Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the HP Aruba-ACNSA HPE6-A78 Questions and answers with ValidTests

Exam HPE6-A78 All Questions
Exam HPE6-A78 Premium Access

View all detail and faqs for the HPE6-A78 exam

Viewing page 5 out of 6 pages
Viewing questions 41-50 out of questions
Questions # 41:

What is a correct description of a stage in the Lockheed Martin kill chain?

Options:

A.

In the delivery stage, the hacker delivers malware to targeted users, often with spear phishing methods.

B.

In the installation phase, hackers seek to install vulnerabilities in operating systems across the network.

C.

In the weaponization stage, malware installed in the targeted network seeks to attack intrusion prevention systems (IPS).

D.

In the exploitation phase, hackers conduct social engineering attacks to exploit weak algorithms and crack user accounts.

Expert Solution
Questions # 42:

Question # 42

What is another setting that you must configure on the switch to meet these requirements?

Options:

A.

Set the aaa authentication login method for SSH to the "radius" server-group (with local as backup).

B.

Configure a CPPM username and password that match a CPPM admin account.

C.

Create port-access roles with the same names of the roles that CPPM will send in Aruba-Admin-Role VSAs.

D.

Disable SSH on the default VRF and enable it on the mgmt VRF instead.

Expert Solution
Questions # 43:

A company has Aruba Mobility Controllers (MCs). Aruba campus APs. and ArubaOS-CX switches. The company plans to use ClearPass Policy Manager (CPPM) to classify endpoints by type The ClearPass admins tell you that they want to run Network scans as part of the solution

What should you do to configure the infrastructure to support the scans?

Options:

A.

Create a TA profile on the ArubaOS-Switches with the root CA certificate for ClearPass's HTTPS certificate

B.

Create device fingerprinting profiles on the ArubaOS-Switches that include SNMP. and apply the profiles to edge ports

C.

Create remote mirrors on the ArubaOS-Swrtches that collect traffic on edge ports, and mirror it to CPPM's IP address.

D.

Create SNMPv3 users on ArubaOS-CX switches, and make sure that the credentials match those configured on CPPM

Expert Solution
Questions # 44:

You are deploying a new wireless solution with an HPE Aruba Networking Mobility Master (MM), Mobility Controllers (MCs), and campus APs (CAPs). The solution will include a WLAN that uses Tunnel for the forwarding mode and WPA3-Enterprise for the security option.

You have decided to assign the WLAN to VLAN 301, a new VLAN. A pair of core routing switches will act as the default router for wireless user traffic.

Which links need to carry VLAN 301?

Options:

A.

Only links on the path between APs and the core routing switches

B.

Only links on the path between APs and the MC

C.

All links in the campus LAN to ensure seamless roaming

D.

Only links between MC ports and the core routing switches

Expert Solution
Questions # 45:

You have been authorized to use containment to respond to rogue APs detected by ArubaOS Wireless Intrusion Prevention (WIP). What is a consideration for using tarpit containment versus traditional wireless containment?

Options:

A.

Rather than function wirelessly, tarpit containment sends ARP frames over the wired network to poison rogue APs ARP tables and prevent them from transmitting on the wired network.

B.

Rather than target all clients connected to rogue APs, tarpit containment targets only authorized clients that are connected to a rogue AP, reducing the chance of negative effects on neighbors.

C.

Tarpit containment does not require an RF Protect license to function, while traditional wireless containment does.

D.

Tarpit containment forms associations with clients to enable more effective containment with fewer disassociation frames than traditional wireless containment.

Expert Solution
Questions # 46:

What is a benefit or using network aliases in ArubaOS firewall policies?

Options:

A.

You can associate a reputation score with the network alias to create rules that filler traffic based on reputation rather than IP.

B.

You can use the aliases to translate client IP addresses to other IP addresses on the other side of the firewall

C.

You can adjust the IP addresses in the aliases, and the rules using those aliases automatically update

D.

You can use the aliases to conceal the true IP addresses of servers from potentially untrusted clients.

Expert Solution
Questions # 47:

You have been asked to send RADIUS debug messages from an AOS-CX switch to a central SIEM server at 10.5.15.6. The server is already defined on the switch with this command:

logging 10.5.15.6

You enter this command:

debug radius all

What is the correct debug destination?

Options:

A.

file

B.

console

C.

buffer

D.

syslog

Expert Solution
Questions # 48:

A company has AOS-CX switches deployed in a two-tier topology that uses OSPF routing at the core.

You need to prevent ARP poisoning attacks. To meet this need, what is one technology that you could apply to user VLANs on access layer switches? (Select two.)

Options:

A.

ARP inspection

B.

OSPF passive interface

C.

BPDU guard (protection)

D.

DHCPv4 snooping

E.

BPDU filtering

Expert Solution
Questions # 49:

Refer to the exhibit.

How can you use the thumbprint?

Options:

A.

Install this thumbprint on management stations to use as two-factor authentication along with manager usernames and passwords, this will ensure managers connect from valid stations

B.

Copy the thumbprint to other Aruba switches to establish a consistent SSH Key for all switches this will enable managers to connect to the switches securely with less effort

C.

When you first connect to the switch with SSH from a management station, make sure that the thumbprint matches to ensure that a man-in-t he-mid die (MITM) attack is not occurring

D.

install this thumbprint on management stations the stations can then authenticate with the thumbprint instead of admins having to enter usernames and passwords.

Expert Solution
Questions # 50:

What is a benefit of deploying HPE Aruba Networking ClearPass Device Insight?

Options:

A.

Highly accurate endpoint classification for environments with many device types, including Internet of Things (IoT)

B.

Simpler troubleshooting of ClearPass solutions across an environment with multiple ClearPass Policy Managers

C.

Visibility into devices’ 802.1X supplicant settings and automated certificate deployment

D.

Agent-based analysis of devices’ security settings and health status, with the ability to implement quarantining

Expert Solution
Viewing page 5 out of 6 pages
Viewing questions 41-50 out of questions