Pass HP HPE6-A78 PDF Dumps | Recently Updated 62 Questions
Updated Test Engine to Practice HPE6-A78 Dumps & Practice Exam
NEW QUESTION # 16
How should admins deal with vulnerabilities that they find in their systems?
- A. They should apply fixes, such as patches, to close the vulnerability before a hacker exploits it.
- B. They should classify the vulnerability as malware. a DoS attack or a phishing attack.
- C. They should notify the security team as soon as possible that the network has already been breached.
- D. They should add the vulnerability to their Common Vulnerabilities and Exposures (CVE).
Answer: A
NEW QUESTION # 17
Refer to the exhibit.
You are deploying a new ArubaOS Mobility Controller (MC), which is enforcing authentication to Aruba ClearPass Policy Manager (CPPM). The authentication is not working correctly, and you find the error shown In the exhibit in the CPPM Event Viewer.
What should you check?
- A. that the snared secret configured for the CPPM authentication server matches the one defined for the device on CPPM
- B. that the MC has valid admin credentials configured on it for logging into the CPPM
- C. that the IP address that the MC is using to reach CPPM matches the one defined for the device on CPPM
- D. that the MC has been added as a domain machine on the Active Directory domain with which CPPM is synchronized
Answer: C
NEW QUESTION # 18
What is a benefit of Opportunistic Wireless Encryption (OWE)?
- A. It provides protection for wireless clients against both honeypot APs and man-in-the-middle (MUM) attacks
- B. It allows anyone lo connect, but provides better protection against eavesdropping than a traditional open network
- C. It offers more control over who can connect to the wireless network when compared with WPA2-Personal
- D. It allows both WPA2-capabie and WPA3-capable clients to authenticate to the same WPA-Personal WLAN
Answer: B
NEW QUESTION # 19
What is an Authorized client as defined by ArubaOS Wireless Intrusion Prevention System (WIP)?
- A. a client that has a certificate issued by a trusted Certification Authority (CA)
- B. a client that has successfully authenticated to an authorized AP and passed encrypted traffic
- C. a client that is not on the WIP blacklist
- D. a client that is on the WIP whitelist.
Answer: B
NEW QUESTION # 20
What is a difference between radius and TACACS+?
- A. RADIUS uses TCP for Its connection protocol, while TACACS+ uses UDP tor its connection protocol.
- B. RADIUS encrypts the complete packet, white TACACS+ only offers partial encryption.
- C. RADIUS combines the authentication and authorization process while TACACS+ separates them.
- D. RADIUS uses Attribute Value Pairs (AVPs) in its messages, while TACACS+ does not use them.
Answer: C
NEW QUESTION # 21
What is one way that Control Plane Security (CPsec) enhances security for me network?
- A. It prevents access from unauthorized IP addresses to critical services, such as SSH on Mobility Controllers (MCs).
- B. It protects wireless clients' traffic tunneled between APs and Mobility Controllers, from eavesdropping
- C. It protects management traffic between APs and Mobility Controllers (MCs) from eavesdropping.
- D. It prevents Denial of Service (DoS) attacks against Mobility Controllers' (MCs") control plane.
Answer: B
NEW QUESTION # 22
You have an Aruba Mobility Controller (MC). for which you are already using Aruba ClearPass Policy Manager (CPPM) to authenticate access to the Web Ul with usernames and passwords You now want to enable managers to use certificates to log in to the Web Ul CPPM will continue to act as the external server to check the names in managers' certificates and tell the MC the managers' correct rote in addition to enabling certificate authentication. what is a step that you should complete on the MC?
- A. Create a local admin account mat uses certificates in the account, specify the correct trusted CA certificate and external authentication
- B. install all of the managers' certificates on the MC as OCSP Responder certificates
- C. Verify that the MC trusts CPPM's HTTPS certificate by uploading a trusted CA certificate Also, configure a CPPM username and password on the MC
- D. Verify that the MC has the correct certificates, and add RadSec to the RADIUS server configuration for CPPM
Answer: D
NEW QUESTION # 23
A company has Aruba Mobility Controllers (MCs). Aruba campus APs. and ArubaOS-CX switches. The company plans to use ClearPass Policy Manager (CPPM) to classify endpoints by type The ClearPass admins tell you that they want to run Network scans as part of the solution What should you do to configure the infrastructure to support the scans?
