Brilliant HPE6-A77 Exam Dumps Get HPE6-A77 Dumps PDF [Q16-Q34]

Share

Brilliant HPE6-A77 Exam Dumps Get HPE6-A77 Dumps PDF

HPE6-A77 Dumps PDF - HPE6-A77 Real Exam Questions Answers


HP HPE6-A77 Exam Syllabus Topics:

TopicDetails
Topic 1
  • TACACS authentication from Network Access Devices
  • Integration of Authorization Sources and External Context Servers into Enforcement
Topic 2
  • Customized Admin Privileges for the Policy Manager
  • Self-Registration both with and without sponsorship
Topic 3
  • Integration of Endpoint Profiling into Enforcement
  • Cluster Layout positioning of Publisher and Subscribers, Use of Policy Manager Zones
Topic 4
  • Quarantine and remediation based on Posture Token and the status of the agent
  • Implimentation of both Server and Controller Initiated Captive Portal Authentication

 

NEW QUESTION 16
A Customer has these requirements:
* 2.000 loT endpoints that use MAC authentication
* 6,000 endpoints using a mix of username/password and certificate (Corporate/BYOD) based authentication
* 1,000 guest endpoints at peak usage that use guest self-registration
* 1500 BYOD devices estimated as 3 devices per User (500 users)
* 2,500 endpoints that have OnGuard installed and connect on a daily basis What licenses should be installed to meet customer requirements?

  • A. 11,500 Access, 1,500 Onboard, 2.500 Onguard
  • B. 9,000 Access, 500 Onboard. 2.500 Onguard
  • C. 13.000 Access, 1.500 Onboard, 2,500 Onguard
  • D. 11,500 Access, 500 Onboard, 2,500 Onguard

Answer: A

 

NEW QUESTION 17
What type of EAP certificate are you able to use on ClearPass? (Select two.)

  • A. Self signed, when all the clients are part of the organization domain.
  • B. Private signed, when the clients are onboarded or are part of the organization domain.
  • C. Private signed, when some clients are onboarded and some are not part of the organization.
  • D. Public signed, when not all of the clients are part of the organization domain.
  • E. Self signed, when all the clients are Onboarded with the same Root CA as the Self signed certificate.

Answer: C,D

 

NEW QUESTION 18
A customer has a ClearPass cluster deployment with four servers, two servers at the data center and two servers at a large remote site connected over an SD-WAN solution The customer would like to implement OnGuard, Guest Self-Registration, and 802.1x authentication across their entire environment. During testing the customer is complaining that users connecting to an Instant Cluster Employee SSID at the remote site, with the OnGuard Persistent Agent installed are randomly getting their health check missed.
What could be a possible cause of this behavior?

  • A. The OnGuard Clients are automatically mapped to the Policy Manager Zone based on their IP range but an ACL on the switch could be blocking access.
  • B. The traffic on the TCP port 6658 is congested due to the fact that this port is also used by the IPsec keep-alive packets of the SD-WAN solution.
  • C. The ClearPass Policy Manager zones have been defined but the local IP sub-nets have not been property mapped to the zones and the OnGuard Agent might connect to any of the servers in the cluster.
  • D. The Aruba-user-role received by the IAP is filtering the TCP port 6658 to the ClearPass servers and after 10 seconds the SSL fallback gets activated and randomly generates the issue.

Answer: D

 

NEW QUESTION 19
Refer to the exhibit:

A customer has configured onboard in a cluster with two nodes All devices were onboarded in the network through node1but those clients tail to authenticate through node2 with the error shown. What steps would you suggest to make provisioning and authentication work across the entire cluster? (Select three.)

  • A. Make sure that the EAP certificates on both nodes are issued by one common root Certificate Authority (CA).
  • B. Configure the Onboard Root CA to trust the Policy Manager EAP certificate root.
  • C. Make sure that the HTTPS certificate on both nodes is issued as a Code Signing certificate
  • D. Have all of the BYOD clients re-run the Onboard process
  • E. Configure the Network Settings in Onboard to trust the Policy Manager EAP certificate
  • F. Have all of the BYOD clients disconnect and reconnect to me network

Answer: A,B,E

 

NEW QUESTION 20
What is used to validate the EAP Certificate? (Select three.)

  • A. Common Name
  • B. Server Identity
  • C. SAN entries
  • D. Key usage
  • E. Trust chain
  • F. Date

Answer: A,D,E

 

NEW QUESTION 21
A customer has configured Onboard with Single SSID provision for Aruba IAP Windows devices work as expected but cannot get the Apple iOS devices to work. The Apple iOS devices automatically get redirected to a blank page and do not get the Onboard portal page. What would you check to fix the issue?

