HPE7-A10 HPE Aruba Network Security Expert Practice Questions
Prepare for HPE7-A10 with more than an answer.
- Level
- Expert
- Valid for
- 3 years
Domains covered on the exam 3
- Protect and Defend58%
- Analyze38%
- Forensics4%
- 1
A network administrator is troubleshooting an EAP-TLS authentication failure for a corporate user. The ClearPass Access Tracker shows that the request was rejected during client certificate validation, and the administrator confirms the user's certificate has indeed been revoked on the Certificate Authority. Which specific protocol and component is ClearPass using to get this real-time revocation status from the CA infrastructure?
sequenceDiagram participant Client participant Switch participant CPPM as ClearPass participant CA as Certificate Authority Client->>Switch: EAPOL-Start Switch-->>Client: EAP-Request/Identity Client-->>Switch: EAP-Response/Identity ([email protected]) Switch->>CPPM: RADIUS Access-Request (EAP-Response/Identity) CPPM-->>Client: EAP-Request (TLS Start, Server Certificate) Client-->>CPPM: EAP-Response (Client Certificate) activate CPPM CPPM->>CA: Revocation Status Check? CA-->>CPPM: Status: Revoked deactivate CPPM CPPM->>Switch: RADIUS Access-RejectShow answer details
Correct answer: A
The Online Certificate Status Protocol (OCSP) provides real-time revocation checking. ClearPass's EAP-TLS authentication method can verify each client certificate with OCSP (Verify Certificate using OCSP: Optional, Required or Required (CRL fallback)), sending the certificate's serial number to the OCSP responder named in the certificate (or an override URL); the responder returns a signed status of good, revoked or unknown, and a revoked status causes an Access-Reject. OCSP is the recommended method because it gives real-time status. Downloading a CRL over HTTP is also a revocation mechanism, but it is a periodically refreshed list, not a real-time per-certificate query; LDAP and RADIUS are not used to query the CA for certificate status.
- 2
An administrator has uploaded a custom Network Analytics Engine (NAE) script to an AOS-CX 10.13 switch and wants to create an agent from it that monitors a specific process with a custom CPU threshold. Where are the script's configurable parameters defined, and how does the administrator supply values for the new agent?
Show answer details
Correct answer: C
User-settable parameters of an NAE script are declared in its ParameterDefinitions dictionary (each with Name, Description, Type, Default and optional Encrypted/Required attributes). When the administrator creates an agent in the Web UI (Analytics > Agents > + Create, or + Create Agent from the Scripts page), the Create Agent dialog lists the selected script's parameters, shows default values in the More Info column and requires a value for any Required parameter that has no default; the same parameter_values can be supplied in a REST API POST to the script's nae_agents collection. One script can back many agents with different values, and integer parameters can be changed after the agent is created. The Manifest only identifies the script (Name, Description, Version, Author), parameters are not hard-coded per agent, and
show nae-scriptshows only each script's name, version, origin and status. - 3
ClearPass Device Insight (CPDI) has classified a new device on the network as a 'Smart TV' and has observed it communicating with multiple streaming service domains. To fine-tune security policies, which TWO pieces of information discovered by CPDI are most valuable for creating a granular access role in CPPM for all Smart TVs? (Select TWO).
Show answer details
Correct answer: B, C
To build one reusable, least-privilege policy for every Smart TV, the two most useful CPDI outputs are the device category classification and the destinations the devices talk to. CPDI sends each endpoint's classification (and any tags) to ClearPass Policy Manager, where it can drive role-mapping and enforcement rules for all devices of that category regardless of IP address or manufacturer. CPDI also records flow attributes such as Destination Hosts, Destination Connections, ports and application groups, which tell the administrator exactly which streaming services the role's firewall policy must permit - everything else can be denied. IP addresses are per-device and change, and the manufacturer alone does not describe what the device needs to reach.
To build one reusable, least-privilege policy for every Smart TV, the two most useful CPDI outputs are the device category classification and the destinations the devices talk to. CPDI sends each endpoint's classification (and any tags) to ClearPass Policy Manager, where it can drive role-mapping and enforcement rules for all devices of that category regardless of IP address or manufacturer. CPDI also records flow attributes such as Destination Hosts, Destination Connections, ports and application groups, which tell the administrator exactly which streaming services the role's firewall policy must permit - everything else can be denied. IP addresses are per-device and change, and the manufacturer alone does not describe what the device needs to reach.
- 4
A security audit reveals that a company's vulnerability remediation process is too slow, leaving critical systems exposed for extended periods. The CISO wants to implement an automated solution using Aruba products. Which integration provides the capability to automatically restrict network access for devices that a vulnerability scanner has identified as non-compliant?
Show answer details
Correct answer: D
ClearPass Policy Manager features a robust extension framework for integrating with third-party systems. By integrating with a vulnerability scanner, ClearPass can receive real-time updates about the compliance status of endpoints. If the scanner reports a critical vulnerability on a device, ClearPass can use this information in its enforcement policy to automatically trigger a Change of Authorization (CoA) and move the device to a remediation VLAN, thus automating the risk mitigation process.
- 5
A security analyst uses User and Entity Behavior Analytics (UEBA) to detect insider threats. The system flags an event where a user from the finance department, who normally only accesses servers during business hours, logs into a sensitive R&D server at 3:00 AM from an unfamiliar IP address. This is an example of what kind of threat detection?
