โ† All ACMA Flashcard Decks

Security Protocols & Network Access Control Flashcards

7 cards from real ACMA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Protocols & Network Access Control flashcards as text
  1. Which protocol does Aruba ClearPass use to communicate posture and change-of-authorization (CoA) decisions back to the network device?

    Answer: RADIUS with RFC 3576/5176 extensions

    ClearPass uses RADIUS CoA (RFC 3576/5176) to dynamically change a user's session attributes or disconnect the session after initial authentication.

  2. In an Aruba Instant (IAP) deployment, where is the 802.1X authentication typically terminated when using internal RADIUS?

    Answer: The Virtual Controller

    In Aruba Instant, the Virtual Controller (VC) acts as the RADIUS server and terminates 802.1X authentication for all APs in the cluster when using internal RADIUS.

  3. What is the function of a Pre-Shared Key (PSK) SSID with MAC-based authentication bypass (MAB) in an Aruba environment?

    Answer: Uses a device's MAC address as its username and password for RADIUS authentication

    MAC Authentication Bypass (MAB) sends the device's MAC address as both the RADIUS username and password, allowing headless devices to authenticate without 802.1X supplicants.

  4. Which type of Aruba firewall rule allows traffic from a wireless client to reach the DHCP server before full 802.1X authentication completes?

    Answer: Pre-authentication (logon) policy

    Pre-authentication (logon) policies permit essential bootstrap traffic like DHCP, DNS, and captive portal redirects before a user completes full authentication.

  5. What Aruba feature allows different WPA2-PSK passphrases to be assigned per user or device group on the same SSID?

    Answer: PPSK (Private PSK)

    Aruba's Private PSK (PPSK) assigns a unique passphrase per user or device, enabling individual access control and audit tracking on a single PSK SSID.

  6. In WPA2-Enterprise, which 4-way handshake key is derived fresh for each authentication session to provide forward secrecy?

    Answer: PTK (Pairwise Transient Key)

    The PTK is derived fresh during each 4-way handshake from the PMK and random nonces, ensuring session-unique encryption keys that provide forward secrecy.

  7. Which Aruba ClearPass component provides guest self-registration portals and sponsor-based approval workflows?

    Answer: ClearPass Guest

    ClearPass Guest provides the web portals, self-registration forms, and sponsor approval workflows used to manage guest network access.