← All ACA Flashcard Decks

Network Security & Access Control Flashcards

7 cards from real ACA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Network Security & Access Control flashcards as text
  1. Which Aruba technology provides secure tunneling of client traffic from a remote AP back to the campus controller, protecting data in transit?

    Answer: GRE over IPsec (RAP/VPN)

    Remote APs (RAPs) establish an IPsec tunnel to the controller, and client traffic is forwarded inside that encrypted GRE-over-IPsec tunnel.

  2. A security policy requires that only corporate-managed devices receive full network access while BYOD devices are redirected to a limited portal. Which ClearPass feature enables this differentiation?

    Answer: Profiling with enforcement policies

    ClearPass profiles devices (via certificates, MDM attributes, etc.) and applies different enforcement profiles — full access for managed devices, portal redirect for BYOD.

  3. What is the purpose of RADIUS accounting in an Aruba network security deployment?

    Answer: To provide session records (start/stop/interim) for audit, billing, and analytics

    RADIUS accounting sends Start, Interim-Update, and Stop messages to the RADIUS server, recording session duration, bytes transferred, and user identity for audit purposes.

  4. Which attack does Aruba Wireless Intrusion Protection (WIP) counter by sending de-authentication frames to clients attempting to associate with a rogue AP?

    Answer: Rogue AP containment

    WIP containment sends 802.11 de-authentication frames to clients associating with a classified rogue AP, preventing them from staying connected to it.

  5. In an Aruba deployment, which protocol is used between the ClearPass server and the Mobility Controller to deliver dynamic policy enforcement?

    Answer: RADIUS (Access-Accept with VSAs) and RFC 5176 CoA/Disconnect

    ClearPass uses RADIUS Access-Accept with Aruba VSAs for initial role assignment and RFC 5176 CoA/Disconnect to change or terminate sessions dynamically.

  6. What is the minimum recommended action when a ClearPass posture check determines that a connecting device has an outdated antivirus signature?

    Answer: Assign a quarantine role that redirects to a remediation page

    Best practice is to assign a quarantine role with a remediation redirect, allowing the user to update their AV while limiting their network access.

  7. Which Aruba Mobility Controller configuration option prevents a wireless client from communicating directly with other clients on the same SSID?

    Answer: Client isolation (intra-BSS traffic blocking)

    Client isolation (intra-BSS blocking) prevents Layer 2 traffic between clients on the same SSID, commonly used for guest networks to protect clients from each other.