Show answer details
Correct answer: C
This scenario is a classic example of anomaly-based detection, which is the core principle of UEBA. The system first establishes a baseline of normal behavior for each user and entity (e.g., 'Finance user accesses finance servers 9-5 from corporate IPs'). The flagged event is a significant deviation (anomaly) from this established baseline, indicating a potential threat such as a compromised account or a malicious insider.
- 6
A financial services company is implementing a Zero Trust architecture using Aruba solutions. The primary requirement is to enforce micro-segmentation for servers and virtual machines in the data center, ensuring that workloads can only communicate with explicitly authorized clients and other servers. Which combination of Aruba technologies is BEST suited to enforce these granular, stateful east-west policies directly in the data center switching fabric?
Show answer details
Correct answer: D
In the HPE Aruba Networking ESP data-center design, the CX 10000 Distributed Services Switch (DSS) 'enforces east-west traffic policy using an inline stateful firewall in hardware within the switch', so micro-segmentation is enforced at the top-of-rack switch port without hair-pinning server-to-server traffic through a centralized firewall. Aruba Fabric Composer, integrated with vCenter and AMD Pensando Policy Services Manager (PSM), manages the east-west policy centrally and lets VM administrators assign workloads to policy groups. Standard AOS-CX switches only support stateless ACLs (the stateful Policy Enforcement Firewall runs on Aruba gateways and APs); gateway IDS/IPS inspects only traffic that passes through the gateway; WIPS protects the RF environment; and EdgeConnect/OnGuard address SD-WAN and endpoint posture.
- 7
A security analyst is investigating a suspected advanced persistent threat (APT) that has compromised a user's credentials. The analyst needs to trace where on the network the stolen credentials have been used. Which log source should be examined FIRST to identify the first network authentication that used those credentials and every subsequent authenticated session?
Show answer details
Correct answer: B
ClearPass Policy Manager is the authentication server, so its authentication records (Monitoring > Live Monitoring > Access Tracker) list every RADIUS, TACACS+ and WebAuth request with the username, host MAC address, NAS IP/name, service, login status (Accept, Reject or Timeout), roles and enforcement profiles. Filtering on the compromised username over the investigation window shows the first network authentication with the stolen credentials and every later session, including the device and the network access device (switch/AP) used. Gateway firewall logs and switch syslog are keyed to traffic and IP addresses rather than to the credential, and CPDI classification data describes devices rather than user logins; they become useful pivots once the authenticated sessions have been identified.
- 8
A university is deploying a new Public Key Infrastructure (PKI) to secure its wireless network via 802.1X EAP-TLS. The security team wants to ensure that if a student's laptop is lost or stolen, its certificate can be immediately invalidated to prevent network access. Which TWO PKI components or protocols are essential for implementing this real-time certificate validation check during the authentication process? (Select TWO).
Show answer details
Correct answer: B, D
Both mechanisms let the RADIUS server check whether a client certificate has been revoked during EAP-TLS. A Certificate Revocation List (CRL) is a CA-signed list of revoked certificate serial numbers that the server downloads and refreshes (in ClearPass: Administration > Certificates > Revocation Lists, updated on a schedule or with Check Now). The Online Certificate Status Protocol (OCSP) queries a responder for the status (good, revoked or unknown) of an individual certificate at authentication time and is recommended because it gives real-time status (ClearPass EAP-TLS method: Verify Certificate using OCSP = Optional, Required or Required (CRL fallback)). A Registration Authority verifies requester identities, SCEP enrolls certificates and the root CA anchors trust; none of them checks revocation during authentication.
Both mechanisms let the RADIUS server check whether a client certificate has been revoked during EAP-TLS. A Certificate Revocation List (CRL) is a CA-signed list of revoked certificate serial numbers that the server downloads and refreshes (in ClearPass: Administration > Certificates > Revocation Lists, updated on a schedule or with Check Now). The Online Certificate Status Protocol (OCSP) queries a responder for the status (good, revoked or unknown) of an individual certificate at authentication time and is recommended because it gives real-time status (ClearPass EAP-TLS method: Verify Certificate using OCSP = Optional, Required or Required (CRL fallback)). A Registration Authority verifies requester identities, SCEP enrolls certificates and the root CA anchors trust; none of them checks revocation during authentication.
- 9
True or False: After a Network Analytic Engine (NAE) script is successfully installed and validated on an AOS-CX switch, it will automatically begin monitoring the network and generating alerts based on its logic.
Show answer details
Correct answer: B
This statement is false. Installing an NAE script only makes it available on the switch. To activate it, a network administrator must explicitly create an NAE agent based on that script. The agent is the running instance of the script that performs the actual monitoring and alerting. Without creating the agent, the script remains dormant.
- 10
A multinational corporation is enhancing its security posture by integrating ClearPass Device Insight (CPDI) with its existing ClearPass Policy Manager (CPPM) deployment. The goal is to dynamically adjust access policies based on the real-time risk score of endpoints. An administrator observes that CPDI has flagged a corporate laptop with a high-risk score due to it communicating with a known command-and-control server. Which automated remediation action is the most effective and commonly implemented response within CPPM?
Show answer details
Correct answer: C
The integration between CPDI and CPPM is designed for dynamic, automated responses. When CPDI detects a high-risk device, it can signal CPPM to trigger a RADIUS Change of Authorization (CoA). This allows CPPM to instantly re-evaluate the device's session and apply a different enforcement policy, such as assigning a 'Quarantine' role that maps to a restricted VLAN. This contains the threat while allowing for further investigation, which is a core tenet of dynamic Zero Trust security.
