ACMA Mobility Architecture & Infrastructure 3 — Questions and Answers
Question 1: When an Aruba AP operates in 'split-tunnel' mode, what traffic is sent directly to the local network without going through the controller?
- All encrypted 802.11 frames
- Corporate VPN traffic
- Guest or internet-bound traffic defined by policy (Correct answer)
- Management traffic from the AP
Correct answer: Guest or internet-bound traffic defined by policy
In split-tunnel mode, traffic matching local breakout policies (e.g., guest internet) exits locally while corporate traffic tunnels to the controller.
Question 2: Which layer of the OSI model does Aruba's GRE tunnel between an AP and controller primarily operate at?
- Layer 1
- Layer 2
- Layer 3 (Correct answer)
- Layer 7
Correct answer: Layer 3
GRE tunnels between APs and controllers encapsulate Layer 2 frames within Layer 3 IP packets routed across the network.
Question 3: In Aruba's 'campus AP' deployment model, which device terminates 802.11 associations and processes user authentication?
- The AP itself in autonomous mode
- The Mobility Controller (Correct answer)
- The upstream router
- ClearPass exclusively
Correct answer: The Mobility Controller
In campus mode, APs are lightweight and forward all 802.11 frames to the Mobility Controller, which terminates associations and enforces authentication.
Question 4: What Aruba feature allows APs deployed in remote offices to terminate their tunnels to a controller over the internet securely?
- Remote AP (RAP) (Correct answer)
- Air Monitor
- Mesh Portal
- Spectrum Monitor
Correct answer: Remote AP (RAP)
Remote APs use IPsec to establish a secure tunnel to the controller across the internet, enabling home or branch office deployments.
Question 5: In Aruba's Virtual AP (VAP) architecture, what does each VAP map to on the physical AP?
- A separate physical radio
- A distinct SSID with its own set of policies (Correct answer)
- A unique CAPWAP tunnel
- A separate controller connection
Correct answer: A distinct SSID with its own set of policies
Each VAP represents an SSID with its own security, QoS, and forwarding policies broadcast by a single physical AP radio.
Question 6: Which Aruba product line is purpose-built for branch office deployments, combining switching, routing, and wireless in one device?
- Aruba 7000 Series Controller
- Aruba 9000 Series Gateway (Correct answer)
- Aruba Instant On AP
- Aruba 2530 Switch
Correct answer: Aruba 9000 Series Gateway
The Aruba 9000 Series SD-WAN Gateways provide integrated WAN, LAN switching, and wireless termination for branch deployments.
Question 7: When configuring Aruba APs for a high-density environment, which AP placement strategy is most recommended?
- Maximize AP transmit power to cover as much area as possible
- Reduce cell size using lower power and higher AP density (Correct answer)
- Use only 2.4 GHz to penetrate walls better
- Place APs only in hallways to reduce interference
Correct answer: Reduce cell size using lower power and higher AP density
High-density environments benefit from smaller, lower-power cells with more APs to handle more concurrent clients per radio.
When an Aruba AP operates in 'split-tunnel' mode, what traffic is sent directly to the local network without going through the controller?