Aruba Certified Switching Professional (ACSP) HPE6-A73 — Questions and Answers
Question 1: What does the 'show logging' command display on an Aruba switch?
- The NTP server synchronization status
- Buffered syslog messages stored in the switch's memory (Correct answer)
- The debug output of active troubleshooting sessions
- The SNMP trap log sent to external servers
Correct answer: Buffered syslog messages stored in the switch's memory
The 'show logging' command displays the syslog messages that have been stored in the switch's internal logging buffer.
Question 2: Which IPv6 transition technology transports IPv6 packets across an IPv4-only network by encapsulating them in IPv4 headers using protocol number 41?
- IPv4-mapped IPv6 addresses
- IPv6-in-IPv4 tunneling (6in4) (Correct answer)
- Dual-stack deployment
- NAT64
Correct answer: IPv6-in-IPv4 tunneling (6in4)
IPv6-in-IPv4 tunneling (6in4, protocol 41) encapsulates IPv6 packets within IPv4 headers to carry IPv6 traffic across networks that only support IPv4.
Question 3: What happens to traffic on a VSX setup when the ISL fails but both switches remain operational?
- LACP on the ISL forces a re-election
- Both switches continue forwarding normally with no impact
- The secondary switch shuts down all its access ports to prevent split-brain loops (Correct answer)
- All traffic is redirected through the keepalive link
Correct answer: The secondary switch shuts down all its access ports to prevent split-brain loops
If the ISL fails while both VSX peers are still alive, the secondary switch disables its access ports to avoid a split-brain loop scenario.
Question 4: Which hashing algorithm component is NOT typically used by Aruba CX switches for LAG load balancing?
- Source and destination MAC address
- Source and destination IP address
- VLAN ID of the frame (Correct answer)
- Layer 4 source and destination port
Correct answer: VLAN ID of the frame
LAG load balancing hashes on MAC, IP, and L4 port fields, but VLAN ID is not a standard hashing input for load distribution.
Question 5: When redistributing static routes into OSPF on an Aruba AOS-CX switch, which command is used and what default metric type is applied?
- redistribute static, Type 1 (E1) by default
- import static, Type 1 (E1) by default
- inject static, Type 2 (E2) by default
- redistribute static, Type 2 (E2) by default (Correct answer)
Correct answer: redistribute static, Type 2 (E2) by default
The 'redistribute static' command under router ospf injects static routes as OSPF external routes with Type 2 (E2) metric by default.
Question 6: Two Aruba CX switches are connected with a LAG. The administrator notices only half the expected bandwidth is being utilized. What should be investigated first?
- The load-balancing hash may be producing skewed distribution (Correct answer)
- LACP timers are mismatched between the switches
- One of the LAG member ports may be operating at half-duplex
- The LAG MTU is set too low
Correct answer: The load-balancing hash may be producing skewed distribution
Uneven LAG utilization is most commonly caused by hash polarization, where most flows map to the same member port.
Question 7: Which mechanism on Aruba switches prevents an unauthorized host from using an IP address not assigned by DHCP?
- Port Security MAC limit
- IP Source Guard (Correct answer)
- DHCP Snooping alone
- Dynamic ARP Inspection
Correct answer: IP Source Guard
IP Source Guard filters packets based on the DHCP snooping binding table, preventing hosts from using IP addresses not assigned by DHCP.
Question 8: Which of the following is a valid reason to place an extended ACL close to the traffic source on an Aruba switch?
- Extended ACLs only function correctly near the source
- To drop unwanted traffic early and reduce unnecessary transit (Correct answer)
- Because standard ACLs cannot be applied near the source
- To save ACL TCAM resources on core switches
Correct answer: To drop unwanted traffic early and reduce unnecessary transit
Placing extended ACLs near the source drops unwanted traffic before it traverses the network, reducing bandwidth consumption on transit links.
Question 9: In a two-router VRRP setup, both routers report as master simultaneously. What is the most likely cause?
- The virtual IP matches both routers' physical IP addresses
- The advertisement multicast traffic between the routers is blocked (Correct answer)
- VRRP preemption is disabled on both routers
- Both routers have the same VRID configured
Correct answer: The advertisement multicast traffic between the routers is blocked
A split-brain scenario (dual masters) typically occurs when VRRP advertisement multicasts cannot reach each other, causing each router to believe the other has failed.
Question 10: Which authentication type is supported by VRRPv2 but was deprecated in VRRPv3?
- SHA-256 HMAC
- Simple text (plain-text) password (Correct answer)
- MD5 keyed hash
- PKI certificate-based authentication
Correct answer: Simple text (plain-text) password
VRRPv2 supported simple text (Type 1) and MD5 (Type 2) authentication, but both were deprecated in VRRPv3 as RFC 5798 does not include VRRP authentication.
Question 11: Which OSPF neighbor state indicates that the two Aruba switches have fully synchronized their link-state databases?
- FULL (Correct answer)
- EXCHANGE
- LOADING
- 2-WAY
Correct answer: FULL
The FULL state means both routers have identical LSDBs and the adjacency is complete; this is the desired end state for OSPF neighbors.
Question 12: What is the function of a BGP Route Distinguisher (RD) in EVPN?
- To indicate which VNI is directly associated with a specific BGP EVPN route
- To make EVPN routes globally unique in the BGP table when the same prefix exists in multiple VRFs (Correct answer)
- To set the administrative distance of routes learned via EVPN
- To encrypt EVPN routes during BGP advertisement between VTEPs
Correct answer: To make EVPN routes globally unique in the BGP table when the same prefix exists in multiple VRFs
An RD is prepended to EVPN routes to make them globally unique in the BGP table, allowing identical prefixes from different VRFs or tenants to coexist without ambiguity.
Question 13: What happens to packets that exceed the configured police rate when the action is set to 'drop' on an Aruba switch?
- Packets are buffered until rate decreases
- Packets are queued in the lowest-priority queue
- Packets are remarked to a lower DSCP and forwarded
- Packets are discarded immediately (Correct answer)
Correct answer: Packets are discarded immediately
With a police action of 'drop', packets exceeding the committed rate are immediately discarded rather than buffered or remarked.
Question 14: What does SSL/TLS encryption provide?
- Authentication
- Data integrity
- Confidentiality
- All of the above
SSL/TLS encryption provides a comprehensive suite of security features for communication over a network. It ensures confidentiality by encrypting data, preventing eavesdropping. It also provides data integrity, guaranteeing that data has not been tampered with during transit, and authentication, verifying the identity of the communicating parties.
Question 15: On an ArubaOS-CX switch, which ports are exempt from DAI validation by default?
- Ports with port security enabled
- Trunk ports only
- Trusted ports (Correct answer)
- Ports in the default VLAN
Correct answer: Trusted ports
DAI trusted ports (typically uplinks) bypass ARP inspection, while all untrusted ports have their ARP packets validated against the binding database.
Question 16: When configuring a VSX MCLAG (Multi-Chassis LAG), what must be consistent on both VSX peers for the LAG to function correctly?
- STP port cost must be set to 0 on both peers
- Interface speed must be identical on both peers
- The LACP system-ID and port-channel configuration must match (Correct answer)
- Both peers must use the same physical uplink count
Correct answer: The LACP system-ID and port-channel configuration must match
MCLAG requires the same LACP system-ID (configured as VSX system-MAC) and matching port-channel parameters on both peers so the downstream device sees a single logical LAG.
Question 17: A network administrator wants to prevent man-in-the-middle attacks that leverage ARP spoofing. They have already enabled DHCP Snooping on the user access VLANs. Which additional security feature must be enabled to validate ARP packets against the DHCP Snooping binding database?
- Control Plane Policing (CoPP)
- Port Security
- RA Guard
- Dynamic ARP Inspection (DAI) (Correct answer)
Correct answer: Dynamic ARP Inspection (DAI)
Dynamic ARP Inspection (DAI) is the feature designed to mitigate ARP spoofing attacks. It intercepts ARP packets on untrusted ports and validates the IP-to-MAC address binding against the trusted database built by DHCP Snooping. Port Security limits MAC addresses, CoPP protects the CPU, and RA Guard is for IPv6 rogue router advertisements.
Question 18: In an Aruba OSPF network, which LSA type is flooded only within its originating area and describes the router's own links?
- Type 1 Router LSA (Correct answer)
- Type 2 Network LSA
- Type 5 AS External LSA
- Type 3 Summary LSA
Correct answer: Type 1 Router LSA
Type 1 Router LSAs are generated by every OSPF router and describe all its links and states; they are flooded only within the originating area.
Question 19: On an Aruba switch, what is the effect of setting a VLAN to 'voice' type on an access port?
- It blocks all non-voice traffic on that port
- It enables LLDP-MED to automatically configure IP phones on a separate voice VLAN (Correct answer)
- It encrypts all voice traffic on the VLAN
- It assigns QoS markings to all frames on the port
Correct answer: It enables LLDP-MED to automatically configure IP phones on a separate voice VLAN
Setting a VLAN type to 'voice' allows LLDP-MED to signal IP phones to use the designated voice VLAN automatically.
Question 20: On an Aruba CX switch, which spanning-tree feature should be configured on an edge port connected to an end-user device to immediately place the port into a forwarding state and shut it down if it receives a BPDU?
