Winter Sale - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

Free and Premium HP HPE7-A07 Dumps Questions Answers

Page: 1 / 9
Total 126 questions

Aruba Certified Campus Access Mobility Expert Written Exam Questions and Answers

Question 1

A customer has deployed an AOS 10 mobility gateway cluster consisting of three controllers at a single site The WLAN is configured to tunnel wireless device traffic to the AOS 10 mobility cluster. The clients are authorized to use WPA2-Personal. An end-user has opened a ticket with the helpdesk stating they cannot connect their client device to the network. There are other devices currently associated with the SSID with no issues.

Reviewing the output, what Is the issue?

Options:

A.

The RADIUS response from the authentication server is

B.

The client device has an invalid certificate

C.

The client device has an invalid pre-shared key.

D.

transition mode is not enabled

Buy Now
Question 2

You created a new SSID with the security settings shown in the exhibit.

Some, but not all users complain that client devices are unable to connect to this SS1D. What is the reason for this?

Options:

A.

The WPA3 Enterprise GCM-2S6 mode does not support transition mode.

B.

WPA3 Enterprise is not backward compatible with WPA2 Enterprise.

C.

MAC authentication after a failed 802. ix authentication is not possible as the option "MAC Authentication Fall-Through" is disabled.

D.

The primary servers shared key differs from the shared key configured for this server on HPE Aruba Networking Central.

Question 3

A customer is evaluating device profiles on a CX 6300 switch. The test device has the following attribute:

• MAC address=81:cd:93:13:ab:31

The test device needs to be assigned the "lot-prod'' role, in addition the "lot-default" role must be applied for any other device connected lo interface 1/1/1. This is a lab environment with no configuration of any external authentication server for the test.

Given the configuration example, what is required to meet this testing requirement?

Options:

A.

Enter the command "pot-access device-profile mode block-until-profile-applied"" for interface 1/1/1.

B.

Enter the command "port-access fallback-role lot-default globally

C.

Enter the command "port-access onboarding-method precedence" to set device profiles with a lower precedence.

D.

Enter the command "port-access device-profile mode block-until-profile-applied" globally.

Question 4

The wireless administrator for a college campus is gelling reports of connectivity issues when students are working outdoors.

Reviewing the settings above, watch change is needed to align with best practices?

Options:

A.

Disable 802 11r.

B.

Disable 802 11k.

C.

increase 5Gnz TX power range Min/Max.

D.

increase 5 GHz wireless coverage tuning to Aggressive.

Question 5

Exhibit.

What is me expected behavior for ARP traffic sent from H1?

Options:

A.

A2 will drop the ARP traffic.

B.

A2 will send the ARP traffic out of ports 1/1/1-1/1/4.

C.

A2 will flood the ARP traffic out of all interfaces.

D.

A2 will send the ARP traffic out of ports 1/1/1 and 1/1/3.

Question 6

You are testing the use of the automated port-access role configuration process using RadSec authentication over VXLAN. During your testing you observed that the RadSec connection will fan during the digital certificate exchange

What would be the cause of this Issue?

Options:

A.

The RadSec server was defined on the switch using an IPv6 address that was unreachable

B.

Tracking mode was set to "dead-only", and the RadSec server was marked as unreachable.

C.

The switch is configured to establish a TLS connection with a proxy server, not the radius server.

D.

The RADIUS TCP packets are Being dropped and the TLS tunnel is not established.

Question 7

Your customer’s employees connected to a wired network are complaining about a poor user experience. The customer has HPE Aruba Networking User Experience Insight (UXI) sensors deployed on their premises. These sensors have been running for multiple months. They are testing both the wired network (using the wired interface of each sensor) and the wireless networks. Your customer used the UXI dashboard to find the reason for the poor user experience. To find more details, the customer asked you to check the packet captures that have been downloaded from the sensors using the UXI dashboard.

From the .zip file downloaded from the UXI sensors, you checked the "datagrams" .pcap file, but you were not able to find any issues. How can you explain this?

Options:

A.

The default filters of the packet captures do not allow failed tests to be captured by the sensor.

B.

The "datagrams" .pcap file only contains the successful tests. Failed tests are contained in the "datagrams-failed" .pcap file.

C.

