[2023] HPE6-A78 Actual Exam Dumps, HPE6-A78 Practice Test [Q18-Q42]

Share

[2023] HPE6-A78 Actual Exam Dumps, HPE6-A78 Practice Test

ExamTorrent HPE6-A78 dumps & Aruba ACNSA sure practice dumps


HP HPE6-A78 exam is designed for IT professionals who want to establish their expertise in network security. Aruba Certified Network Security Associate Exam certification is intended for those who are familiar with the fundamental concepts, technologies, and best practices of network security. HPE6-A78 exam measures a candidate's proficiency in implementing secure networks, identifying security threats, and troubleshooting security issues.


The HP HPE6-A78 exam consists of 60 multiple-choice questions and candidates have 90 minutes to complete it. The passing score for the exam is 70%. HPE6-A78 exam is available in multiple languages, including English, Spanish, French, German, Japanese, and Simplified Chinese. It can be taken online or at a Pearson VUE testing center.

 

NEW QUESTION # 18
What is a guideline for creating certificate signing requests (CSRs) and deploying server Certificates on ArubaOS Mobility Controllers (MCs)?

  • A. Generate the private key online, but the public key and CSR offline, to install the same certificate on multiple MCs.
  • B. Create the CSR and public/private keypair offline If you want to install the same certificate on multiple MCs.
  • C. if you create the CSR and public/private Keypair offline, create a matching private key online on the MC.
  • D. Create the CSR online using the MC Web Ul if your company requires you to archive the private key.

Answer: D


NEW QUESTION # 19
What is a guideline for managing local certificates on an ArubaOS-Switch?

  • A. Install an Online Certificate Status Protocol (OCSP) certificate to simplify the process of enrolling and re-enrolling for certificate
  • B. Before installing the local certificate, create a trust anchor (TA) profile with the root CA certificate for the certificate that you will install
  • C. Create a self-signed certificate online on the switch because ArubaOS-Switches do not support CA-signed certificates.
  • D. Generate the certificate signing request (CSR) with a program offline, then, install both the certificate and the private key on the switch in a single file.

Answer: D


NEW QUESTION # 20
What is one practice that can help you to maintain a digital chain or custody In your network?

  • A. Ensure that all network infrastructure devices receive a valid clock using authenticated NTP
  • B. Ensure that all network Infrastructure devices use RADIUS rather than TACACS+ to authenticate managers
  • C. Enable packet capturing on Instant AP or Mobility Controller (MC) control path on an ongoing basis.
  • D. Enable packet capturing on Instant AP or Moodily Controller (MC) datepath on an ongoing basis

Answer: D


NEW QUESTION # 21
You have detected a Rogue AP using the Security Dashboard Which two actions should you take in responding to this event? (Select two)

  • A. There is no need to locate the AP If the Aruba solution is properly configured to automatically contain it.
  • B. There is no need to locale the AP If you manually contain It.
  • C. For forensic purposes, you should copy out logs with relevant information, such as the time mat the AP was detected and the AP's MAC address.
  • D. This is a serious security event, so you should always contain the AP immediately regardless of your company's specific policies.
  • E. You should receive permission before containing an AP. as this action could have legal Implications.

Answer: C,D


NEW QUESTION # 22
A company has an ArubaOS controller-based solution with a WPA3-Enterprise WLAN. which authenticates wireless clients to Aruba ClearPass Policy Manager (CPPM). The company has decided to use digital certificates for authentication A user's Windows domain computer has had certificates installed on it However, the Networks and Connections window shows that authentication has tailed for the user. The Mobility Controllers (MC's) RADIUS events show that it is receiving Access-Rejects for the authentication attempt.
What is one place that you can you look for deeper insight into why this authentication attempt is failing?

  • A. the RADIUS events within the CPPM Event Viewer
  • B. the packets captured on the MC control plane destined to UDP 1812
  • C. the reports generated by Aruba ClearPass Insight
  • D. the Alerts tab in the authentication record in CPPM Access Tracker

Answer: D


NEW QUESTION # 23
An ArubaOS-CX switch enforces 802.1X on a port. No fan-through options or port-access roles are configured on the port The 802 1X supplicant on a connected client has not yet completed authentication Which type of traffic does the authenticator accept from the client?

  • A. RADIUS only
  • B. DHCP, DNS, and EAP only
  • C. EAP only
  • D. DHCP, DNS and RADIUS only

Answer: C


NEW QUESTION # 24
What are the roles of 802.1X authenticators and authentication servers?

  • A. The authenticator stores the user account database, while the server stores access policies.
  • B. The authenticator is a RADIUS client and the authentication server is a RADIUS server.
  • C. The authenticator makes access decisions and the server communicates them to the supplicant.
  • D. The authenticator supports only EAP, while the authentication server supports only RADIUS.

