1.1. Which network service is most likely misconfigured on the client PC?Show answer details
Correct answer: C
The problem describes a classic DNS (Domain Name System) issue. The ability to successfully ping by IP address (
10.1.1.1) confirms that Layer 3 connectivity exists between the PC and the server. The failure to ping by hostname (server1.example.com) indicates that the PC is unable to resolve the hostname to its corresponding IP address. This is almost always caused by an incorrect or unreachable DNS server configuration on the client. - 4
A new Aruba wireless network is being deployed. The security team mandates the use of the most secure and current Wi-Fi encryption standard available. Which standard should the network administrator implement for the corporate SSID?
Show answer details
Correct answer: D
WPA3 is the latest and most secure Wi-Fi security standard. For a corporate environment, WPA3-Enterprise is the recommended choice as it combines the strong encryption of WPA3 with 802.1X authentication, providing individual user authentication through a RADIUS server. This is significantly more secure than pre-shared key (PSK) methods. WEP and WPA are obsolete and highly insecure.
- 5
A network administrator needs to create a static default route on an Aruba CX switch. This route should direct all traffic for unknown destinations to the upstream firewall at IP address 192.168.1.254. What is the correct command to configure this route in the default VRF?
Show answer details
Correct answer: A
The command
ip route 0.0.0.0/0 192.168.1.254configures a static default route. The destination0.0.0.0/0is a special address that matches all possible IP destinations. The next-hop address192.168.1.254tells the switch where to send any packet that does not have a more specific match in its routing table. - 6
Which two pieces of information are required for a client device to communicate on a TCP/IP network beyond its local subnet? (Select TWO)
Show answer details
Correct answer: A, C
A client needs its own unique IP Address and Subnet Mask to communicate on its local subnet. To communicate with devices on different subnets (i.e., beyond its local network), it must also have a Default Gateway address configured. The default gateway is the router interface to which the client sends all traffic destined for remote networks. DNS is needed for name resolution, not basic IP communication.
- 7
True or False: In an Aruba Instant AP cluster, one AP is dynamically elected as the Virtual Controller, which is responsible for managing and distributing the configuration to all other member APs in the same cluster.
Show answer details
Correct answer: A
This statement is true. The core architecture of Aruba Instant APs (IAPs) is the Virtual Controller. In a cluster of IAPs on the same Layer 2 network, one AP is elected to function as the master, or Virtual Controller. The administrator connects to this single Virtual Controller to configure the entire cluster, and the configuration is then synchronized to all other member APs. If the master AP fails, another AP in the cluster is elected to take over the role seamlessly.
- 8
A hospital is deploying Aruba CX 6400 modular switches in its wiring closets to connect critical medical devices. The primary requirements are uninterrupted network operation even during a single switch failure and active-active forwarding paths for all connected devices. Which Aruba technology should be implemented at the access layer to meet these specific requirements?
Show answer details
Correct answer: D
VSX is supported on the Aruba CX 6400 (and CX 8xxx/9300/10000), while VSF stacking is not supported on the 6400. A VSX pair keeps two independent control planes, synchronizes MAC, ARP and STP state over the ISL, and presents multi-chassis LAGs, so dual-homed devices get active-active links that survive the failure of either switch. STP blocks redundant links (active-passive), and VRRP only provides first-hop gateway redundancy. VSX does not apply to CX 6300 switches; on 6300/6200 access switches the equivalent resiliency option is a VSF stack.
- 9
A network technician is configuring a new Aruba AP-515 in a corporate office. The security policy requires that employee wireless traffic be tunneled to a central Aruba Mobility Gateway for policy enforcement, while guest traffic should be bridged locally at the AP. Which AP operation mode supports this requirement?
Show answer details
Correct answer: B
In Campus AP (CAP) mode the AP is managed by an Aruba Mobility Controller/Gateway, and the forwarding mode is set per SSID in the virtual AP profile (
forward-mode {tunnel | bridge | split-tunnel | decrypt-tunnel}). The employee SSID can use tunnel mode, so the AP sends that traffic in a GRE tunnel to the gateway for policy enforcement, while the guest SSID uses bridge mode and the AP forwards guest traffic directly onto the local wired network. (AOS 10 uses per-WLAN Tunnel or Bridge forwarding for the same result; its 'Mixed' mode means one WLAN whose clients are bridged or tunneled depending on the assigned VLAN.) Instant and standalone APs are not managed by a Mobility Gateway, and Spectrum Monitor is a non-serving analysis mode. - 10
A network administrator is troubleshooting an issue where a user connected to an Aruba CX switch port cannot access network resources. The port is configured for 802.1X authentication. The RADIUS server logs show no authentication attempt from the user's MAC address. The user's device does not have an 802.1X supplicant configured. What feature should be configured on the switch port to allow this device to gain network access based on its MAC address after 802.1X fails?
Show answer details
Correct answer: C
When a device does not have an 802.1X supplicant, it will not respond to the EAP requests from the switch, and dot1x authentication will time out. By configuring MAC Authentication as a fallback method, the switch will then attempt to authenticate the device using its MAC address against the RADIUS server. This is a common strategy for supporting devices like printers or IoT sensors on 802.1X-enabled ports.
