HPE7-A06 HPE Campus Access Switching Expert (Written) Practice Questions
Prepare for HPE7-A06 with more than an answer.
- Level
- Expert
- Valid for
- 3 years
Domains covered on the exam 10
- Network Stack4%
- Connectivity9%
- Network Resiliency and Virtualization8%
- Switching19%
- WLAN9%
- Routing16%
- Security10%
- Authentication/Authorization9%
- Troubleshooting10%
- Performance Optimization6%
- 1
A network architect is designing a campus network where user roles and access permissions change frequently. The goal is to enforce security policies based on a user's role (e.g., 'Employee', 'Contractor') regardless of their location or device. In an ArubaOS-CX and ClearPass environment, which technology provides this identity-based segmentation and policy enforcement within the switching fabric?
Show answer details
Correct answer: C
User-Based Tunneling (UBT), also known as Dynamic Segmentation, is the Aruba technology designed for this exact purpose. When a user authenticates, ClearPass assigns them a user role. This role is downloaded to the ArubaOS-CX switch, which then tunnels the user's traffic to a central enforcement point (an Aruba Gateway or another switch). The role contains the policy (ACLs, QoS, etc.) that is applied to the user's traffic, providing consistent enforcement based on identity, not physical location.
- 2
A company has a two-tier campus network with a BGP-based core. An access layer switch is connected to two different distribution switches. The access switch is running OSPF with both distribution switches. The distribution switches are redistributing the OSPF routes into BGP. From the perspective of a core router, it is learning the same access-layer subnet prefix from both distribution switches. By default, how will the BGP best path selection algorithm on the core router choose the path to the access-layer subnet?
Show answer details
Correct answer: C
When a route is redistributed from an IGP (like OSPF) into BGP, the OSPF metric is, by default, carried over into the BGP Multi-Exit Discriminator (MED) attribute. Assuming other higher-priority BGP attributes (like Weight, Local Preference, AS_PATH) are equal, the BGP best path algorithm will use the MED to break the tie. It will prefer the path with the lower MED value, which corresponds to the lower OSPF cost, making it the 'closest' exit point from the BGP domain.
- 3
After a campus-wide power outage, users report that they cannot access any network resources. A network engineer logs into a core ArubaOS-CX switch and issues the
show ip routecommand, which shows no OSPF routes. Theshow ospf neighborcommand shows all neighbors are in theInitstate. The physical links are up and IP connectivity has been verified with ping. What is the most probable cause for OSPF neighbors being stuck in theInitstate?Show answer details
Correct answer: C
The OSPF
Initstate means a router is receiving Hello packets from a neighbor but does not see its own Router ID in those packets, indicating a one-way communication problem. Since physical and IP connectivity are confirmed, a common cause is an ACL blocking the return OSPF traffic. The core switch can send Hellos, but the distribution switches' Hellos are being blocked by an inbound ACL on the core switch. This prevents the core switch from seeing its own ID in the neighbor's Hello packet, so the state never progresses to2-Way. - 4
A network administrator at a university is configuring guest wireless access. The security policy states that guest traffic must be completely isolated from the internal corporate network and routed directly to the internet. The campus uses Aruba APs and Mobility Conductors. Which AP forwarding mode should be configured for the guest SSID to meet this requirement?
Show answer details
Correct answer: B
Bridge mode is the ideal forwarding mode for this scenario. In bridge mode, the AP bridges the guest clients' traffic directly onto the local wired network segment it is connected to. This allows the guest traffic to be placed on a dedicated guest VLAN at the access layer, which can then be routed directly to the internet firewall, completely bypassing the corporate network and the mobility conductors. Tunnel mode would send the traffic back to the conductor, which is not desired for guest traffic isolation.
- 5
A network engineer is configuring TACACS+ for administrative access on a stack of ArubaOS-Switch devices. The goal is to have authentication and authorization handled by a central ClearPass server, but to allow local authentication as a fallback if the ClearPass server is unreachable. What is the correct sequence of commands to achieve this?
