ACMA Security Protocols & Network Access Control 3 — Questions and Answers
Question 1: Which protocol does Aruba ClearPass use to communicate posture and change-of-authorization (CoA) decisions back to the network device?
- TACACS+
- SNMP
- RADIUS with RFC 3576/5176 extensions (Correct answer)
- DIAMETER
Correct answer: RADIUS with RFC 3576/5176 extensions
ClearPass uses RADIUS CoA (RFC 3576/5176) to dynamically change a user's session attributes or disconnect the session after initial authentication.
Question 2: In an Aruba Instant (IAP) deployment, where is the 802.1X authentication typically terminated when using internal RADIUS?
- Each individual AP
- The Virtual Controller (Correct answer)
- An external ClearPass server
- The upstream switch
Correct answer: The Virtual Controller
In Aruba Instant, the Virtual Controller (VC) acts as the RADIUS server and terminates 802.1X authentication for all APs in the cluster when using internal RADIUS.
Question 3: What is the function of a Pre-Shared Key (PSK) SSID with MAC-based authentication bypass (MAB) in an Aruba environment?
- Allows any device to join without credentials
- Uses a device's MAC address as its username and password for RADIUS authentication (Correct answer)
- Combines WPA2 PSK with certificate authentication
- Provides open authentication with captive portal
Correct answer: Uses a device's MAC address as its username and password for RADIUS authentication
MAC Authentication Bypass (MAB) sends the device's MAC address as both the RADIUS username and password, allowing headless devices to authenticate without 802.1X supplicants.
Question 4: Which type of Aruba firewall rule allows traffic from a wireless client to reach the DHCP server before full 802.1X authentication completes?
- Post-authentication policy
- Pre-authentication (logon) policy (Correct answer)
- Captive portal policy
- Management policy
Correct answer: Pre-authentication (logon) policy
Pre-authentication (logon) policies permit essential bootstrap traffic like DHCP, DNS, and captive portal redirects before a user completes full authentication.
Question 5: What Aruba feature allows different WPA2-PSK passphrases to be assigned per user or device group on the same SSID?
- Multi-PSK
- MPSK Local
- Dynamic PSK
- PPSK (Private PSK) (Correct answer)
Correct answer: PPSK (Private PSK)
Aruba's Private PSK (PPSK) assigns a unique passphrase per user or device, enabling individual access control and audit tracking on a single PSK SSID.
Question 6: In WPA2-Enterprise, which 4-way handshake key is derived fresh for each authentication session to provide forward secrecy?
- PSK (Pre-Shared Key)
- PMK (Pairwise Master Key)
- PTK (Pairwise Transient Key) (Correct answer)
- GMK (Group Master Key)
Correct answer: PTK (Pairwise Transient Key)
The PTK is derived fresh during each 4-way handshake from the PMK and random nonces, ensuring session-unique encryption keys that provide forward secrecy.
Question 7: Which Aruba ClearPass component provides guest self-registration portals and sponsor-based approval workflows?
- ClearPass Policy Manager
- ClearPass Guest (Correct answer)
- ClearPass Onboard
- ClearPass OnGuard
Correct answer: ClearPass Guest
ClearPass Guest provides the web portals, self-registration forms, and sponsor approval workflows used to manage guest network access.
Which protocol does Aruba ClearPass use to communicate posture and change-of-authorization (CoA) decisions back to the network device?