ACA Network Security & Access Control 3 — Questions and Answers
Question 1: Which Aruba Mobility Controller feature detects and classifies rogue APs operating on the same RF spectrum?
- Adaptive Radio Management (ARM)
- Air Monitor (AM) mode (Correct answer)
- AppRF
- GRE tunneling
Correct answer: Air Monitor (AM) mode
APs in Air Monitor mode continuously scan all channels and report rogue devices to the controller for classification and containment.
Question 2: A ClearPass administrator wants to allow guests to self-register. Which ClearPass module provides the guest self-registration portal?
- ClearPass OnGuard
- ClearPass Guest (Correct answer)
- ClearPass Insight
- ClearPass Device Insight
Correct answer: ClearPass Guest
ClearPass Guest provides customizable captive portals, self-registration workflows, and guest account management.
Question 3: Which Aruba security feature automatically moves a client to a quarantine role when ClearPass sends a RADIUS Change of Authorization (CoA)?
- Dynamic Authorization (Correct answer)
- Static VLAN assignment
- User-Based Tunneling
- AirMatch
Correct answer: Dynamic Authorization
Dynamic Authorization (RFC 5176) allows ClearPass to send CoA or Disconnect-Message packets to the controller mid-session to change a client's role or terminate the session.
Question 4: In Aruba's layered security model, which layer is responsible for encrypting the wireless data frames over the air?
- Layer 7 Application Firewall
- Layer 2 (CCMP/AES encryption) (Correct answer)
- Layer 3 IPsec tunnel
- Layer 4 TLS
Correct answer: Layer 2 (CCMP/AES encryption)
CCMP (AES-based) operates at Layer 2 and encrypts the 802.11 data frames between the client and the AP over the air.
Question 5: What Aruba feature uses DHCP fingerprinting and OUI lookup to automatically identify the type of device connecting to the network?
- ClearPass Device Insight / Profiling (Correct answer)
- AppRF
- AirWave Alerts
- STM (Station Management)
Correct answer: ClearPass Device Insight / Profiling
ClearPass Device Profiling uses DHCP fingerprinting, HTTP user-agent, OUI, and other signals to identify device type, OS, and manufacturer.
Question 6: Which wireless attack does Aruba's Wireless Intrusion Protection (WIP) detect by identifying a legitimate SSID broadcast from an unauthorized MAC address?
- Deauthentication flood
- Evil twin / honeypot AP (Correct answer)
- ARP poisoning
- DHCP starvation
Correct answer: Evil twin / honeypot AP
An evil twin attack uses a rogue AP broadcasting a legitimate SSID to lure clients; WIP detects the SSID/BSSID mismatch against the valid AP table.
Question 7: In an Aruba network, what is the primary function of the Pairwise Master Key (PMK) derived during 802.1X authentication?
- It directly encrypts user data frames
- It seeds the 4-Way Handshake to derive per-session PTK/GTK keys (Correct answer)
- It replaces the need for a RADIUS server
- It is used for AP-to-controller CAPWAP encryption
Correct answer: It seeds the 4-Way Handshake to derive per-session PTK/GTK keys
The PMK is derived from the EAP exchange and is used as input to the 4-Way Handshake, which produces the PTK (unicast) and GTK (multicast) encryption keys.
Which Aruba Mobility Controller feature detects and classifies rogue APs operating on the same RF spectrum?