CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 2: HPE7-A10: HPE Network Security Expert

You are designing an AOS-10 architecture and ClearPass solution for a manufacturing company. The company that has legacy equipment that is only WPA2 capable. You need to enhance security for these devices. This equipment will connect to an SSID named "Factory." If the equipment passes authentication and receives custo…

Nội dung câu hỏi

You are designing an AOS-10 architecture and ClearPass solution for a manufacturing company. The company that has legacy equipment that is only WPA2 capable. You need to enhance security for these devices. This equipment will connect to an SSID named "Factory." If the equipment passes authentication and receives custom Device Category "Manufacturing," it should receive this AOS user role: "equipment." That role and a "profiling" role for unprofiled devices are already configured on the AOS devices. The users responsible for configuring PSKs on the equipment belong to the "FactoryAdmins" group in the company's Active Directory domain. CPPM has an authentication source for that domain named MyAD. As part of the solution, you have created these services on CPPM:- Service 1:- Type: Application- Authentication source: MyAD- Authorization source: None- Enforcement policy:- Rule 1 condition: Authorization:Endpoints Repository:Category EQUALS Manufacturing- Rule 1 profile list: Enforcement profiles that permit application access and assign the Guest Operators role- Default action: Deny access- Service 2- Type: Wireless with mPSK- Authentication source: Guest Devices Repository- Authorization source: None- Enforcement policy:- Rule 1 condition: Endpoint Device Insight Tag EQUALS Manufacturing- Rule 1 profile list: Enforcement profile that assigns Aruba-User-Role = equipment and [Registered Device MPSK] profile- Rule 2 condition: Endpoint:Device Insight Tag NOT_EXISTS- Rule 2 profile list: Enforcement profile that assigns Aruba-User-Role = profiling and [Registered Device MPSK] profile- Default action: Deny accessWhat is an error in this configuration?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Service 2 requires the Endpoints Repository as an authorization source and adjustments to the enforcement policy. — đáp án hiện tại
  2. B. Service 1 uses the wrong service type.
  3. C. Service 2 uses the wrong authentication source.
  4. D. Service 2 is missing a necessary rule in the enforcement policy.

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề