New Year Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > HP > Aruba Certified Professional - Campus Access > HPE7-A07

HPE7-A07 Aruba Certified Campus Access Mobility Expert Written Exam Question and Answers

Question # 4

A customer is starting to test AAA on their edge switch interfaces. The client device support team is concerned about clients being denied access to the network due to mistakes in configuration or reachability to the authentication servers.

What should be enabled to address the concerns of the client device support team? (Select two)

A.

Configure onboarding-method concurrent

B.

Configure the critical role

C.

Configure auth-mode multi-device

D.

Configure the fallback role

E.

Configure port-access radius-override

Full Access
Question # 5

The ACME company has an AOS-CX 6200 VSF switch slack with an uplink over subscription ratio of 9.6:1. They have indicated that their low-priority TCP traffic has been flagged with a DSCP marking coloring them yellow.

Refer to the exhibit.

They are considering adding two more nodes to the stack without adding any additional uplinks due to existing wiring constraints. One of their architects has suggested adding the following configuration:

What would be the impact of applying the acmethreshold profile as shown? (Select two.)

A.

All upper-layer protocol traffic egressing LAG1 will be subject to drop probability.

B.

All TCP traffic egressing LAG1 wail be subject to drop probability

C.

Only VoIP packets egressing queue 5 on LAG1 will likely be protected from uplink over-utilization.

D.

VoIP packets egressing any queue on LAG1 will more likely be protected from uplink over-utilization

E.

Yellow-flagged TCP traffic egressing LAG1 will be subject to drop probability

Full Access
Question # 6

A customer is installing CX 6300 switches, mobility gateways, and AP-635s.

The customer's VoIP system uses both wired and wireless handsets.

The handsets are configured to mark voice traffic using a DSCP value of 46.

The wireless handsets connect to a bridged SSID using WPA3-SAE.

What will allow the switch to honor the QoS mark set by the handset?

A.

Configure Voice Wi-Fi Multimedia Share for DSCP 46 on the voice SSID

B.

Activate UCC for the HPE Aruba Networking Central Group managing the APs

C.

Enable QoS trust DSCP

D.

Enable WMM on the voice SSID

Full Access
Question # 7

A customer has deployed an AOS 10 mobility gateway cluster consisting of three controllers at a single site The WLAN is configured to tunnel wireless device traffic to the AOS 10 mobility cluster. The clients are authorized to use WPA2-Personal. An end-user has opened a ticket with the helpdesk stating they cannot connect their client device to the network. There are other devices currently associated with the SSID with no issues.

Reviewing the output, what Is the issue?

A.

The RADIUS response from the authentication server is

B.

The client device has an invalid certificate

C.

The client device has an invalid pre-shared key.

D.

transition mode is not enabled

Full Access
Question # 8

Which data transmission method provides the most efficient use of airtime for VoIP traffic?

A.

FDMA

B.

OFDM

C.

MU-MIMO

D.

TWT

Full Access
Question # 9

A university runs its own TV station in the city. The IT department deploys a multimedia server so the TV productions can be sent out to the entire campus over the IP network using multicast-based communications. In order to improve the bandwidth consumption, PIM Sparse Mode and IGMP Snooping features are enabled.

When wireless users join the multicast groups, all users connected to the same WLAN experience poor network performance. However, wired users are not affected in this way. While troubleshooting, the network administrator saves the packet captures shown in the exhibit and concludes that all users, even those not joining the multicast group, receive the same multicast flow at slow speeds.

Which features should the network administrator enable to fix the problem?

A.

ARP broadcast conversion into unicast and Multicast Transmission Optimization

B.

Dynamic Multicast Optimization and UCC QoS correction

C.

Dynamic Multicast Optimization and Multicast Transmission Optimization

D.

UCC QoS correction and Multicast Transmission Optimization

Full Access
Question # 10

What is the recommended configuration to ensure link aggregation is consistent in a campus topology using VSX with two aggregation switches and downlinks to access switches?

A.

Use the command "vsx-sync active-gateways" under the VSX context.

B.

Use a custom LACP hash algorithm for improved load balancing.

C.

Use the command "vsx-sync mclag-interfaces" from the global context.

D.

Use the command "vsx-sync mclag-interfaces" under the VSX context.