  • A. Verify if the Onboard URL is updated correctly in the external captive portal profile.
  • B. Verify if the external captive portal profile is enabled to use HTTPS with port 443.
  • C. Verify if Onboard Pre-Provisioning enforcement profile sends the correct Aruba user role.
  • D. Verify if the checkbox "Enable bypassing the Apple Captive Network Assistant" is checked.

Answer: A

 

NEW QUESTION 22
A customer is looking to implement a Web-Based Health Check solution with the following requirements:
* for the HR user's client devices, check if a USB stick is mounted.
* for the R&D user's client devices, check if the hard disk is fully encrypted.
The Web-Based Health Check service has been configured but the customer it is not sure how to design the Profile Policy How can be accomplished this customer request?

  • A. create one Posture Policy to check the HR users client devices and use the NAP Agent to check R&D users client devices
  • B. create two Posture Policies and use the Restrict by Roles option to filter for HR and R&D user roles and apply the correct SHV checks
  • C. create one Posture Policy and define Rules Conditions that will apply different Tokens for each SHV check condition
  • D. create two Posture Policies and customize the OnGuard Agent (Persistent or Dissolvable) to select the correct SHV checks

Answer: D

 

NEW QUESTION 23
Refer to the exhibit:



The customer configured an 802.1x service with different enforcement actions for personal and corporate laptops. The corporate laptops are always being redirected to the BYOD Portal. The customer has sent you the above screenshots.
How would you resolve the issue? (Select two)

  • A. Remove the EAP-PEAP with [user authenticated] condition for Onboard and create another service
  • B. Modify the enforcement policy and change the rule evaluation algorithm to select first match
  • C. Modify the enforcement policy and re-order the EAP-PEAP with [user authenticated] rule to the last condition.
  • D. Modify the enforcement policy and re-order the condition with Posture - Unknown as the fifth condition
  • E. Modify the enforcement policy and re-order the condition with posture not_equals to healthy as the sixth condition

Answer: C,D

 

NEW QUESTION 24
What is the Open SSID (otherwise referred to as Dual SSID) Onboard deployment service workflow?

  • A. OnBoard Pre-Auth Application service, OnBoard Authorization Application service. OnBoard Provisioning RADIUS service
  • B. OnBoard Authorization Application service, OnBoard Pre-Auth Application service, OnBoard Provisioning RADIUS service
  • C. OnBoard Authorization RADIUS service, OnBoard Pre-Auth Application service, OnBoard Provisioning RADIUS service
  • D. OnBoard Pre-Auth RADIUS service. OnBoard Authorization Application service. OnBoard Provisioning RADIUS service

Answer: B

 

NEW QUESTION 25
You have recently implemented a serf-registration portal in ClearPass Guest to be used on a Guest SSID broadcast from an Aruba controller. Your customer has started complaining that the users are not able to reliably access the internet after clicking the login button on the receipt page. They tell you that the users willclick the login button multiple times and alter about a minute they gain access.
What could be causing this issue?

  • A. The guest client is delayed getting an IP address from the DHCP server.
  • B. The guest users are assigned a firewall user role that has a rate limit.
  • C. The self-registration page is configured with a 1 minute login delay.
  • D. The enforcement profile on ClearPass is set up with an lETF:session delay.

Answer: C

 

NEW QUESTION 26
A customer has acquired another company that has its own Active Directory infrastructure The 802 1X authentication works with the customers original Active Directory servers but the customer would like to authenticate users from the acquired company as well. What steps are required, in regards to the Authentication Sources, in order to support this request? (Select two.)

  • A. Create a new Authentication Source, type Generic LDAP.
  • B. There is no need to Join ClearPass to the new AD domain.
  • C. Add the new AD server(s) as backup into the existing Authentication Source.
  • D. Create a new Authentication Source, type Active Directory.
  • E. Join the ClearPass server(s) to the new AD domain.

Answer: B,E

 

NEW QUESTION 27
Refer to the exhibit:



Your customer configured a ClearPass server to process the Guest and Secure SSIDs broadcastingfrom both Aruba and Cisco WLAN controllers When an Employee connects to Aruba or Cisco secure SSID, the authentication hits the guest service causing the client to fail the connection to the network.
What change can be implemented to make both the secure and guest services created for Aruba and Cisco devices to work correctly?