- Loop Protect
- Admin-Edge
- BPDU Guard (Correct answer)
- BPDU Filter
Correct answer: BPDU Guard
BPDU Guard is a security feature designed for host-facing ports (edge ports) that should never be connected to another switch. If a port with BPDU Guard enabled receives a BPDU packet, it immediately transitions to an err-disabled state, effectively shutting down the port to prevent potential loops. While Admin-Edge (or PortFast) places a port immediately into forwarding state, it does not provide the protective shutdown action upon BPDU receipt; BPDU Guard adds this crucial security layer.
Question 21: A network administrator configures VLAN translation on an Aruba CX switch. What does this feature accomplish?
- It duplicates frames across multiple VLANs simultaneously
- It removes VLAN tags from all frames on a port
- It maps an incoming VLAN tag to a different VLAN ID as traffic enters the switch (Correct answer)
- It converts 802.1Q tagged frames to 802.1ad (QinQ) frames
Correct answer: It maps an incoming VLAN tag to a different VLAN ID as traffic enters the switch
VLAN translation (also called VLAN mapping) rewrites the VLAN ID of incoming frames, enabling connectivity between networks using different VLAN numbering schemes.
Question 22: What is the administrative distance of OSPF routes on an Aruba AOS-CX switch by default?
- 120
- 110 (Correct answer)
- 90
- 115
Correct answer: 110
OSPF has a default administrative distance of 110 on Aruba AOS-CX, the same as Cisco IOS, used to prefer routes from different routing protocols.
Question 23: Which version of IGMP introduced support for Source-Specific Multicast (SSM), allowing receivers to specify a source address?
- IGMPv3 (Correct answer)
- IGMPv4
- IGMPv2
- IGMPv1
Correct answer: IGMPv3
IGMPv3 introduced the ability for hosts to specify source addresses, enabling Source-Specific Multicast (SSM).
Question 24: Which Aruba QoS mechanism is most appropriate when an ISP requires traffic to be shaped to a specific rate before sending it across a WAN link to avoid ingress policing drops at the ISP edge?
- Ingress traffic policing
- DSCP remarking to CS0
- Egress traffic shaping (Correct answer)
- Strict priority queuing only
Correct answer: Egress traffic shaping
Egress traffic shaping smooths traffic to match the ISP's contracted rate using token buckets, preventing drops at the ISP's ingress policer.
Question 25: What IEEE standard defines the 802.1Q VLAN tagging mechanism used on Aruba switches?
- 802.3ad
- 802.1Q (Correct answer)
- 802.1X
- 802.1D
Correct answer: 802.1Q
IEEE 802.1Q defines the standard for VLAN tagging, including the 4-byte tag inserted into Ethernet frames to identify the VLAN.
Question 26: What is the recommended best practice for ACL sequence numbers on Aruba switches to allow future ACE insertions?
- Number ACEs in increments of 10 (10, 20, 30…) to leave gaps for insertion (Correct answer)
- Use only even numbers for permits and odd for denies
- Use sequential numbering (1, 2, 3…) for clarity
- Sequence numbers are not supported; ACEs are appended only
Correct answer: Number ACEs in increments of 10 (10, 20, 30…) to leave gaps for insertion
Numbering ACEs in increments of 10 leaves room to insert new entries between existing ones without resequencing the entire ACL.
Question 27: When an Aruba AOS-CX switch is managed via REST API, which authentication method is typically used for API calls?
- Basic HTTP authentication only
- SSH public key exchange
- Cookie-based session token obtained via a login endpoint (Correct answer)
- RADIUS challenge-response
Correct answer: Cookie-based session token obtained via a login endpoint
AOS-CX REST API uses a cookie-based session token: clients POST credentials to the login endpoint and receive a session cookie for subsequent API requests.
Question 28: What is the primary purpose of 802.1X port-based authentication on ArubaOS-CX switches?
- Encrypt all frames traversing the port
- Prevent VLAN hopping attacks
- Limit broadcast domain size
- Authenticate devices before granting network access (Correct answer)
Correct answer: Authenticate devices before granting network access
802.1X enforces authentication via EAP between a supplicant, authenticator (switch), and authentication server before allowing network access.
Question 29: An Aruba switch is configured with SNMP but the NMS is not receiving traps. Which configuration element is most likely missing?
- SNMP port 161 open on the switch firewall
- SNMP MIB files installed on the switch
- SNMP community string for read access
- SNMP trap receiver host address and version (Correct answer)
Correct answer: SNMP trap receiver host address and version
SNMP traps require the trap receiver's IP address and SNMP version to be explicitly configured on the switch; without this, traps have no destination.
Question 30: During a VSX split-brain event, where both the Inter-Switch Link (ISL) and the keepalive connection have failed, what is the default behavior of the secondary VSX switch?
- It transitions all its VSX-LAG member ports to a standby state.
