ACMA Security Protocols & Network Access Control 2 — Questions and Answers
Question 1: Which 802.1X authentication framework component is responsible for making the final access decision based on user credentials?
- Supplicant
- Authenticator
- Authentication Server (Correct answer)
- Network Access Server
Correct answer: Authentication Server
The Authentication Server (typically a RADIUS server) validates credentials and makes the final access decision in the 802.1X framework.
Question 2: In Aruba's ClearPass Policy Manager, what is the primary purpose of an Enforcement Profile?
- Define which users can log in
- Specify the network access attributes applied after authentication (Correct answer)
- Collect device posture information
- Manage RADIUS shared secrets
Correct answer: Specify the network access attributes applied after authentication
An Enforcement Profile in ClearPass defines the set of attributes (VLAN, role, ACL) that are applied to a session after successful authentication and authorization.
Question 3: What EAP method provides both server-side and client-side certificate authentication, making it one of the most secure options?
- EAP-PEAP
- EAP-TLS (Correct answer)
- EAP-TTLS
- EAP-FAST
Correct answer: EAP-TLS
EAP-TLS requires certificates on both the server and the client, providing mutual authentication and strong security.
Question 4: In Aruba WPA3-Enterprise, what is the minimum key length required for the CNSA suite mode?
- 128-bit AES
- 192-bit AES (Correct answer)
- 256-bit AES
- 512-bit AES
Correct answer: 192-bit AES
WPA3-Enterprise CNSA (Commercial National Security Algorithm) suite mode requires a minimum of 192-bit AES encryption.
Question 5: When a wireless client is placed in a VLAN after 802.1X authentication, which component on an Aruba controller sends the VLAN assignment back to the AP?
- RADIUS server
- Mobility Controller (Correct answer)
- ClearPass
- DNS server
Correct answer: Mobility Controller
The Aruba Mobility Controller receives the RADIUS Access-Accept (with VLAN attributes) and then communicates the VLAN assignment to the AP over the GRE tunnel.
Question 6: Which Aruba security feature inspects client traffic for malicious activity and can quarantine devices without requiring network re-authentication?
- Adaptive Radio Management (ARM)
- RFProtect
- AppRF
- Aruba Intrusion Detection System (IDS) (Correct answer)
Correct answer: Aruba Intrusion Detection System (IDS)
Aruba's IDS monitors wireless frames for attack signatures and can quarantine suspicious clients without forcing a full re-authentication cycle.
Question 7: What does the 'role' concept in Aruba's firewall policy engine represent?
- The physical AP a client is connected to
- A named policy container that defines traffic permissions for a user or device group (Correct answer)
- The SSID the user is associated with
- The VLAN tag used for the user's traffic
Correct answer: A named policy container that defines traffic permissions for a user or device group
A role in Aruba's stateful firewall is a named container that groups ACL policies and is assigned to users or devices based on their identity or posture.
Which 802.1X authentication framework component is responsible for making the final access decision based on user credentials?