  • A. Move the HS_Building Aruba 802.1x service to the second position in the service order.
  • B. Move the HS-Guest User Authentication with MAC Caching service to the first position.
  • C. Modify the service rule matching algorithm to ALLin HS-GuestUser Authentication service.
  • D. Disable HS-Guest User Authentication service and move HS-Guest MAC Authentication to seventh position.

Answer: B

 

NEW QUESTION 28
You are deploying ClearPass Policy Manager with Guest functionality for a customer withmultiple Aruba Networks Mobility Controllers The customer wants to avoid SSL errors during guest access but due to company security policy cannot use a wildcard certificate on ClearPass or the Controllers.
What is the most efficient way to configure the customers guest solution? (Select two.)

  • A. Install multiple public certificates with a different Common Name on each controller
  • B. Build one Web Login page with vendor settings for controller {company domain)
  • C. Build multiple Web Login pages with vendor settings configured for each controller
  • D. Install the same public certificate on all Controllers with the common name "controller {company domain}"

Answer: C,D

 

NEW QUESTION 29
Refer to the exhibit:


You configured a new Wireless 802.1X service for a Cisco WLC broadcasting the Secure-ADM-5007 SSID.
The client falls to connect to the SSID. Using the screenshots as a reference, how would you fix this issue?
(Select two.)

  • A. Change the service condition to Radius:lETF Calling-Station-ld EQUALS Secure-ADM-5007
  • B. Remove the service condition Radius:lETF Service-Type BELONGSJTO Login-User (1). 2. 8
  • C. Make sure that the Network Devices entry for the Cisco WLC has a vendor setting of "Airspace"
  • D. Update the service condition Radius:IETF Called-Station-ld CONTAINS secure-adm-5007

Answer: B,D

 

NEW QUESTION 30
Refer to the exhibit:





A year ago, your customer deployed an Aruba ClearPass Policy Manager Server for a Guest SSIC hosted in an IAP Cluster.The customer just created a new Web Login Page forthe Guest SSID. Even though the previous Web Login page worked test with the new Web Login Page are falling and the customer has forwarded you the above screenshots What recommendation would you give the customer to tix the issue?

  • A. The Address filed under the WebLogin Vendor settings is not configured correctly, it should be set to instantarubanetworks.com
  • B. The customer should reset the password tor the username accx@exam com using Guest Manage Accounts
  • C. The service type configured is not correct. The Guest authentication should De an Application authentication type of service.
  • D. The WebLogin Pre-Auth Check is set to Aruba Application Authentication which requires a separate application service on the policy manager

Answer: C

 

NEW QUESTION 31
Refer to the exhibit:



You are doing a ClearPass PoC at a customer site with a single Aruba Mobility Controller. The customer asked for a demonstration of a simple Web Login functionality. You used a service template to create the guest services. During testing, the usergets redirected back to the weblogin page with an Authentication failed message. The guest configurations on the Aruba Mobility Controller are configured correctly.
Why would the guest fail to authenticate successfully?

  • A. The Unique-Device-Count does not allow any Client devices.Update the Enforcement policy condition:
    Unique-Device-Count.
  • B. The authentication source mapped in the service is incorrect, it should be mapped as (Guest Device Repository] [Local SQL DB].
  • C. The username and/or password used for authentication is incorrect Re-enter the correct password on the weblogin page.
  • D. The username used for authentication does not exist in the Guest User Database Create a new user and authenticate again.

Answer: B

 

NEW QUESTION 32
Refer to the exhibit:

When creating a new report, there is an option to send report Notifications by Email. Where is the email server configured?

  • A. In the insight report on the next screen of the report definition.
  • B. In the ClearPass Policy Manager Endpoint Context servers under Administration.
  • C. In the Insight Reports Interface under Administration on the sidebar menu.
  • D. In the ClearPass Policy Manager Messaging setup under Administration.

Answer: C

 

NEW QUESTION 33
Refer to the exhibit:



The customer created a new enforcement policy condition to allow VIP Users access without additional security compliance checks hut cannot gel it working. The customer has sent you the above screenshots.
How would you resolve the issue?

  • A. Include VIP User role along with the Healthy posture enforcement condition.
  • B. Modify the Enforcement Policy and re-order the VIPuser condition to the lop.
  • C. Set the Enforcement Policy rules evaluation algorithm to evaluate all.
  • D. Ask the VIP user to complete the one time webhealthcheck to get the VIP profile.

Answer: A

 

NEW QUESTION 34
......

Valid HPE6-A77 Test Answers & HP HPE6-A77 Exam PDF: https://www.actualtestsquiz.com/HPE6-A77-test-torrent.html