The datagrams captured on the physical Ethernet interface are in a different .pcap file.

D.

The UXI sensor could not upload the latest test results to the cloud, so the packet capture is outdated.

Question 8

Which statement is true given the following CLI output from a CX 6300?

Options:

A.

The underlay loopback addresses are in the 172 21 11 x range.

B.

There are two anycast addresses m me overlay fabric.

C.

Duplicate MAC addresses were detected in the overlay fabric

D.

There are three active client overlay VLANs in the overlay fabric

Question 9

A customer is evaluating device profiles on a CX 6300 switch. The test device has the following attribute:

    MAC address = 81:cd:93:13:ab:31

The test device needs to be assigned the "iot-prod" role. In addition, the "iot-default" role must be applied for any other device connected to interface 1/1/1.

This is a lab environment with no configuration of any external authentication server for the test.

Given the configuration example, what is required to meet this testing requirement?

Options:

A.

Enter the command port-access onboarding-method precedence to set device profiles with a higher precedence

B.

Enter the command port-access device-profile mode block-until-profile-applied globally

C.

Enter the command port-access fallback-role iot-default globally

D.

Enter the command port-access onboarding-method precedence to set device profiles with a lower precedence

Question 10

Exhibit.

A network administrator attempts to improve multicast traffic flow and performs some packet captures for validation What can the network administrator conclude from the results?

Options:

A.

The data rate increased from 6 Mops to 300 Mops because Broadcast Multicast optimization (BCMCO) was configured.

B.

The capture taken after optimization does not show a packet length because Multicast Transmission Optimization was configured.

C.

The type flew remains consistent because Dynamic Multicast Optimization (DMO) was configured.

D.

The data rate increased from 6 Mbps to 300 Mops because Dynamic Multicast Optimization (DMO) was configured.

Question 11

An administrator is creating a fabric with NetConductor in HPE Aruba Networking Central Considering an EVPN VXLAN fabric, click on the most appropriate layer to be configured as a Rome-Reflector Persona.

Options:

Question 12

A BGP routing table contains multiple routes to the same destination prefix.

Referring to the table below which route would be marked with a ">" symbol?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

E.

Option E

Question 13

A university owns a campus with several buildings segmented into east and west wings, which are L3 separated. The east wing has 1600 APs. and the west wing has 1200 Aps. Each wing has a single gateway cluster managed by HPE Aruba Networking Central. Each cluster contains one 7210 mobility gateway The gateways are configured with DHCP relay and route all client VLANs. A new business-critical faculty real-time application requires users to roam within wings but not across wings without disconnections or delay increments.

Which changes must the network administrator make lo successfully meet the requirement without performance degradation matching best practices? (Select two.)

Options:

A.

Replace the 7210 mobility gateway in the west wing with a pair of 7030 mobility gateways.

B.

Add a single 7210 mobility gateway to each cluster.

C.

Remove the DHCP relay from the gateways and enable the DHCP server instead

D.

Replace me 7210 mobility gateway in the east wing with a pair or 9012 mobility gateways

E.

Run L2 for all SSIDs and permit the users' VLANs in the gateway's uplinks.

Question 14

Exhibit.

Which statement is true?

Options:

A.

The SSID supports HR-DSSS data rates

B.

The SSID is supports 6 GHz clients.

C.

The SSID supports 802 11ax clients.

D.

The SSID supports 802 11ac clients.

Question 15

Match each Group Based Policy (GBP) rote description to its respective role ID.

Options:

Question 16

What should be defined on the Edge-1 to establish valid BGP routing between agg-sw1 and agg-sw2 using BGP protocol using the IP addresses above?

Options:

A.

OPTION A

B.

OPTION B

C.

OPTION C

D.

OPTION D

Question 17

You are troubleshooting a WLAN deployment with APs and gateways set up with an 802.1X tunneled SSID. End-users are complaining that they can't connect to the enterprise SSID. Which possible AP tunnel states could be the cause of the issue? (Select two.)

Options:

A.

SM_STATE_CONNECTING

B.

SM_STATE_SURVIVED

C.

SM_STATE_SURVIVING

D.

SM_STATE_CONNECTED

E.