Full Access
Question # 11

You are tasked with developing a comprehensive, flexible, and survivable zero-trust wired access network using CX 6300 switching and HPE Aruba Networking ClearPass Policy Manager. Match the scenario to the special roles to achieve your objectives.

Full Access
Question # 12

You are troubleshooting a WLAN deployment with APs and gateways set up with an 802.1X tunneled SSID. End-users are complaining that they can't connect to the enterprise SSID. Which possible AP tunnel states could be the cause of the issue? (Select two.)

A.

SM_STATE_CONNECTING

B.

SM_STATE_SURVIVED

C.

SM_STATE_SURVIVING

D.

SM_STATE_CONNECTED

E.

SM_STATE_REKEYING

Full Access
Question # 13

Refer to the exhibits.

What is the effect when you add the statement neighbor 10.2.0.3 send-community both to the IPv4 address family? (Select two)

A.

It causes R1 to negotiate for the ability to import and export all type-1 and type-2 communities with R2

B.

It causes R1 to allow the exchange of communities with NLRI records in both inbound and outbound directions

C.

It will cause the existing BGP peering between R1 and R2 to bounce

D.

It causes R1 to negotiate the ability to send and receive standard and extended communities with R2

Full Access
Question # 14

You recently added ClearPass as an authentication server to an HPE Aruba Networking Central group. RADIUS authentication with Local User Roles (LUR) works fine Out the same access points cannot use Downloadable User Roles (DUR).

What should he corrected in this configuration to fa the issue with DUR?

A.

Add a new Enforcement Policy of type ‘’WEBAUTH’’ on ClearPass and associate it with the matching service on ClearPass

B.

Add the correct IP addresses or IP subnets of the Network Access Devices (NADs) under the "Devices" tab on ClearPass

C.

Replace the AP's expiree digital certificate using the "crypto pki-import pem serverCert" command.

D.

Add the correct values for "CPPM username" and "CPPM Password" m the authentication server configuration on HPE Aruba Networking Central

Full Access
Question # 15

A customer deployed AP-535s for IoT devices that send many small packets. They want to reduce congestion and allow simultaneous transmission to or from multiple users.

A.

UL MU-MIMO

B.

DL MU-MIMO

C.

HE TXBF

D.

OFDMA

Full Access
Question # 16

Your customer asked for help to apply an ACL for wireless guest users with the following criteria:

• Wi-Fi guests are on VLAN 555

• allow internet access

• only allow access to public DNS servers

• deny access to all internal networks except for any DHCP server

These session ACLs are already present in the CLI of the mobility gateway group:

You have access to the CLl. Which user role meets all the criteria?

A)

B)

C)

D)

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 17

What is the expected behavior for ARP traffic sent from H1?

A.

A2 will send the ARP traffic out of ports 1/1/1 and 1/1/3.

B.

A2 will send the ARP traffic out of ports 1/1/1–1/1/4.

C.

A2 will drop the ARP traffic.

D.

A2 will flood the ARP traffic out of all interfaces.

Full Access
Question # 18

What is me recommended configuration to ensure link aggregation is consistent in a campus topology using VSX with two aggregation switches and downlinks to access switches?

A.

Use a custom LACP hash algorithm for improved load Balancing.

B.

Keep the MTU values at the default setting for GRE and VXLAN communications

C.

Use the command "vsx-sync mclag-interfaces" under the VSX context.

D.

Use the command "vsx-sync active-gateways" under the VSX context.

Full Access
Question # 19

An OSPF router has learned a pain 10 an external network by Doth an E1 and an E2 advertisement Both routes have the same path cost Which path will the router prefer?

A.

The router will prefer the E1 path.

B.

The router will use Doth paths equally utilizing ECMP.

C.

The router will prefer the E2 path.

D.

Both routes will be suppressed until the path conflict has been resolved.

Full Access
Question # 20

A network administrator wants to configure an 802 1X supplicant for a wireless network that includes the following:

1. AES encryption

2. EAP-MSCHAPv2-based user and machine authentication

3. validation of server certificate in Microsoft Windows 10

The network administrator creates a WLAN profile and selects the change connection settings option Then the network administrator changes the security type to Microsoft Protected EAP (PEAP) and enables user and machine authentication under Additional Settings.

What must the network administrator do next to accomplish the task?

A.

Enable user authentication

B.

