ACMA Network Security 2 — Questions and Answers
Question 1: Which Aruba security feature automatically classifies and contains rogue APs detected on the wireless network?
- Air Monitor
- Wireless Intrusion Protection (WIP) (Correct answer)
- RFProtect
- Spectrum Analysis
Correct answer: Wireless Intrusion Protection (WIP)
Wireless Intrusion Protection (WIP) detects, classifies, and contains rogue APs and other wireless threats.
Question 2: What is the purpose of 802.1X port-based authentication in an Aruba wired environment?
- To encrypt traffic between switch and AP
- To assign VLANs based on CDP neighbors
- To authenticate devices before granting network access (Correct answer)
- To prevent STP topology changes
Correct answer: To authenticate devices before granting network access
802.1X authenticates devices at the port level before allowing them to access network resources.
Question 3: In Aruba ClearPass, what component issues certificates and enforces posture assessment?
- ClearPass Guest
- ClearPass OnGuard
- ClearPass Policy Manager (Correct answer)
- ClearPass Device Insight
Correct answer: ClearPass Policy Manager
ClearPass Policy Manager is the core engine that enforces authentication, authorization, and posture policies.
Question 4: Which attack does Aruba's 'STA blacklisting' feature primarily defend against?
- Evil twin AP attacks
- Repeated authentication failures or brute-force attempts (Correct answer)
- Deauthentication flood attacks
- ARP poisoning from client devices
Correct answer: Repeated authentication failures or brute-force attempts
STA blacklisting blocks client stations that repeatedly fail authentication, mitigating brute-force attacks.
Question 5: What security mode does Aruba recommend when deploying WPA3 in a mixed environment with WPA2 clients?
- WPA3-Personal only
- WPA2/WPA3 Transition Mode (Correct answer)
- WPA3-Enterprise only
- Open Enhanced mode
Correct answer: WPA2/WPA3 Transition Mode
WPA2/WPA3 Transition Mode allows both WPA2 and WPA3 clients to connect to the same SSID simultaneously.
Question 6: Which Aruba feature uses DHCP fingerprinting and HTTP user-agent strings to identify client device types?
- AirMatch
- AppRF
- Device Fingerprinting in ClearPass (Correct answer)
- ArubaOS Firewall Policies
Correct answer: Device Fingerprinting in ClearPass
ClearPass Device Fingerprinting uses DHCP, HTTP, and other attributes to identify and profile endpoint device types.
Question 7: What is the role of the 'trusted' flag on an Aruba AP port in the context of network security?
- It disables encryption on that port
- It allows the AP to forward traffic without firewall policy inspection
- It marks the uplink as a legitimate wired infrastructure port, suppressing rogue detection on it (Correct answer)
- It assigns the port to a trusted VLAN automatically
Correct answer: It marks the uplink as a legitimate wired infrastructure port, suppressing rogue detection on it
Marking an AP port as trusted tells the system it is a valid infrastructure uplink so it is not flagged as a rogue.
Which Aruba security feature automatically classifies and contains rogue APs detected on the wireless network?