Authentication Methods Flashcards
7 cards from real ACMA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Authentication Methods flashcards as text
Which EAP method uses a client-side certificate for mutual authentication without requiring a server-side password?
Answer: EAP-TLS
EAP-TLS requires both the client and server to present X.509 certificates, providing strong mutual authentication without passwords.
In Aruba ClearPass, what is the purpose of the 'Authentication Source' configuration?
Answer: Specifies where user credentials are validated, such as AD or LDAP
An Authentication Source in ClearPass defines the backend identity store (e.g., Active Directory, LDAP, or a local database) used to verify user credentials.
What is the role of the Authenticator in the 802.1X framework?
Answer: Acts as a middleman forwarding EAP messages between supplicant and authentication server
The Authenticator (typically a wireless AP or switch) relays EAP messages between the supplicant (client) and the authentication server without inspecting credentials.
Which authentication method is considered the weakest for WPA2-Enterprise deployments because it only validates the server, not the client?
Answer: EAP-MD5
EAP-MD5 provides only one-way authentication (server to client is not validated) and sends a challenge-response that is vulnerable to offline dictionary attacks.
When configuring MAC Authentication Bypass (MAB) on an Aruba AP, what credential does the device send to the RADIUS server?
Answer: The device's MAC address as both username and password
In MAB, the AP sends the connecting device's MAC address as the RADIUS username and password, allowing the server to authorize known devices.
Which Aruba feature allows different VLANs to be assigned to users based on RADIUS attributes returned after authentication?
Answer: Dynamic VLAN Assignment
Dynamic VLAN Assignment uses RADIUS attributes (such as Tunnel-Private-Group-ID) returned in the Access-Accept message to place clients in specific VLANs.
In a ClearPass Policy Manager enforcement policy, what happens when no enforcement profile matches the client's authentication result?
Answer: ClearPass applies the default enforcement profile configured in the service
When no rule in an enforcement policy matches, ClearPass falls through to the default enforcement profile defined for that service.