Show answer details
Correct answer: B
The order of methods in the
aaa authenticationcommand defines the sequence in which the switch attempts authentication. The commandaaa authentication login default group tacacs localinstructs the switch to first attempt authentication against the configured TACACS+ server group. If all servers in that group are unreachable (timeout), it will then fall back to using the locally configured user database. This provides the desired behavior of central authentication with a local fallback. - 6
A financial institution is implementing a multi-VRF environment on their ArubaOS-CX core switches to segment traffic between corporate, trading, and guest networks. A network architect needs to ensure that specific high-priority trading data from the trading VRF can be routed to a shared monitoring service located in the corporate VRF, without leaking all routes between the VRFs. Which routing feature is the most precise and secure method to achieve this specific inter-VRF communication?
Show answer details
Correct answer: C
The most scalable, secure, and precise method for controlled inter-VRF routing on ArubaOS-CX switches is using Multi-Protocol BGP (MP-BGP) with route targets (RTs). By configuring specific RTs for export on one VRF and for import on another, an administrator can selectively leak only the required routes (e.g., the monitoring service prefix) without merging the entire routing tables. Static routes are less dynamic, and PBR is more for path selection than inter-VRF routing. Merging VRFs into a global table is insecure and defeats the purpose of segmentation.
- 7
A network engineer is troubleshooting an ArubaOS-CX switching environment where an NAE agent designed to monitor BGP neighbor states is not generating expected alerts. The agent's script is syntactically correct and the NAE engine is running. What are the most likely reasons for the agent's failure to trigger alerts? (Select TWO)
Show answer details
Correct answer: B, C
A common failure point for NAE agents is an incorrect resource URI. If the script's monitor is trying to access a path like
/rest/v10.04/system/bgp/neighborsbut the path is wrong, misspelled, or unsupported in the current firmware, the agent cannot retrieve data and will not trigger alerts. Another likely issue is that the condition being checked in the script logic is never met, so the alert action is never called.Even if the agent is monitoring the correct URI, the Python logic that evaluates the data might be flawed. For example, if the script checks for
neighbor_state == 'down'but the state is actually reported as 'Idle' or 'Connect', the condition will never evaluate to true, and the alert action will not be triggered. This is a common issue in script-based monitoring. - 8
True or False: In an ArubaOS-CX VSX environment, the VSX keepalive link is mandatory for detecting a dual-active scenario, and it must be a direct Layer 3 connection between the primary and secondary switches.
Show answer details
Correct answer: A
This statement is true. The VSX keepalive connection is a critical component for split-brain detection (dual-active scenario). It operates at Layer 3 and is used as a heartbeat mechanism when the Inter-Switch Link (ISL) fails. A direct point-to-point connection is the recommended and most reliable design, although routing it through an OOB management network is a possible, though less ideal, alternative.
- 9
A university is deploying a large campus network with Aruba CX switches and ClearPass. The security policy requires that devices connecting to wired ports are dynamically assigned to different VLANs based on their type (e.g., IP phones, printers, corporate laptops). A network engineer has configured 802.1X and MAB, and is now creating enforcement policies in ClearPass. Which ClearPass feature is essential for identifying the device type and returning the correct VLAN to the switch?
Show answer details
Correct answer: C
ClearPass Profiling is the feature designed for device identification. It collects attributes from network traffic and authentication requests (like DHCP fingerprints, MAC OUI, and LLDP data) to classify endpoints. Once a device is profiled (e.g., identified as a 'Polycom IP Phone'), enforcement policies can use this profile information as a condition to return specific RADIUS attributes, such as
Tunnel-Private-Group-ID, which instructs the switch to place the device in the correct VLAN. - 10
A hospital is upgrading its campus core with a pair of Aruba 8360 switches running in a VSX pair. They have a requirement for multicast video streaming for medical imaging, which relies on PIM-SM. The network administrator needs to ensure multicast routing functions correctly and efficiently across the VSX pair. What is the recommended approach for configuring PIM in this VSX environment?
Show answer details
Correct answer: B
In a VSX environment, PIM must be configured on both switches. The
pim active-forwardingcommand should be enabled on the SVIs within the VSX pair. This allows both switches to actively forward multicast traffic, preventing traffic from being dropped and enabling efficient load balancing. PIM state is not synchronized via VSX; each switch maintains its own PIM neighbor relationships and state tables. Disabling PIM on one switch would break multicast routing.