Change the security type to Microsoft: Smart Card or other certificate.

C.

Change default RC4 encryption for AES

D.

Enable server certificate validation

Full Access
Question # 21

Exhibit.

Which statement is true?

A.

The SSID supports HR-DSSS data rates

B.

The SSID is supports 6 GHz clients.

C.

The SSID supports 802 11ax clients.

D.

The SSID supports 802 11ac clients.

Full Access
Question # 22

A customer with a gateway connected to a device on gigabitethernet 0/0/3 configures an Asset ID TLV on the device for inventory management.

Refer to the exhibit.

The customer mentions the Asset ID is not shown. What is causing the issue?

A.

MTU size is too small.

B.

Unknown TLVs cannot be displayed.

C.

LLDP-MED needs to be enabled.

D.

LLDP TX is not enabled.

Full Access
Question # 23

in a WLAN network with a tunneled SSID. you see the following events in HPE Aruba Networking Central:

The customer asks you to investigate log messages What should you tell them?

A.

This indicates a security issue. The client with a MAC address ending with 37 18;0d Is performing a Denial-of-Service attack on your network. You should track down the client and remove it from the network.

B.

This is normal, expected behavior. No further actions are needed.

C.

This indicates a client WLAN driver issue for the client with a MAC address ending with 37:18

:Od. You should upgrade the client WLAN driver.

D.

There is a roaming issue Enable Fast Roaming 802.11r and OKC to resolve the issue.

Full Access
Question # 24

Your customer’s employees connected to a wired network are complaining about a poor user experience. The customer has UXI sensors deployed on their premises. These sensors nave been running for multiple months. They are testing both the wired network (using the wired Interface of each sensor) and the wireless networks. Your customer used the UXI dashboard to find the reason for the poor user experience to find more details, the customer asked you to check the packet captures that have been downloaded from the sensors using the UXI dashboard.

From the zip file downloaded from the UXI sensors, you checked the "datagrams" .pcap file, but you were not able to find any issues How can you explain this?

A.

The "datagrams- pcap file only contains me successful tests Failed tests are contained in the "datagrams-failed" .pcap file

B.

The UXI sensor could not upload the latest test results to the cloud, so the packet capture is outdated

C.

The datagrams captured on the physical Ethernet interface are in a different .pcap file.

D.

The default filers of the packet captures do not allow tailed tests to be captured by the sensor

Full Access
Question # 25

A customer has deployed an AOS 10 mobility gateway cluster consisting of three controllers at a single site The WLAN is configured to tunnel wireless device traffic to the AOS 10 mobility cluster The clients are authenticated by ClearPass using WPA3-Enterprise (opmode wpa3-aes-ccm-128). The security team has requested the ability to force a wireless device to reauthenticate using ClearPass.

Which steps are required to ensure ClearPass can consistently initiate a change of authorization against an AOS 10 mobility cluster, including during gateway failover scenarios? (Select two)

A.

set cluster mode to Auto Site under High Availability - Cluster configuration

B.

modify WLAN - SSID - VLAN - Mode Configuration

C.

enable manual cluster configuration under High Availability - Cluster Configuration

D.

enable Dynamic Authorization CoA under High Availability - Cluster Configuration

E.

modify NAS IPv4 address under Security - Advanced - RADIUS Client

Full Access
Question # 26

Refer to the exhibit.

Which statement is true?

A.

The client performed passive scanning

B.

The client is using BSS Fast Transition

C.

The client is failing 802.1X authentication

D.

The client used an incorrect passphrase

Full Access
Question # 27

An AOS 10 multi-site deployment has sites with AP-only bridged SSlDs and other sites with APs and gateways operating tunneled SSiDs. Client session state sync errors exist between secure lab environments and public -facing areas at several sites.

What is causing the issues?

A.

The DTLS connections are down between APs in the lab and APs in public areas

B.

The affected clients are associated with an SSID with 11r and 11k disabled.

C.

The sites with issues are the overlay AP with gateway sites because the connection to HPE Aruba Networking central is interrupted

D.

The sites with issues are the AP-only deployments because the connection to HPE Aruba Networking Central is interrupted

Full Access
Question # 28

Match each Group Based Policy (GBP) rote description to its respective role ID.

