ACMA Network Security 5 — Questions and Answers
Question 1: What Aruba technology allows an AP to serve both as an access point and monitor the RF environment for threats simultaneously?
- Dual-band radio mode
- Air Monitor (AM) mode with hybrid AP (Correct answer)
- Spectrum analysis mode
- Adaptive Radio Management (ARM)
Correct answer: Air Monitor (AM) mode with hybrid AP
Hybrid AP mode allows an AP to serve clients on one radio while the other radio operates as an Air Monitor for threat detection.
Question 2: Which Aruba Mobility Controller feature prevents IP spoofing by validating that a client's source IP matches its DHCP-assigned address?
- ARP inspection
- IP Spoofing Protection (IP anti-spoof) (Correct answer)
- Source NAT policy
- DHCP Snooping on the AP
Correct answer: IP Spoofing Protection (IP anti-spoof)
IP Spoofing Protection checks that a client's source IP matches the address assigned by DHCP, dropping packets with mismatched source IPs.
Question 3: When Aruba ClearPass OnGuard performs a posture check, which of the following would cause a client to be assigned to a 'quarantine' role?
- Client authenticates with a valid certificate
- Client's antivirus definitions are out of date (Correct answer)
- Client connects from an approved MAC address
- Client uses WPA3-Personal
Correct answer: Client's antivirus definitions are out of date
Outdated antivirus definitions fail posture requirements, causing ClearPass to assign the client to a restricted quarantine role.
Question 4: In Aruba role-based access, what is the 'logon' role primarily used for?
- Granting full network access after authentication
- Providing limited access before authentication completes, typically for captive portal redirect (Correct answer)
- Assigning administrator privileges to controllers
- Enabling 802.1X supplicant functionality
Correct answer: Providing limited access before authentication completes, typically for captive portal redirect
The logon role grants minimal access before a user authenticates, allowing only the traffic needed to complete the authentication process.
Question 5: Which Aruba feature detects and alerts on ad-hoc wireless networks formed between client devices?
- Client Match
- Wireless Intrusion Detection (WID) (Correct answer)
- Adaptive Radio Management
- ClearPass Profiling
Correct answer: Wireless Intrusion Detection (WID)
Wireless Intrusion Detection identifies ad-hoc networks, which bypass infrastructure controls and pose a security risk.
Question 6: What security advantage does Aruba's tunnel-mode SSID provide over bridge-mode for sensitive corporate traffic?
- Tunnel mode enables WPA3 while bridge mode only supports WPA2
- Tunnel mode sends all client traffic to the controller for centralized firewall inspection before routing (Correct answer)
- Bridge mode provides higher throughput for security scanning
- Tunnel mode encrypts traffic end-to-end to the internet
Correct answer: Tunnel mode sends all client traffic to the controller for centralized firewall inspection before routing
Tunnel mode forwards all wireless client traffic to the Mobility Controller, where centralized firewall and policy enforcement is applied before routing.
Question 7: Which standard defines the EAP-TLS authentication method commonly deployed in Aruba enterprise WLANs?
- IEEE 802.11i
- RFC 5216 (Correct answer)
- IEEE 802.1X
- RFC 3748
Correct answer: RFC 5216
RFC 5216 defines EAP-TLS, which uses mutual certificate-based authentication and is the strongest EAP method for enterprise deployments.
What Aruba technology allows an AP to serve both as an access point and monitor the RF environment for threats simultaneously?