Answer: C


NEW QUESTION # 25
You are troubleshooting an authentication issue for Aruba switches that enforce 802 IX10 a cluster of Aruba ClearPass Policy Manager (CPPMs) You know that CPPM Is receiving and processing the authentication requests because the Aruba switches are showing Access-Rejects in their statistics However, you cannot find the record tor the Access-Rejects in CPPM Access Tracker What is something you can do to look for the records?

  • A. Go to the CPPM Event Viewer, because this is where RADIUS Access Rejects are stored.
  • B. Verify that you are logged in to the CPPM Ul with read-write, not read-only, access
  • C. Make sure that CPPM cluster settings are configured to show Access-Rejects
  • D. Click Edit in Access viewer and make sure that the correct servers are selected.

Answer: C


NEW QUESTION # 26
Your Aruba Mobility Master-based solution has detected a rogue AP Among other information the ArubaOS Detected Radios page lists this Information for the AP SSID = PubllcWiFI BSSID = a8M27 12 34:56 Match method = Exact match Match type = Eth-GW-wired-Mac-Table The security team asks you to explain why this AP is classified as a rogue. What should you explain?

  • A. The ap has a BSSID mat matches authorized client MAC addresses. This indicates that the AP is spoofing the MAC address to gam unauthorized access to your company's wireless services, so It is a rogue
  • B. The AP is spoofing a routers MAC address as its BSSID. This indicates mat, even though WIP cannot determine whether the AP is connected to your LAN. it is a rogue.
  • C. The AP Is connected to your LAN because It is transmitting wireless traffic with your network's default gateway's MAC address as a source MAC Because it does not belong to the company, it is a rogue
  • D. The AP has been detected as launching a DoS attack against your company's default gateway. This qualities it as a rogue which needs to be contained with wireless association frames immediately

Answer: B


NEW QUESTION # 27
Your ArubaoS solution has detected a rogue AP with Wireless intrusion Prevention (WIP). Which information about the detected radio can best help you to locate the rogue device?

  • A. the confidence level
  • B. the match type
  • C. the detecting devices
  • D. the match method

Answer: D


NEW QUESTION # 28
You configure an ArubaOS-Switch to enforce 802.1X authentication with ClearPass Policy Manager (CPPM) denned as the RADIUS server Clients cannot authenticate You check Aruba ClearPass Access Tracker and cannot find a record of the authentication attempt.
What are two possible problems that have this symptom? (Select two)

  • A. Clients are not configured to trust the root CA certificate for CPPM's RADIUS/EAP certificate.
  • B. Clients are configured to use a mismatched EAP method from the one In the CPPM service.
  • C. CPPM does not have a network device defined for the switch's IP address.
  • D. users are logging in with the wrong usernames and passwords or invalid certificates.
  • E. The RADIUS shared secret does not match between the switch and CPPM.

Answer: A,D


NEW QUESTION # 29
You have been asked to rind logs related to port authentication on an ArubaOS-CX switch for events logged in the past several hours But. you are having trouble searching through the logs What is one approach that you can take to find the relevant logs?

  • A. Specify a logging facility that selects for "port-access" messages.
  • B. Enable debugging for "portaccess" to move the relevant logs to a buffer.
  • C. Configure a logging Tiller for the "port-access" category, and apply that filter globally.
  • D. Add the "-C and *-c port-access" options to the "show logging" command.

Answer: D


NEW QUESTION # 30
What is a difference between radius and TACACS+?

  • A. RADIUS combines the authentication and authorization process while TACACS+ separates them.
  • B. RADIUS uses TCP for Its connection protocol, while TACACS+ uses UDP tor its connection protocol.
  • C. RADIUS uses Attribute Value Pairs (AVPs) in its messages, while TACACS+ does not use them.
  • D. RADIUS encrypts the complete packet, white TACACS+ only offers partial encryption.

Answer: A


NEW QUESTION # 31
You are deploying an Aruba Mobility Controller (MC). What is a best practice for setting up secure management access to the ArubaOS Web UP

  • A. Change the default 4343 port tor the web UI to TCP 443.
  • B. Install a CA-signed certificate to use for the Web UI server certificate.
  • C. Avoid using external manager authentication tor the Web UI.
  • D. Make sure to enable HTTPS for the Web UI and select the self-signed certificate Installed in the factory.

Answer: B


NEW QUESTION # 32
From which solution can ClearPass Policy Manager (CPPM) receive detailed information about client device type OS and status?

  • A. ClearPass Guest
  • B. ClearPass Onboard
  • C. ClearPass Access Tracker
  • D. ClearPass OnGuard

Answer: D


NEW QUESTION # 33
Which attack is an example or social engineering?

