HPE7-A07 Aruba Campus Access Mobility Expert (Written) Practice Questions
Prepare for HPE7-A07 with more than an answer.
- Exam fee
- $400 USD
- Time limit
- 120 minutes
- Questions on the exam
- 70
- Passing score
- Not publicly disclosed
- Level
- Expert
- Valid for
- 3 years
Domains covered on the exam 7
- Wireless Networks and WLAN20%
- Campus Network Infrastructure20%
- Network Overlays and Segmentation20%
- Security15%
- Performance Optimization and QoS10%
- Network Resiliency and Redundancy5%
- Management, Monitoring, and Troubleshooting10%
- 1
An administrator is deploying Aruba NetConductor to simplify the management of a large EVPN-VXLAN campus fabric. What is the primary function of NetConductor in this environment?
Show answer details
Correct answer: C
Aruba NetConductor is an orchestration application that runs within Aruba Central. Its primary purpose is to abstract away the complexity of manually configuring an EVPN-VXLAN fabric. It provides an intent-based workflow that allows administrators to define the fabric topology, segmentation policies, and services, and then it automatically generates and pushes the necessary CLI configurations to all the switches in the fabric.
- 2
A network engineer is configuring an Aruba Mobility Gateway cluster for high availability. To ensure that client sessions are maintained during a failover event, which feature must be enabled?
Show answer details
Correct answer: C
For a gateway cluster to provide seamless, stateful failover, state synchronization must be enabled. This feature ensures that client authentication states, session information, and user roles are continuously synchronized between the active and standby gateways in the cluster. When a failover occurs, the new active gateway already has all the necessary session information and can take over without forcing clients to re-authenticate, thus preserving their sessions.
- 3
In a centralized overlay deployment using Aruba Mobility Gateways, user traffic from an access point is tunneled back to a gateway for policy enforcement. What is the encapsulation protocol used for these tunnels between the APs and the Gateways?
Show answer details
Correct answer: B
Aruba's centralized architecture uses GRE tunnels to forward user traffic from the access points to the Mobility Gateways. This allows for the creation of an overlay network where policies can be centrally defined and enforced on the gateway, regardless of the user's location or the underlying wired network topology. VXLAN is used in distributed overlays (fabric), IPsec is for secure VPNs, and L2TP is another tunneling protocol not typically used for this purpose in Aruba's architecture.
- 4
A network administrator is troubleshooting an OSPF adjacency issue between two Aruba CX switches. The
show ospf neighborcommand output is empty. The administrator has verified that the IP addresses are in the same subnet, the area IDs match, and the interfaces are up. Which of the following parameters, if mismatched, would prevent an OSPF adjacency from forming? (Select TWO)Show answer details
Correct answer: B, D
For an OSPF adjacency to form, several parameters in the Hello packet must match between neighbors. Among the most critical are the Hello and Dead timers, and the Stub Area Flag. If one router is configured for a standard area and the other for a stub area, the flag mismatch will prevent adjacency. Similarly, if the Hello/Dead timers differ (e.g., 10/40 on one and 30/120 on the other), the adjacency will not form. Router IDs must be unique in the OSPF domain, and Process IDs are locally significant and do not need to match.
- 5
A network administrator captures the following simplified 802.11 beacon frame from an Aruba AP. A client is failing to connect to this network, and the administrator suspects a capabilities mismatch. Based on the information in the frame, what is the most likely reason for the connection failure?
graph TD subgraph Beacon Frame A[Frame Control] B[Duration] C[DA: ff:ff:ff:ff:ff:ff] D[SA: AP_BSSID] E[BSSID: AP_BSSID] F[SSID: Corp-WiFi] G[Supported Rates: 1, 2, 5.5, 11 Mbps] H[Capability Info: Short Preamble=No, WPA3=Yes, 802.11k=Yes] I[HT Capabilities: 40MHz Channel=No] endShow answer details
Correct answer: C
The Capability Information field in the beacon frame explicitly indicates that WPA3 is enabled ('WPA3=Yes'). If the client device (e.g., an older laptop or IoT device) does not have a WPA3-compatible driver or hardware, it will fail the security handshake and be unable to connect. While most modern networks operate in a WPA3-Transition mode to allow both WPA2 and WPA3 clients, if the network is configured for WPA3-only, this would be a direct cause of failure for older clients. The other options are less likely: lack of 802.11k support is not a connection stopper, and the beacon indicates short preambles are disabled.