- A. Create a TA profile on the ArubaOS-Switches with the root CA certificate for ClearPass's HTTPS certificate
- B. Create SNMPv3 users on ArubaOS-CX switches, and make sure that the credentials match those configured on CPPM
- C. Create device fingerprinting profiles on the ArubaOS-Switches that include SNMP. and apply the profiles to edge ports
- D. Create remote mirrors on the ArubaOS-Swrtches that collect traffic on edge ports, and mirror it to CPPM's IP address.
Answer: C
NEW QUESTION # 24
You have deployed a new Aruba Mobility Controller (MC) and campus APs (CAPs). One of the WLANs enforces 802.IX authentication lo Aruba ClearPass Policy Manager {CPPM) When you test connecting the client to the WLAN. the test falls You check Aruba ClearPass Access Tracker and cannot find a record of the authentication attempt You ping from the MC to CPPM. and the ping is successful.
What is a good next step for troubleshooting?
- A. Reset the user credentials
- B. Renew CPPM's RADIUS/EAP certificate
- C. Check CPPM Event viewer.
- D. Check connectivity between CPPM and a backend directory server
Answer: C
NEW QUESTION # 25
An ArubaOS-CX switch enforces 802.1X on a port. No fan-through options or port-access roles are configured on the port The 802 1X supplicant on a connected client has not yet completed authentication Which type of traffic does the authenticator accept from the client?
- A. DHCP, DNS and RADIUS only
- B. EAP only
- C. RADIUS only
- D. DHCP, DNS, and EAP only
Answer: B
NEW QUESTION # 26
What distinguishes a Distributed Denial of Service (DDoS) attack from a traditional Denial or service attack (DoS)?
- A. A DoS attack targets one server, a DDoS attack targets all the clients that use a server
- B. A DDoS attack targets multiple devices, while a DoS Is designed to Incapacitate only one device
- C. A DDoS attack originates from external devices, while a DoS attack originates from internal devices
- D. A DDoS attack is launched from multiple devices, while a DoS attack is launched from a single device
Answer: C
NEW QUESTION # 27
Refer to the exhibit.
You need to ensure that only management stations in subnet 192.168.1.0/24 can access the ArubaOS-Switches' CLI. Web Ul. and REST interfaces The company also wants to let managers use these stations to access other parts of the network What should you do?
- A. Specify vlan 100 as the management vlan for the switches.
- B. Specify 192.168.1.0.255.255.255.0 as authorized IP manager address
- C. Configure the switch to listen for these protocols on OOBM only.
- D. Establish a Control Plane Policing class that selects traffic from 192.168 1.0/24.
Answer: D
NEW QUESTION # 28
What is a vulnerability of an unauthenticated Dime-Heliman exchange?
- A. Diffie-Hellman with elliptic curve values is no longer considered secure in modem networks, based on NIST recommendations.
- B. Participants must agree on a passphrase in advance, which can limit the usefulness of Diffie- Hell man in practical contexts.
- C. A hacker can replace the public values exchanged by the legitimate peers and launch an MITM attack.
- D. A brute force attack can relatively quickly derive Diffie-Hellman private values if they are able to obtain public values
Answer: C
NEW QUESTION # 29
You are deploying an Aruba Mobility Controller (MC). What is a best practice for setting up secure management access to the ArubaOS Web UP
- A. Make sure to enable HTTPS for the Web UI and select the self-signed certificate Installed in the factory.
- B. Install a CA-signed certificate to use for the Web UI server certificate.
- C. Avoid using external manager authentication tor the Web UI.
- D. Change the default 4343 port tor the web UI to TCP 443.
Answer: B
NEW QUESTION # 30
Refer to the exhibit.
This Aruba Mobility Controller (MC) should authenticate managers who access the Web Ul to ClearPass Policy Manager (CPPM) ClearPass admins have asked you to use RADIUS and explained that the MC should accept managers' roles in Aruba-Admin-Role VSAs Which setting should you change to follow Aruba best security practices?
- A. Change the local user role to read-only
- B. Disable local authentication
- C. Clear the MSCHAP check box
- D. Change the default role to "guest-provisioning"
Answer: D
NEW QUESTION # 31
Refer to the exhibit.
A diem is connected to an ArubaOS Mobility Controller. The exhibit snows all Tour firewall rules that apply to this diem What correctly describes how the controller treats HTTPS packets to these two IP addresses, both of which are on the other side of the firewall
10.1 10.10
203.0.13.5
- A. it permits both of the packets
- B. It drops the packet to 10.1.10.10 and permits the packet to 203.0.13.5.
