Câu 5: HPE7-A10: HPE Network Security Expert
# Introduction to the customerYou are helping a company add HPE Aruba Networking ClearPass to their network, which uses HPE Aruba Networking network infrastructure devices. The company currently has a Windows domain and Windows CA. The Window CA issues certificates to domain computers, domain users, and servers such a…
Nội dung câu hỏi
# Introduction to the customerYou are helping a company add HPE Aruba Networking ClearPass to their network, which uses HPE Aruba Networking network infrastructure devices. The company currently has a Windows domain and Windows CA. The Window CA issues certificates to domain computers, domain users, and servers such as domain controllers. An example of a certificate issued by the Windows CA is shown here. # ClearPass cluster IP addressing and hostnamesA customer's ClearPass cluster has these IP addresses:• Publisher = 10.47.47.5• Subscriber 1 = 10.47.47.6• Subscriber 2 = 10.47.47.7• Virtual IP with Subscriber 1 and Subscriber 2 = 10.47.47.8The customer's DNS server has these entries• cp.acnsxtest.com = 10.47.47.5• cps1.acnsxtest.com = 10.47.47.6• cps2.acnsxtest.com = 10.47.47.7• radius.acnsxtest.com = 10.47.47.8• onboard.acnsxtest.com = 10.47.47.8Refer to the scenario. Assume that you have set up CPPM to assign HPE Aruba Networking ClearPass roles and AOS user roles as indicated in the scenario. However, a penetration tester was able to access the network with medical staff privileges on a client with a valid computer certificate but revoked medical user certificate. In this circumstance, the customer wants the client to receive computer-only access. What can you do to correct this issue while still meeting the other customer requirements?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Add a role mapping rule that assigns clients that have failed TEAP Method 2 to a "user-failed" role. Add an enforcement policy rule to the top of the list that assigns clients with the "domain-computer" and "user-failed" roles to the "computer-only" profile. — đáp án hiện tại
- B. Check the order of the enforcement policy rules. Make sure that any rule that applies the "computer-only" profile is at the top of the list. Also, ensure that the default rule is the drop access profile.
- C. Change the authentication method configuration to use CRLs to validate certificates' status instead of OCSP.
- D. Adjust the authentication filter used in the authentication source. Change any references to the %{Username} variable to the %{TEAP-Method-2-Username} variable.
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.