  • A. A hacker eavesdrops on insecure communications, such as Remote Desktop Program (RDP). and discovers login credentials.
  • B. An email Is used to impersonate a Dank and trick users into entering their bank login information on a fake website page.
  • C. A user visits a website and downloads a file that contains a worm, which sell-replicates throughout the network.
  • D. An attack exploits an operating system vulnerability and locks out users until they pay the ransom.

Answer: B


NEW QUESTION # 34
You have an Aruba Mobility Controller (MC). for which you are already using Aruba ClearPass Policy Manager (CPPM) to authenticate access to the Web Ul with usernames and passwords You now want to enable managers to use certificates to log in to the Web Ul CPPM will continue to act as the external server to check the names in managers' certificates and tell the MC the managers' correct rote in addition to enabling certificate authentication. what is a step that you should complete on the MC?

  • A. Create a local admin account mat uses certificates in the account, specify the correct trusted CA certificate and external authentication
  • B. Verify that the MC trusts CPPM's HTTPS certificate by uploading a trusted CA certificate Also, configure a CPPM username and password on the MC
  • C. install all of the managers' certificates on the MC as OCSP Responder certificates
  • D. Verify that the MC has the correct certificates, and add RadSec to the RADIUS server configuration for CPPM

Answer: D


NEW QUESTION # 35
What is one of the roles of the network access server (NAS) in the AAA framewonx?

  • A. It negotiates with each user's device to determine which EAP method is used for authentication
  • B. It determines which resources authenticated users are allowed to access and monitors each users session
  • C. It authenticates legitimate users and uses policies to determine which resources each user is allowed to access.
  • D. It enforces access to network services and sends accounting information to the AAA server

Answer: C


NEW QUESTION # 36
What are some functions of an AruDaOS user role?

  • A. The role determines which firewall policies and bandwidth contract apply to the clients traffic
  • B. The role determines which wireless networks (SSiDs) a user is permitted to access
  • C. The role determines which authentication methods the user must pass to gain network access
  • D. The role determines which control plane ACL rules apply to the client's traffic

Answer: C


NEW QUESTION # 37
You are managing an Aruba Mobility Controller (MC). What is a reason for adding a "Log Settings" definition in the ArubaOS Diagnostics > System > Log Settings page?

  • A. Configuring the log facility and log format that the MC will use for forwarding logs to all Syslog servers
  • B. Configuring the Syslog server settings for the server to which the MC forwards logs for a particular category and level
  • C. Configuring the MC to generate logs for a particular event category and level, but only for a specific user or AP.
  • D. Configuring a filter that you can apply to a defined Syslog server in order to filter events by subcategory

Answer: B


NEW QUESTION # 38
What correctly describes the Pairwise Master Key (PMK) in thee specified wireless security protocol?

  • A. In WPA3-Personal, the PMK is derived directly from the passphrase and is the same tor every session.
  • B. In WPA3-Personal, the PMK is unique per session and derived using Simultaneous Authentication of Equals.
  • C. In WPA3-Personal, the PMK is the same for each session and is communicated to clients that authenticate
  • D. In WPA3-Enterprise, the PMK is unique per session and derived using Simultaneous Authentication of Equals.

Answer: D


NEW QUESTION # 39
You need to deploy an Aruba instant AP where users can physically reach It. What are two recommended options for enhancing security for management access to the AP? (Select two )

  • A. Disable Its console ports
  • B. Disable the Web Ul.
  • C. install a CA-signed certificate
  • D. Configure WPA3-Enterpnse security on the AP
  • E. Place a Tamper Evident Label (TELS) over its console port

Answer: C,E


NEW QUESTION # 40
What is a benefit of Opportunistic Wireless Encryption (OWE)?

  • A. It provides protection for wireless clients against both honeypot APs and man-in-the-middle (MUM) attacks
  • B. It allows anyone lo connect, but provides better protection against eavesdropping than a traditional open network
  • C. It allows both WPA2-capabie and WPA3-capable clients to authenticate to the same WPA-Personal WLAN
  • D. It offers more control over who can connect to the wireless network when compared with WPA2-Personal

Answer: B


NEW QUESTION # 41
What is a Key feature of me ArubaOS firewall?

  • A. The firewall is designed to fitter traffic primarily based on wireless 802.11 headers, making it ideal for mobility environments
  • B. The firewall Includes application layer gateways (ALGs). which it uses to filter Web traffic based on the reputation of the destination web site.
  • C. The firewall examines all traffic at Layer 2 through Layer 4 and uses source IP addresses as the primary way to determine how to control traffic.
  • D. The firewall is stateful which means that n can track client sessions and automatically allow return traffic for permitted sessions

Answer: B


NEW QUESTION # 42
......

HPE6-A78 Actual Questions and Braindumps: https://pass4sure.examtorrent.com/HPE6-A78-prep4sure-dumps.html