โ† All ACMA Flashcard Decks

Security Protocols & Network Access Control Flashcards

7 cards from real ACMA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Protocols & Network Access Control flashcards as text
  1. What is the purpose of the Aruba 'captive portal' authentication method in a guest network scenario?

    Answer: Redirects unauthenticated HTTP/HTTPS clients to a login or acceptance page

    Captive portal intercepts web traffic from unauthenticated clients and redirects them to a login or terms-of-service page before granting internet access.

  2. When configuring an Aruba SSID for WPA3-Personal, which key exchange protocol replaces the traditional PSK 4-way handshake?

    Answer: Simultaneous Authentication of Equals (SAE)

    WPA3-Personal uses SAE (Dragonfly handshake) instead of the traditional PSK 4-way handshake, providing resistance to offline dictionary attacks.

  3. What is the default behavior of Aruba's 'deny all' implicit rule at the end of every user role's firewall policy?

    Answer: Silently drops all traffic not explicitly permitted by earlier rules

    Aruba's implicit deny rule at the end of each role silently drops any traffic that does not match a preceding permit rule, following standard firewall best practice.

  4. In Aruba ClearPass, what is an 'Endpoint' context used for in an authorization policy?

    Answer: To query device attributes (OS, posture, MDM status) stored in the Endpoints repository

    The Endpoint context in ClearPass authorization policies allows rules to reference device attributes such as OS type, MDM enrollment status, or posture check results.

  5. Which Aruba feature prevents a wireless client from communicating directly with other clients on the same SSID at Layer 2?

    Answer: Client isolation (also called wireless client isolation or PSPF)

    Client isolation (Publicly Secure Packet Forwarding / PSPF) blocks direct client-to-client Layer 2 forwarding on the same SSID, commonly used in guest networks.

  6. What RFC defines the RADIUS attribute VSA (Vendor-Specific Attribute) mechanism that Aruba uses to pass proprietary policy information?

    Answer: RFC 2865

    RFC 2865 (Remote Authentication Dial-In User Service) defines the core RADIUS protocol including Attribute 26 for Vendor-Specific Attributes (VSAs).

  7. Which 802.11 management frame protection feature, supported in WPA3, helps prevent deauthentication and disassociation attacks?

    Answer: 802.11w (MFP - Management Frame Protection)

    802.11w (Protected Management Frames / MFP) cryptographically protects deauthentication and disassociation frames, preventing spoofed disconnection attacks.