โ† All ACMA Flashcard Decks

Authentication Methods Flashcards

7 cards from real ACMA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Authentication Methods flashcards as text
  1. What is Aruba's Downloadable User Roles (DUR) feature designed to accomplish?

    Answer: Push role configurations from ClearPass to APs at authentication time, eliminating pre-configuration on the AP

    Downloadable User Roles allow ClearPass to dynamically push complete role definitions (ACLs, policies) to Aruba APs via RADIUS VSAs, so roles don't need to be pre-configured on each AP.

  2. Which Aruba VSA (Vendor-Specific Attribute) is commonly used to assign a user role upon successful RADIUS authentication?

    Answer: Aruba-User-Role (Aruba VSA 1)

    Aruba-User-Role (VSA attribute 1, vendor ID 14823) is returned in the RADIUS Access-Accept to specify the role the client should be placed in.

  3. What distinguishes WPA3-Enterprise from WPA2-Enterprise in terms of authentication security?

    Answer: WPA3-Enterprise mandates 192-bit cryptographic suite and requires PMF

    WPA3-Enterprise (192-bit mode) mandates the use of GCMP-256/CCMP-256 encryption and requires Protected Management Frames (PMF/802.11w) to be mandatory.

  4. In ClearPass, what is the 'Authentication Method' configuration item used for?

    Answer: Defining which EAP types and inner methods the policy will accept

    An Authentication Method in ClearPass defines acceptable EAP types (e.g., PEAP, EAP-TLS, TTLS) and their inner methods, controlling how credentials are exchanged.

  5. What happens during RADIUS Change of Authorization (CoA) in an Aruba deployment?

    Answer: The RADIUS server proactively sends a new policy to the AP to modify or terminate an active session

    RADIUS CoA (RFC 5176) allows the RADIUS server to send unsolicited messages to the AP to change session attributes (e.g., role, VLAN) or disconnect a client mid-session.

  6. Which authentication scenario would most benefit from using EAP-FAST over EAP-PEAP?

    Answer: Environments where server certificate deployment is impractical but strong mutual auth is needed

    EAP-FAST uses Protected Access Credentials (PACs) instead of server certificates to establish the TLS tunnel, making it suitable when PKI infrastructure is unavailable.

  7. When an Aruba AP operates in 'bridge mode', where does 802.1X authentication processing occur?

    Answer: On the AP itself using a local RADIUS configuration

    In bridge mode (also called local forwarding), the AP handles 802.1X authentication locally and communicates directly with the configured RADIUS server without relaying through a controller.