Refer to the exhibit.
Based on the configuration of the Enforcement Profiles In the Onboard Authorization service shown, which Onboarding action will occur?
A. The device will be disconnected from the network after Onboarding so that an EAP-TLS authentication is not performed.
B. The device will be disconnected from and reconnected to the network after Onboarding is completed.
C. The device's onboard authorization request will be denied.
D. The device will be disconnected after post-Onboarding EAP-TLS authentication, so a second EAP-TLS authentication is performed.
E. After logging in on the Onboard web login page, the device will be disconnected form and reconnected to the network before Onboard begins.
In a VPN that uses certificate-based authentication, which component must be configured on the Mobility Master (MM) to allow a RAP to successfully connect to a Mobility Controller (MC)
A. RAP VPN username and password
B. WLAN and new RAP group
C. RAP IPSec pre-shared key
D. RAP whitelist
Which is a valid policy simulation types in ClearPass? (Select three.)
A. Enforcement Policy
B. Posture token derivation
C. Role Mapping
D. Endpoint Profiler
E. Chained simulation
Refer to the exhibit.
An Enforcement Profile has been created in the Policy Manager as shown. Which action will ClearPass take based on this Enforcement Profile?
A. ClearPass will count down 600 seconds and send a RADIUS CoA message to the user to end the user's session after this time is up.
B. ClearPass will send the Session-Timeout attribute in the RADIUS Access-Accept packet to the NAD and the NAD will end the user's session after 600 seconds.
C. ClearPass will count down 600 seconds and send a RADIUS CoA message to the NAD to end the user's session after this time is up.
D. ClearPass will send the Session-Timeout attribute in the RADIUS Access-Request packet to the NAD and the NAD will end the user's session after 600 seconds.
E. ClearPass will send the Session-Timeout attribute in the RADIUS Access-Accept packet to the User and the user's session will be terminated after 600 seconds.
Refer to the exhibit.
A known unicast packet is received from Switch-1 on the standby and must be forwarded to Switch-2. How does the VSF fabric decide which port in the aggregated (ink should forward the packet?
A. The standby uses its own port in the link aggregation to forward the fabric.
B. The standby sends the packet to the commander over a VSF link, and the commander decides the correct port.
C. The standby uses the typical load sharing algorithm, and it might select either its port or the commander's port.
D. The standby selects the port on the designated forwarder for the aggregation.
What is the purpose of the captive portal URL hash key on an AOS-Switch?
A. It authenticates guest users based on the password the users enter hi the portal.
B. It encrypts and secures the RADIUS messages that the AOS-Switch sends to ClearPass.
C. It does not let users alter the URL that redirects them to the portal.
D. It specifies the captive portal URL and conceals the setting in the config.
An administrator configures an ArubaOS-Switch for per -user tunneled node. Which protocols does the switch use to establish and maintain a connection with the Aruba Mobility Controller (MO? (Select two.)
A. GRE
B. SSL
C. PAPI
D. IPSec
Refer to the exhibit.
Which statements accurately describe the status of the Onboarded devices in the configuration tor the network settings shown? (Select two.)
A. They will connect to Employee_Secure SSID after provisioning.
B. They will connect to Employee_Secure SSID for provisioning their devices.
C. They will use WPA2-PSK with AES when connecting to the SSID.
D. They will connect to secure_emp SSID after provisioning.
E. They will perform 802.1X authentication when connecting to the SSID.
Refer to the exhibit.
Based on the Enforcement Policy configuration, when a user with Role Engineer connects to the network and the posture token assigned is Unknown, which Enforcement Profile will be applied?
A. EMPLOYEE_VLAN
B. RestrictedACL
C. Deny Access Profile
D. HR VLAN
E. Remote Employee ACL
Refer to the exhibit.
When configuring a Web Login Page in ClearPass Guest, the information shown is displayed. What is the Address field value 'securelogin.arubanetworks.com' used for?
A. for ClearPass to send a TACACS+ request to the NAD
B. for appending to the Web Login URL, before the page name
C. for the client to POST the user credentials to the NAD
D. for ClearPass to send a RADIUS request to the NAD
E. for appending to the Web Login URL, after the page name.