Free HPE6-A68 Exam Braindumps (page: 7)

Page 6 of 30

A hotel chain deployed ClearPass Guest. When hotel guests connect to the Guest SSID, launch a web browser and enter the address www.google.com, they are unable to immediately see the web login page.
What are the likely causes of this? (Select two.)

  1. The ClearPass server has a trusted server certificate issued by Verisign.
  2. The ClearPass server has an untrusted server certificate issued by the internal Microsoft Certificate server.
  3. The ClearPass server does not recognize the client's certificate.
  4. The DNS server is not replying with an IP address for www.google.com.

Answer(s): B,D

Explanation:

You would need a publicly signed certificate.


Reference:

http://community.arubanetworks.com/t5/Security/Clearpass-Guest-certificate-error-for- guest-visitors/td-p/221992



Refer to the exhibit.



An Enforcement Profile has been created in the Policy Manager as shown.

Which action will ClearPass take based on this Enforcement Profile?

  1. ClearPass will count down 600 seconds and send a RADIUS CoA message to the user to end the user's session after this time is up.
  2. ClearPass will send the Session-Timeout attribute in the RADIUS Access-Accept packet to the NAD and the NAD will end the user's session after 600 seconds.
  3. ClearPass will count down 600 seconds and send a RADIUS CoA message to the NAD to end the user's session after this time is up.
  4. ClearPass will send the Session-Timeout attribute in the RADIUS Access-Request packet to the NAD and the NAD will end the user's session after 600 seconds.
  5. ClearPass will send the Session-Timeout attribute in the RADIUS Access-Accept packet to the User and the user's session will be terminated after 600 seconds.

Answer(s): E

Explanation:

Session Timeout (in seconds) - Configure the agent session timeout interval to re-evaluate the system health again. OnGuard triggers auto-remediation using this value to enable or disable AV-RTP status check on endpoint. Agent re-authentication is determined based on session-time out value. You can specify the session timeout interval from 60 ­ 600 seconds. Setting the lower value for session timeout interval results numerous authentication requests in Access Tracker page. The default value is 0.


Reference:

http://www.arubanetworks.com/techdocs/ClearPass/Aruba_CPPMOnlineHelp/Content/CPPM_User Guide/Enforce/EPAgent_Enforcement.htm



Refer to the exhibit.



Based on the information shown, what is the purpose of using [Time Source] for authorization?

  1. to check how long it has been since the last login authentication
  2. to check whether the guest account expired
  3. to check whether the MAC address is in the MAC Caching repository
  4. to check whether the MAC address status is known in the endpoints table
  5. to check whether the MAC address status is unknown in the endpoints table

Answer(s): D



A customer with an Aruba Controller wants it to work with ClearPass Guest. How should the customer configure ClearPass as an authentication server in the controller so that guests are able to authenticate successfully?

  1. Add ClearPass as a RADIUS CoA server.
  2. Add ClearPass as a RADIUS authentication server.
  3. Add ClearPass as a TACACS+ authentication server.
  4. Add ClearPass as an HTTPS authentication server.

Answer(s): B

Explanation:

5. Configuring the Aruba Controller
5.1 Add Clearpass as RADIUS Server
Navigate to Configuration > SECURITY > Authentication > Servers Click on RADIUS Server and enter the Name of your Clearpass Server: myClearpass Click Add
Click on myClearpass in the Server List Etc.


Reference:

https://community.arubanetworks.com/t5/Security/Step-by-Step-Controller-CPPM-6-5- Captive-Portal-authentication/td-p/229740






Post your Comments and Discuss HP HPE6-A68 exam with other Community members:

HPE6-A68 Discussions & Posts