Full Access
Question # 29

Your customer added third-party USB dongles to the USB ports of their AOS 10 access points. The customer uses AP-615 and AP-635 Each AP is connected with a Cat 6A cable to a CX 6300F Class 4 PoE switch All APs are in the same group in HPE Aruba Networking Central and share the same configuration However, many of the dongles do not come up.

Which option will solve this issue?

A.

Replace the Class a PoE switches with Class 6 PoE switches.

B.

Create two separate service profiles in the loT tab of the Central configuration settings.

C.

Perform a "poe disable" followed by a "poe enable" for the switch ports which connect to the APs so that the APs reboot.

D.

Move the AP-635 access points to a different group in Central to configure the dongles separately from the AP-615.

Full Access
Question # 30

A customer is deploying a new warehouse with AP-634 APs in the united States with mobile devices that can operate in the 6GHz spectrum All testing and RF analyses were performed during the POC using AP-635 APs In a different location During the deployment, they noticed fewer 6GHz channels were broadcasting in the air.

Why would the AP-634 deployment have a lesser amount of broadcasting channels?

A.

The AP-634 APs do not have an advanced subscription.

B.

The AP-634 APs cannot broadcast an 6Gnz channels due to regulatory restrictions.

C.

The AP-635 APs received different allowable 6GHz channels from the AFC service versus the AP-634 APs due to the POC running in a different location.

D.

The AP-634 AP’s persona was configured in the Central group as Standard Power.

Full Access
Question # 31

An OSPF router has learned a path to an external network by both an E1 and an E2 advertisement. Both routes have the same path cost. Which path will the router prefer?

A.

The router will use both paths equally utilizing ECMP.

B.

Both routes will be suppressed until the path conflict has been resolved.

C.

The router will prefer the E1 path.

D.

The router will prefer the E2 path.

Full Access
Question # 32

Which statement is true given the following CLI output from a CX 6300?

A.

The underlay loopback addresses are in the 172 21 11 x range.

B.

There are two anycast addresses m me overlay fabric.

C.

Duplicate MAC addresses were detected in the overlay fabric

D.

There are three active client overlay VLANs in the overlay fabric

Full Access
Question # 33

Exhibit.

Which would explain this issue?

A.

HTTPS wildcard certificates are not supported

B.

HTTPS certificate is not required in ClearPass Guest.

C.

captiveportal-login aruba-training com needs to be entered m the Address field for the ClearPass Guest

D.

".aruba-training com needs to be entered in the Address field for the ClearPass Guest

Full Access
Question # 34

A customer is running out of IP addresses in a network segment. What will happen If they add an additional IPsubnet to the same VLAN?

A.

Broadcasts for me two subnets win arrive on all ports in the same VLAN

B.

IGMP will not work in both of the subnets in the same VLAN

C.

This would result in a single SVI using two subinterfaces.

D.

Users can reach each other and establish PTP traffic without passing an L3 point in the same VLAN

Full Access
Question # 35

In a WLAN network with a tunneled SSID, you see the following events in HPE Aruba Networking Central:

The customer asks you to investigate log messages. What should you tell them?

A.

This indicates a security issue. The client with a MAC address ending with 37:18:0d is performing a Denial-of-Service attack on your network. You should track down the client and remove it from the network

B.

There is a roaming issue. Enable Fast Roaming 802.11r and OKC to resolve the issue

C.

This indicates a client WLAN driver issue for the client with a MAC address ending with 37:18:0d. You should upgrade the client WLAN driver

D.

This is normal, expected behavior. No further actions are needed

Full Access
Question # 36

Exhibit.

What is me expected behavior for ARP traffic sent from H1?

A.

A2 will drop the ARP traffic.

B.

A2 will send the ARP traffic out of ports 1/1/1-1/1/4.

C.

A2 will flood the ARP traffic out of all interfaces.

D.

A2 will send the ARP traffic out of ports 1/1/1 and 1/1/3.

Full Access
Question # 37

Exhibit.

A customer is reporting mat connectivity is Tailing for some wireless client Devices. What are your conclusions from the capture? (Select two.)

A.

The client does not have an ARP entry for me default gateway.

B.

The network is using WPA2-PSK key management.

C.

The network is using WPA3-SAE key management.

D.

The client is not receiving an IP address.

E.

The client does not support beamforming.

Full Access