- 6
A financial services firm is deploying an EVPN-VXLAN fabric using Aruba CX switches. The network architect has designed the fabric with a two-tier spine-and-leaf topology. To ensure optimal and loop-free forwarding for Layer 2 broadcast, unknown unicast, and multicast (BUM) traffic within a VNI, which mechanism is the Aruba-recommended best practice to implement in the underlay network?
Show answer details
Correct answer: B
The recommended best practice for handling BUM traffic in an EVPN-VXLAN fabric is to use multicast in the underlay network, specifically PIM-SM. This allows VTEPs to join multicast groups corresponding to VNIs, ensuring BUM traffic is efficiently forwarded only to VTEPs that need it, rather than flooding it across the entire underlay. Static replication is not scalable, ingress replication relies on the control plane which can be less efficient for high BUM rates, and IGMP snooping operates at Layer 2 within a VLAN, not in the Layer 3 underlay for VXLAN.
- 7
A university is implementing Dynamic Segmentation with Aruba Gateways and Aruba CX switches. A security policy must be enforced where authenticated users are assigned a 'Student' role. This role should allow access to the internet and university portal servers, but explicitly deny any traffic to the 'Faculty_Research' subnet. Which components are required to build and enforce this policy? (Select TWO)
Show answer details
Correct answer: A, B
Dynamic Segmentation relies on a centralized policy engine (ClearPass) to assign roles and a network device (Aruba Gateway) to enforce them. ClearPass authenticates the user and, based on its own policies, returns the 'Student' role name via a RADIUS enforcement profile. The Aruba Gateway, having received this role, applies its locally configured 'Student' user role, which contains the specific ACLs to permit internet/portal access and deny access to the research subnet. VSX provides redundancy but doesn't define the policy, and NetConductor is for fabric orchestration.
- 8
A consultant is troubleshooting a newly configured VSX pair of Aruba CX 8360 switches. The ISL link is up and the keepalive is successful over the management network. However, the secondary switch continually fails to synchronize its configuration and reports a 'sync-loss' state. The consultant verifies that
vsx-syncis enabled for the necessary features. What is the most likely cause of this synchronization failure?Show answer details
Correct answer: B
For VSX synchronization to function correctly, both switches in the pair must be running the exact same ArubaOS-CX software version. A mismatch in firmware will prevent the configuration synchronization protocol from working, leading to a persistent 'sync-loss' state even if the ISL and keepalive links are healthy. While NTP is a best practice, minor time drifts won't block synchronization. The ISL uses LACP which negotiates link parameters, and the keepalive should not be routed through the ISL.
- 9
True or False: In an Aruba EVPN-VXLAN fabric, the Distributed Anycast Gateway functionality requires each VTEP participating in a given VNI to be configured with the exact same IP and MAC address for its SVI.
Show answer details
Correct answer: A
This statement is true. The core principle of a Distributed Anycast Gateway (DAG) is that every leaf switch (VTEP) that serves as a gateway for a particular subnet (VNI) presents the identical default gateway IP and MAC address to the connected hosts. This allows hosts to send traffic to their local leaf for routing, enabling optimal egress traffic paths and seamless host mobility within the fabric.
- 10
A hospital is deploying EAP-TLS for its corporate wireless network to achieve the highest level of security. The network team is using Aruba ClearPass as the RADIUS server. During testing, corporate-issued laptops are failing to connect. A packet capture on the client shows the ClearPass server is sending a RADIUS Access-Reject message immediately after the client sends its Client Hello message. What is the most probable misconfiguration in ClearPass?
Show answer details
Correct answer: C
In EAP-TLS, the RADIUS server must trust the Certificate Authority (CA) that issued the client's certificate. If the root or intermediate CA certificate is not imported into the ClearPass Trust List, ClearPass cannot validate the client's certificate chain and will reject the authentication attempt. The rejection happening immediately after the Client Hello suggests the server cannot even begin to validate the client's presented identity, which points directly to a trust list issue. An expired client certificate or untrusted server certificate would cause failure at a later stage of the TLS handshake.