- C. It drops both of the packets
- D. It permits the packet to 10.1.10.10 and drops the packet to 203 0.13.5
Answer: A
NEW QUESTION # 32
A company has an ArubaOS controller-based solution with a WPA3-Enterprise WLAN. which authenticates wireless clients to Aruba ClearPass Policy Manager (CPPM). The company has decided to use digital certificates for authentication A user's Windows domain computer has had certificates installed on it However, the Networks and Connections window shows that authentication has tailed for the user. The Mobility Controllers (MC's) RADIUS events show that it is receiving Access-Rejects for the authentication attempt.
What is one place that you can you look for deeper insight into why this authentication attempt is failing?
- A. the RADIUS events within the CPPM Event Viewer
- B. the reports generated by Aruba ClearPass Insight
- C. the Alerts tab in the authentication record in CPPM Access Tracker
- D. the packets captured on the MC control plane destined to UDP 1812
Answer: C
NEW QUESTION # 33
A company is deploying ArubaOS-CX switches to support 135 employees, which will tunnel client traffic to an Aruba Mobility Controller (MC) for the MC to apply firewall policies and deep packet inspection (DPI).
This MC will be dedicated to receiving traffic from the ArubaOS-CX switches.
What are the licensing requirements for the MC?
- A. one AP license per-switch
- B. one AP license per-switch. and one PEF license per-switch
- C. one PEF license per-switch
- D. one PEF license per-switch. and one WCC license per-switch
Answer: B
NEW QUESTION # 34
What is one difference between EAP-Tunneled Layer security (EAP-TLS) and Protected EAP (PEAP)?
- A. EAP-TLS begins with the establishment of a TLS tunnel, but PEAP does not use a TLS tunnel as part of Its process
- B. EAP-TLS requires the supplicant to authenticate with a certificate, hut PEAP allows the supplicant to use a username and password.
- C. EAP-TLS creates a TLS tunnel for transmitting user credentials, while PEAP authenticates the server and supplicant during a TLS handshake.
- D. EAP-TLS creates a TLS tunnel for transmitting user credentials securely while PEAP protects user credentials with TKIP encryption.
Answer: B
NEW QUESTION # 35
What is a benefit or Protected Management Frames (PMF). sometimes called Management Frame Protection (MFP)?
- A. PMF helps to protect APs and MCs from unauthorized management access by hackers.
- B. PMF prevents hackers from capturing the traffic between APs and Mobility Controllers.
- C. PMF ensures trial traffic between APs and Mobility Controllers (MCs) is encrypted.
- D. PMF protects clients from DoS attacks based on forged de-authentication frames
Answer: A
NEW QUESTION # 36
What are the roles of 802.1X authenticators and authentication servers?
- A. The authenticator stores the user account database, while the server stores access policies.
- B. The authenticator is a RADIUS client and the authentication server is a RADIUS server.
- C. The authenticator supports only EAP, while the authentication server supports only RADIUS.
- D. The authenticator makes access decisions and the server communicates them to the supplicant.
Answer: D
NEW QUESTION # 37
You have been instructed to look in the ArubaOS Security Dashboard's client list Your goal is to find clients mat belong to the company and have connected to devices that might belong to hackers Which client fits this description?
- A. MAC address d8:50:e6:f3;6e;60; Client Classification Interfering. AP Classification Interfering
- B. MAC address d8:50:e6:f3;TO;ab; Client Classification Interfering. AP Classification Rogue
- C. MAC address d8:50:e6 f3;6e;c5; Client Classification Interfering. AP Classification Neighbor
- D. MAC address d8:50:e6:f3;6d;a4; Client Classification Authorized; AP Classification, interfering
Answer: A
NEW QUESTION # 38
How does the ArubaOS firewall determine which rules to apply to a specific client's traffic?
- A. The firewall applies the rules in policies associated with the client's wlan
- B. The firewall applies every rule that includes the dent's IP address as the source.
- C. The firewall applies every rule that includes the client's IP address as the source or destination.
- D. The firewall applies thee rules in policies associated with the client's user role.
Answer: B
NEW QUESTION # 39
What is a correct guideline for the management protocols that you should use on ArubaOS-Switches?
- A. Disable Telnet and use SSH instead
- B. Disable Telnet and use TFTP instead.
- C. Disable SSH and use https instead.
- D. Disable HTTPS and use SSH instead
Answer: C
NEW QUESTION # 40
......
HP HPE6-A78 Dumps Cover Real Exam Questions: https://www.examstorrent.com/HPE6-A78-exam-dumps-torrent.html
Dumps Collection HPE6-A78 Test Engine Dumps Training With 62 Questions: https://drive.google.com/open?id=1EnDiGfl0OpyPg7j5d0GU7rET3fUKV7GU