Câu 10: HPE7-A10: HPE Network Security Expert
# Introduction to the customerYou are helping a company add HPE Aruba Networking ClearPass to their network, which uses HPE Aruba Networking network infrastructure devices. The company currently has a Windows domain and Windows CA. The Window CA issues certificates to domain computers, domain users, and servers such a…
Nội dung câu hỏi
# Introduction to the customerYou are helping a company add HPE Aruba Networking ClearPass to their network, which uses HPE Aruba Networking network infrastructure devices. The company currently has a Windows domain and Windows CA. The Window CA issues certificates to domain computers, domain users, and servers such as domain controllers. An example of a certificate issued by the Windows CA is shown here. # ClearPass cluster IP addressing and hostnamesA customer's ClearPass cluster has these IP addresses:• Publisher = 10.47.47.5• Subscriber 1 = 10.47.47.6• Subscriber 2 = 10.47.47.7• Virtual IP with Subscriber 1 and Subscriber 2 = 10.47.47.8The customer's DNS server has these entries• cp.acnsxtest.com = 10.47.47.5• cps1.acnsxtest.com = 10.47.47.6• cps2.acnsxtest.com = 10.47.47.7• radius.acnsxtest.com = 10.47.47.8• onboard.acnsxtest.com = 10.47.47.8Refer to the scenario. A customer has AOS-CX switches with this configuration on their edge ports: port-access onboarding-method concurrent enable aaa authentication port-access mac-auth enable quiet-period 60 aaa authentication port-access dotx1 authenticator enableThe switch authenticates clients to HPE Aruba Networking ClearPass Policy Manager (CPPM) which has these services:1. An 802.1 X service that uses an EAP-TLS method for most clients2. A MAC-Auth service that uses the [MAC-Auth] method for devices such as printers imported from an inventory managerThe customer now wants to provide limited access to wired guest devices and new devices that need to be enrolled with certificates. You have set up these rights in an AOS-CX role named "guest-login."How should you apply the "guest-login" role on the switches?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. As the role assigned by the default enforcement profile in CPPM's MAC-Auth service
- B. As the port-access preauth-role on the edge interfaces — đáp án hiện tại
- C. As the port-access reject-role on the edge interfaces
- D. As the role assigned by the default enforcement profile in CPPM's 802.1X service
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.