SM_STATE_REKEYING

Question 18

You configured a WPA3-SAE with the following MAC Authentication Role Mapping in Cloud Authentication and Policy:

With further default settings assume a new Android phone is connected to the network. Which role will the client be assigned after connecting for the first time?

Options:

A.

byod

B.

client will be rejected network access

C.

lot-local

D.

unmatched-device

Question 19

A customer is experiencing authentication failures when clients connect to a new EAP-TLS SSID.

Based on the logs and packet capture above, what is the cause of the failure?

Options:

A.

The client cannot validate the RADIUS server's certificate

B.

The MTU in the path between the AP and HPE Aruba Networking ClearPass is too small

C.

HPE Aruba Networking ClearPass cannot validate the user's certificate

D.

The access point doesn't have the correct root CA certificate installed

Question 20

A client connecting to a tunneled open network is receiving the wrong VLAN Your customer has a gateway and has sent over a packet capture from a switch port mirror taken from the upstream switch with a packet capture from the IPsec tunnel and the GRE tunnel to help Identify the VLAN being sent from the controller to the AP.

Where will you see the VLAN assignment?

Options:

A.

The GRE tunnel will include the VLAN lag assignment

B.

VLAN tag assignment win not he captured in any of the packet captures

C.

IPsec tunnel will include the VLAN tag assignment

D.

VLAN tag assignment win be included in the port mirror

Question 21

In a WLAN network with a tunneled SSID, you see the following events in HPE Aruba Networking Central:

The customer asks you to investigate log messages. What should you tell them?

Options:

A.

This indicates a security issue. The client with a MAC address ending with 37:18:0d is performing a Denial-of-Service attack on your network. You should track down the client and remove it from the network

B.

There is a roaming issue. Enable Fast Roaming 802.11r and OKC to resolve the issue

C.

This indicates a client WLAN driver issue for the client with a MAC address ending with 37:18:0d. You should upgrade the client WLAN driver

D.

This is normal, expected behavior. No further actions are needed

Question 22

An engineer has applied the above configuration to R1 and R2. However, the router's OSPF adjacency never progresses past the "EXSTART/DR" state.

Which configuration action on either router will allow R1 and R2 to progress past the "EXSTART/DR" state?

Options:

A.

Change R1 and R2 to a network type of point-to-point

B.

Ensure the OSPF process is not configured with passive-interface default

C.

Change the IP address and mask applied to interface 1/1/1

D.

Remove the layer 3 MTU configuration

Question 23

Exhibit.

Which wireless connection phase has Just been completed?

Options:

A.

MAC Authentication and 4-way handshake

B.

L3 authentication and encryption

C.

802.11 enhanced open association

D.

L2 authentication and encryption

Question 24

You have been tasked to ensure that audit logs on mobility gateways contain accurate timestamps, keeping security in mind. Which configuration change would best secure the time clock against attacks?

Options:

A.

Modify the ACL AllowList to deny NTP

B.

Turn on Use NTP authentication toggle and set the parameters

C.

Use an ACL in the communication path

D.

Modify the audit log timezone to match the mobility gateways

Question 25

Exhibit.

Which user role will be assigned when a voice client tries to connect for the first time, but the RADIUS server is unavailable?

Options:

A.

CRITICAl_AUTH

B.

DEFAULT_AUTH

C.

CRIT1CAL_V0ICE

D.

PRE_AUTH

Question 26

Your customer added third-party USB dongles to the USB ports of their AOS 10 access points. The customer uses AP-615 and AP-635 Each AP is connected with a Cat 6A cable to a CX 6300F Class 4 PoE switch All APs are in the same group in HPE Aruba Networking Central and share the same configuration However, many of the dongles do not come up.

Which option will solve this issue?

Options:

A.

Replace the Class a PoE switches with Class 6 PoE switches.

B.

Create two separate service profiles in the loT tab of the Central configuration settings.

C.

Perform a "poe disable" followed by a "poe enable" for the switch ports which connect to the APs so that the APs reboot.

D.

Move the AP-635 access points to a different group in Central to configure the dongles separately from the AP-615.

Question 27

A customer wan a gateway connected to a device on gigabitethernet 0/0/3 configures an Asset ID TLV on the device for inventory management.

Exhibit.

The customer mentions me Asset ID is not shown What is causing the issue?

Options:

A.

LLDP TX is not enabled.

B.

LLPD-MED needs to be enabled.

C.

MTU size is too small.

D.

Unknown TLVs cannot be displayed.

Question 28

An ACME company employee complained about a recent poor-quality VoIP call while moving around their office environment HPE Aruba Networking Central reported a fair UCC score for this call while your VoIP engineer reported that their systems reported a MOS of 2, 3. The VoIP devices are operating over the 5GHz frequency band.

What are the possible contributing factors? (Select two.)

Options:

A.

Coverage AP deployment plans generally don't support enough cell overlap for VoIP.

B.

802.tr is enabled in the WLAN Security settings.

C.

There was localized interference at the caller’s location

D.

802.1K is disabled in the WLAN Security settings

E.

The client roamed into an area that continuously operates Zigbee.

Question 29

A customer is evaluating device profiles on a CX 6300 switch. The test device has the following attributes:

• MAC address = 81:cd:93:13:ab:31

• LLDP sys-desc = iotcontroller

The test device is being assigned to the ‘’lot-dev’' role However, the customer requires the "lot-prod’’ role be applied.

Given the configuration, what is causing the "iot-dev" role to be applied to the device'?

Options:

A.

The test device does not support CDP.

B.

The device-profile precedence order is not configured.

C.

An external RADIUS server is unreachable.

D.

The LLDP system description matches the IIdp-group configuration.

Question 30

An OSPF router has learned a pain 10 an external network by Doth an E1 and an E2 advertisement Both routes have the same path cost Which path will the router prefer?

Options:

A.

The router will prefer the E1 path.

B.

The router will use Doth paths equally utilizing ECMP.

C.

The router will prefer the E2 path.

D.

Both routes will be suppressed until the path conflict has been resolved.

Question 31

A customer with a gateway connected to a device on gigabitethernet 0/0/3 configures an Asset ID TLV on the device for inventory management.

Refer to the exhibit.

The customer mentions the Asset ID is not shown. What is causing the issue?

Options:

A.

MTU size is too small.

B.

Unknown TLVs cannot be displayed.

C.

LLDP-MED needs to be enabled.

D.

LLDP TX is not enabled.

Question 32

A customer reports that their HPE Aruba Networking ClearPass Guest captive portal is not functioning. The page loads but they are unable to browse after pressing connect. They have uploaded a valid and publicly trusted *. aruba-training.com certificate.

Refer to the exhibit.

Which would explain this issue?

Options:

A.

aruba-training.com needs to be entered in the Address field for the ClearPass Guest

B.

captiveportal-login.aruba-training.com needs to be entered in the Address field for the ClearPass Guest

C.

HTTPS certificate is not required in ClearPass Guest

D.

HTTPS wildcard certificates are not supported

Question 33

Refer to the exhibit.

A network administrator is validating client connectivity and executes the show command shown in the exhibit. Which authentication method was used by the wireless station?

Options:

A.

MAC authentication

B.

802.1X user authentication

C.

WEBauth authentication

D.

802.1X machine authentication

Question 34

A customer is reviewing HPE Aruba Networking Central's Client Insights and notices that several wireless clients are not displaying flow attributes and network activity in the profile tab. This deployment is using AOS-10 mobility gateways.

What are the possible reasons why this data is not visible in HPE Aruba Networking Central? (Select two)

Options:

A.

The client's SSID is configured as mixed mode, and the clients experiencing the issue are tunneled out of the APs

B.

The wireless client VLANs on the gateways are marked as trusted

C.

The client's SSID is configured as bridged

D.

The client's SSID is configured as mixed mode, and the clients experiencing the issue are bridged out of the APs

E.

The wireless client VLANs on the gateways are marked as untrusted

Question 35

Based on best practices if an SSID is configured Tor a primary and secondary gateway cluster with cluster preemption enabled, which will decide if the APs move to the secondary gateway cluster if all of the nodes in the primary gateway cluster are down?

Options:

A.

tunnel orchestrator for LAN tunnel service in HPE Aruba Networking Central

B.

every AP individually

C.

cluster leader in the primary gateway cluster

D.

cluster leader in the secondary gateway cluster

Page: 1 / 9
Total 126 questions