ACP Security and Access Control 3 — Questions and Answers
Question 1: Which Aruba ClearPass service type is used to handle MAC Authentication Bypass (MAB) for devices that cannot perform 802.1X?
- RADIUS Authorization
- MAC Authentication (Correct answer)
- Web-Based Authentication
- TACACS+ Accounting
Correct answer: MAC Authentication
ClearPass's MAC Authentication service type processes MAB requests where the device's MAC address is used as both the username and password.
Question 2: An administrator wants to prevent rogue DHCP servers on an Aruba-managed wired network. Which feature should be enabled?
- Dynamic ARP Inspection
- DHCP Snooping (Correct answer)
- IP Source Guard
- Port Security
Correct answer: DHCP Snooping
DHCP Snooping builds a binding table of valid DHCP leases and drops DHCP offers or acks from untrusted ports, blocking rogue DHCP servers.
Question 3: What is the primary function of Aruba's 'Air Monitor' (AM) mode?
- To serve client traffic on a dedicated 5 GHz radio
- To scan the RF environment for rogue APs and wireless threats without serving clients (Correct answer)
- To extend coverage by acting as a wireless mesh node
- To perform spectrum analysis for cable fault detection
Correct answer: To scan the RF environment for rogue APs and wireless threats without serving clients
An AP in Air Monitor mode dedicates its radios entirely to WIDS/WIPS scanning, detecting rogue APs, ad-hoc networks, and wireless attacks.
Question 4: Which Aruba security feature automatically contains a rogue AP by sending deauthentication frames to its clients?
- Rogue AP Tagging
- Wireless Intrusion Prevention (WIPS) Containment (Correct answer)
- SSID Cloaking
- Band Steering
Correct answer: Wireless Intrusion Prevention (WIPS) Containment
Aruba WIPS can actively contain rogue APs by sending 802.11 deauthentication frames, disconnecting clients that associate with the rogue.
Question 5: In ClearPass Policy Manager, what is a 'Posture Policy' used for?
- Controlling administrator login time windows
- Assessing endpoint health (antivirus, patch level, OS) and returning a posture token (Correct answer)
- Configuring RADIUS proxy failover settings
- Managing guest self-registration workflows
Correct answer: Assessing endpoint health (antivirus, patch level, OS) and returning a posture token
A Posture Policy in ClearPass evaluates the security health of an endpoint and produces a posture token (Healthy, Checkup, Quarantine, Infected) used in enforcement decisions.
Question 6: Which Aruba Mobility Controller feature restricts a wireless client from communicating directly with other clients on the same SSID?
- Client Match
- Proxy ARP
- Client Isolation (Correct answer)
- STP PortFast
Correct answer: Client Isolation
Client Isolation (also called station isolation) prevents wireless clients associated to the same SSID or BSSID from sending traffic directly to each other.
Question 7: What does 'Protected Management Frames' (PMF / 802.11w) protect against in a wireless network?
- Weak WPA2 passphrases
- Spoofed deauthentication and disassociation frames used in DoS attacks (Correct answer)
- Rogue DHCP server responses
- Unauthorized changes to AP configuration
Correct answer: Spoofed deauthentication and disassociation frames used in DoS attacks
802.11w (PMF) cryptographically protects unicast and broadcast management frames, preventing attackers from forging deauth/disassoc frames to disconnect clients.
Which Aruba ClearPass service type is used to handle MAC Authentication Bypass (MAB) for devices that cannot perform 802.1X?