ACMA Network Security 4 — Questions and Answers
Question 1: In Aruba ClearPass, what is the function of an 'Enforcement Profile'?
- It defines the RADIUS server group to query
- It specifies the actions applied to a session after policy evaluation, such as VLAN assignment (Correct answer)
- It stores user credentials for local authentication
- It schedules compliance scans for endpoints
Correct answer: It specifies the actions applied to a session after policy evaluation, such as VLAN assignment
Enforcement Profiles define what actions ClearPass applies to an authenticated session, such as assigning a VLAN or applying a role.
Question 2: Which Aruba mechanism prevents a compromised controller from being used to intercept AP communication by validating controller identity?
- ArubaOS Firewall
- AP Whitelist
- Certificate-based AP provisioning using factory-installed certificates (Correct answer)
- PAPI encryption with shared secrets
Correct answer: Certificate-based AP provisioning using factory-installed certificates
Aruba APs use factory-installed X.509 certificates to mutually authenticate with controllers, preventing rogue controller attacks.
Question 3: What is the difference between 'deny' and 'blacklist' actions in an Aruba firewall policy?
- Deny drops packets silently; blacklist drops and sends an SNMP trap
- Deny blocks matching traffic; blacklist blocks ALL traffic from that client for a configured duration (Correct answer)
- Blacklist requires RADIUS; deny works locally only
- They are functionally identical in ArubaOS
Correct answer: Deny blocks matching traffic; blacklist blocks ALL traffic from that client for a configured duration
Deny blocks only the specific matching traffic, while blacklist blocks all traffic from the offending client for a set time period.
Question 4: Which Aruba feature inspects Layer 7 application traffic to enforce policies based on application type?
- AirMatch
- AppRF (Correct answer)
- RFProtect
- ClientMatch
Correct answer: AppRF
AppRF uses deep packet inspection at Layer 7 to identify and enforce policies based on specific applications.
Question 5: When configuring a RADIUS server in Aruba Mobility Controller, what is the purpose of the 'NAS IP' setting?
- It defines the IP the controller uses as the source of RADIUS packets (Correct answer)
- It sets the IP address of the RADIUS server
- It configures NAT for RADIUS traffic
- It enables RADIUS over IPv6
Correct answer: It defines the IP the controller uses as the source of RADIUS packets
The NAS IP defines the source IP address that the controller uses when sending RADIUS authentication and accounting requests.
Question 6: Which attack is mitigated by enabling 'Management Frame Protection' (802.11w) on an Aruba SSID?
- Passive eavesdropping of data frames
- Deauthentication and disassociation flood attacks (Correct answer)
- WEP key recovery attacks
- ARP cache poisoning
Correct answer: Deauthentication and disassociation flood attacks
802.11w (MFP) cryptographically protects management frames, preventing spoofed deauthentication and disassociation attacks.
Question 7: In an Aruba environment, what does a 'captive portal' primarily provide in terms of network security?
- Encrypted tunneling for guest users
- User identity collection and acceptance of terms before granting network access (Correct answer)
- 802.1X authentication for corporate devices
- Deep packet inspection for malware
Correct answer: User identity collection and acceptance of terms before granting network access
A captive portal redirects unauthenticated users to a web page for credential entry or ToS acceptance before granting internet access.
In Aruba ClearPass, what is the function of an 'Enforcement Profile'?