Authentication Methods Flashcards
7 cards from real ACMA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Authentication Methods flashcards as text
What is the purpose of RADIUS accounting in an Aruba wireless deployment?
Answer: To track session start, stop, and interim usage data for connected clients
RADIUS accounting records session events (Start, Stop, Interim-Update) including duration, bytes transferred, and termination cause for auditing and billing.
Which protocol does Aruba use to carry EAP messages between the wireless AP and the RADIUS authentication server?
Answer: RADIUS (UDP)
EAP messages are encapsulated in RADIUS packets (UDP port 1812 for authentication) between the AP (authenticator) and the RADIUS server.
In Aruba's captive portal authentication, at what point is the client's traffic allowed onto the network?
Answer: After the client completes credentials entry on the portal page
In captive portal authentication, the client associates and receives limited connectivity, then is fully admitted only after submitting valid credentials via the web portal.
What is the function of the RADIUS attribute 'Class' (attribute 25) in Aruba deployments?
Answer: Carries opaque data from the authentication server that is echoed back in accounting messages
The Class attribute is an opaque value set by the RADIUS server that the NAS must include in all subsequent accounting messages for that session.
Which EAP type creates an encrypted TLS tunnel first and then authenticates the user with a legacy method such as PAP inside the tunnel?
Answer: EAP-TTLS
EAP-TTLS (Tunneled TLS) establishes an outer TLS tunnel using a server certificate, then runs an inner authentication method (e.g., PAP, CHAP, MSCHAPv2) inside the tunnel.
When a RADIUS server returns an Access-Reject, what does an Aruba AP typically do with the wireless client by default?
Answer: Sends an 802.11 Deauthentication frame to the client
Upon receiving an Access-Reject from the RADIUS server, the AP denies access and sends a deauthentication frame, disconnecting the client from the SSID.
In Aruba's role-based access control, what is a 'user role' primarily used for?
Answer: Applying firewall policies and bandwidth limits to authenticated clients
A user role in Aruba defines the set of firewall policies, ACLs, and bandwidth contracts applied to a client after authentication.