ACP Professional Standards & Best Practices 3 — Questions and Answers
Question 1: When implementing Aruba's Zero Trust Security framework, which principle is applied to every access request regardless of network location?
- Trust all internal network traffic by default
- Verify identity and posture before granting access to any resource (Correct answer)
- Grant full access after initial authentication is successful
- Apply security checks only at the network perimeter
Correct answer: Verify identity and posture before granting access to any resource
Zero Trust requires continuous verification of identity, device posture, and context before granting access, regardless of whether the request originates inside or outside the network.
Question 2: A company needs to onboard BYOD devices securely onto an Aruba wireless network. Which solution follows Aruba best practices?
- Assign BYOD devices to the same VLAN as corporate endpoints
- Use Aruba ClearPass Onboard to provision unique certificates to BYOD devices (Correct answer)
- Share a single WPA2-PSK passphrase with all users for BYOD access
- Allow BYOD devices to self-configure 802.1X without IT involvement
Correct answer: Use Aruba ClearPass Onboard to provision unique certificates to BYOD devices
Aruba ClearPass Onboard automates provisioning of unique device certificates, enabling secure, identity-based access for BYOD devices without sharing static credentials.
Question 3: What is the recommended Aruba practice for managing AP group configurations in a multi-site deployment?
- Configure each AP individually to allow site-specific customization
- Use AP groups with inheritance from global templates to maintain consistency (Correct answer)
- Assign all APs to the default group and configure site settings manually per AP
- Avoid AP groups and rely solely on SSID profiles for configuration
Correct answer: Use AP groups with inheritance from global templates to maintain consistency
AP groups with inherited global templates ensure configuration consistency across sites while allowing site-specific overrides where needed.
Question 4: During a ClearPass profiling deployment, an administrator notices unknown devices are not being profiled correctly. Which best practice should be reviewed first?
- Disable profiling for unknown devices to reduce false positives
- Verify that SNMP, HTTP User-Agent, and DHCP fingerprinting sources are enabled (Correct answer)
- Remove the unknown device category from ClearPass to simplify enforcement
- Limit profiling to 802.1X-authenticated devices only
Correct answer: Verify that SNMP, HTTP User-Agent, and DHCP fingerprinting sources are enabled
ClearPass relies on multiple data sources (SNMP, DHCP, HTTP User-Agent) for accurate device profiling; ensuring these sources are enabled is the first troubleshooting step.
Question 5: Which SSID design approach does Aruba recommend to reduce co-channel interference in high-density environments?
- Deploy as many SSIDs as possible to separate user groups
- Minimize the number of SSIDs broadcast per AP to reduce beacon overhead (Correct answer)
- Use hidden SSIDs for all employee networks
- Broadcast all SSIDs on both 2.4 GHz and 5 GHz bands simultaneously
Correct answer: Minimize the number of SSIDs broadcast per AP to reduce beacon overhead
Each SSID adds beacon overhead and increases channel contention; Aruba recommends keeping the number of active SSIDs per AP to a minimum (typically 3 or fewer).
Question 6: An Aruba engineer is asked to implement client isolation on a guest SSID. What is the primary security benefit of this configuration?
- It prevents guests from using more than 1 Mbps of bandwidth
- It blocks direct peer-to-peer communication between wireless clients on the same SSID (Correct answer)
- It restricts guest devices to IPv6 addressing only
- It forces guest clients to re-authenticate every 30 minutes
Correct answer: It blocks direct peer-to-peer communication between wireless clients on the same SSID
Client isolation prevents wireless clients on the same SSID from communicating directly with each other, protecting users from lateral attacks on shared networks.
Question 7: What is the Aruba best practice for placing the Mobility Controller in relation to the core network switch?
- Deploy the MC at the network edge, downstream from the access layer
- Deploy the MC in the data center or core, upstream from the distribution layer (Correct answer)
- Place the MC between the firewall and the internet for maximum visibility
- Co-locate the MC on the same rack as every access-layer switch
Correct answer: Deploy the MC in the data center or core, upstream from the distribution layer
Placing the MC at the core or data center ensures that all user traffic passes through the centralized policy enforcement point before reaching network resources.
When implementing Aruba's Zero Trust Security framework, which principle is applied to every access request regardless of network location?