CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 5: HPE7-A10: HPE Network Security Expert

# Introduction to the customerYou are helping a company add HPE Aruba Networking ClearPass to their network, which uses HPE Aruba Networking network infrastructure devices. The company currently has a Windows domain and Windows CA. The Window CA issues certificates to domain computers, domain users, and servers such a…

Nội dung câu hỏi

# Introduction to the customerYou are helping a company add HPE Aruba Networking ClearPass to their network, which uses HPE Aruba Networking network infrastructure devices. The company currently has a Windows domain and Windows CA. The Window CA issues certificates to domain computers, domain users, and servers such as domain controllers. An example of a certificate issued by the Windows CA is shown here. # ClearPass cluster IP addressing and hostnamesA customer's ClearPass cluster has these IP addresses:• Publisher = 10.47.47.5• Subscriber 1 = 10.47.47.6• Subscriber 2 = 10.47.47.7• Virtual IP with Subscriber 1 and Subscriber 2 = 10.47.47.8The customer's DNS server has these entries• cp.acnsxtest.com = 10.47.47.5• cps1.acnsxtest.com = 10.47.47.6• cps2.acnsxtest.com = 10.47.47.7• radius.acnsxtest.com = 10.47.47.8• onboard.acnsxtest.com = 10.47.47.8Refer to the scenario. Assume that you have set up CPPM to assign HPE Aruba Networking ClearPass roles and AOS user roles as indicated in the scenario. However, a penetration tester was able to access the network with medical staff privileges on a client with a valid computer certificate but revoked medical user certificate. In this circumstance, the customer wants the client to receive computer-only access. What can you do to correct this issue while still meeting the other customer requirements?

Minh họa câu hỏi Minh họa câu hỏi

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Add a role mapping rule that assigns clients that have failed TEAP Method 2 to a "user-failed" role. Add an enforcement policy rule to the top of the list that assigns clients with the "domain-computer" and "user-failed" roles to the "computer-only" profile. — đáp án hiện tại
  2. B. Check the order of the enforcement policy rules. Make sure that any rule that applies the "computer-only" profile is at the top of the list. Also, ensure that the default rule is the drop access profile.
  3. C. Change the authentication method configuration to use CRLs to validate certificates' status instead of OCSP.
  4. D. Adjust the authentication filter used in the authentication source. Change any references to the %{Username} variable to the %{TEAP-Method-2-Username} variable.

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề