Configuration & Troubleshooting of Aruba Solutions Flashcards
7 cards from real ACMA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Configuration & Troubleshooting of Aruba Solutions flashcards as text
An admin wants to configure port-based 802.1X authentication on an Aruba switch uplink port. Which port mode should be avoided for this configuration?
Answer: Trunk mode
802.1X port-based authentication is not applicable to trunk ports, which carry multiple VLANs between infrastructure devices and do not authenticate end users.
In ArubaOS, what does the 'aaa profile' bind together for a given SSID?
Answer: Authentication method, server group, and default user role
An AAA profile links the authentication method (802.1X, MAC, captive portal), the RADIUS server group, and the default role assigned to authenticated users.
A client successfully connects to an Aruba SSID but cannot reach the internet. The 'show user' command shows the client in the 'logon' role. What does this indicate?
Answer: Authentication has not completed; the client is in the pre-authentication role
The 'logon' role is the default pre-authentication role; if a client remains there, it means authentication (802.1X, captive portal, or MAC auth) has not succeeded.
When deploying Aruba Central for cloud management, which protocol does the AP use to establish its management tunnel to Aruba Central?
Answer: HTTPS over port 443
Aruba APs managed by Aruba Central use HTTPS (port 443) to establish the management connection to the cloud platform.
An Aruba controller shows high CPU utilization. An admin suspects rogue AP processing is consuming resources. Which command would help identify the number of rogues being tracked?
Answer: show ap monitor ap-list | count
Piping 'show ap monitor ap-list' through count reveals how many neighboring APs are being tracked, which directly impacts CPU load from rogue processing.
An administrator needs to ensure that traffic from IoT devices on VLAN 40 cannot communicate with corporate devices on VLAN 10. What Aruba feature enforces this segmentation?
Answer: Firewall policies within user roles assigned to each VLAN
ArubaOS stateful firewall policies within user roles can deny inter-VLAN traffic, providing role-based network segmentation between IoT and corporate devices.
After upgrading ArubaOS on a Mobility Controller, some APs remain on the previous firmware version. What is the correct way to upgrade AP firmware?
Answer: AP firmware upgrades automatically when the AP reboots after controller upgrade
Aruba APs automatically download and install the firmware image from the controller the next time they reboot or reconnect, so a controller upgrade triggers AP firmware updates on reconnection.