- It maintains all its links in an active state, becoming a second primary switch. (Correct answer)
- It immediately reboots to attempt to re-establish the ISL.
- It shuts down all of its physical interfaces, including non-VSX ports.
Correct answer: It maintains all its links in an active state, becoming a second primary switch.
In a true split-brain scenario where both the ISL and keepalive fail, the secondary switch can no longer determine the state of the primary peer. In this situation, the secondary switch assumes the primary has failed and also becomes a primary, bringing up its interfaces to continue forwarding traffic. This can cause duplicate IP and MAC addresses on the network, but is designed to maintain connectivity for its connected devices. The keepalive mechanism is what normally prevents this by telling the secondary to shut down its VSX links if the ISL fails.
Question 31: In Aruba AOS-CX, which command verifies the current QoS schedule profile applied to a specific interface?
- show interface <port> qos
- show run interface <port>
- show qos interface <port> (Correct answer)
- show qos schedule-profile applied
Correct answer: show qos interface <port>
'show qos interface <port>' displays the QoS settings, queue statistics, and schedule profile currently active on the specified interface.
Question 32: On Aruba AOS-CX, which protocol is used to synchronize time across the switch for accurate logging and security?
- PTP only
- SNTP only
- Chrony
- NTP (Correct answer)
Correct answer: NTP
AOS-CX supports NTP (Network Time Protocol) to synchronize the system clock for accurate logging, certificates, and security policies.
Question 33: Which command displays the current VSF topology, member roles, and software version for each member in AOS-CX?
- show stack-manager
- show redundancy status
- show vsf detail (Correct answer)
- show fabric topology
Correct answer: show vsf detail
The 'show vsf detail' command provides a comprehensive view of all VSF members, their roles, status, and running software.
Question 34: An Aruba CX switch has an ACL applied with 'deny ip any any' as the last entry. A packet matching no other ACE arrives. What happens?
- It is dropped by the explicit deny any any rule (Correct answer)
- It is sent to the CPU for inspection
- It is forwarded due to the implicit permit
- It is rate-limited before dropping
Correct answer: It is dropped by the explicit deny any any rule
An explicit 'deny ip any any' at the end of an ACL drops all unmatched traffic, overriding no other behavior.
Question 35: Which Aruba Central feature allows an administrator to set up automated alerts when a switch CPU exceeds a defined threshold?
- Traffic Analysis
- AI Insights
- Threshold-based alerts in the Alerts & Events module (Correct answer)
- Audit Trails
Correct answer: Threshold-based alerts in the Alerts & Events module
Aruba Central's Alerts & Events module allows configuring threshold-based alerts that trigger notifications when metrics like CPU utilization exceed defined limits.
Question 36: What is the effect of removing the ISL port-channel from a VSX configuration while the system is live?
- Both peers reload to clear the split state
- The system automatically rebuilds the ISL on an alternate path
- VSX gracefully migrates to keepalive-only mode
- VSX enters split-brain mode immediately (Correct answer)
Correct answer: VSX enters split-brain mode immediately
Removing the ISL port-channel while live breaks state synchronization and peer connectivity, triggering split-brain behavior where the Secondary shuts its MCLAG interfaces.
Question 37: In a symmetric IRB model for EVPN-VXLAN, how is inter-subnet traffic forwarded between VTEPs?
- Traffic is forwarded to a centralized routing controller that makes all forwarding decisions
- Traffic is bridged end-to-end without any routing occurring in the fabric
- Traffic is routed only at the ingress VTEP and then bridged to the egress VTEP
- Traffic is routed at both the ingress and egress VTEPs using a dedicated Layer 3 VNI (Correct answer)
Correct answer: Traffic is routed at both the ingress and egress VTEPs using a dedicated Layer 3 VNI
In symmetric IRB, both the ingress VTEP and egress VTEP perform routing using a shared L3 VNI, distributing the routing load symmetrically and enabling consistent traffic paths.
Question 38: An administrator has created a MAC ACL named `IOT-SECURITY` to restrict device access on a specific port. Which of the following commands correctly applies this ACL to interface 1/1/5 for inbound traffic?
- vlan 1; apply access-list mac IOT-SECURITY in
- interface 1/1/5; apply access-list mac IOT-SECURITY in (Correct answer)
- interface 1/1/5; apply access-list mac IOT-SECURITY routed-in
- interface 1/1/5; apply access-list IOT-SECURITY in
Correct answer: interface 1/1/5; apply access-list mac IOT-SECURITY in
To apply an ACL to a physical interface, you must enter the interface context. The command `apply access-list` is used, followed by the ACL type (`mac`), the ACL name (`IOT-SECURITY`), and the direction (`in` for inbound traffic). The `routed-in` direction is used for SVI/VLAN interfaces, not physical Layer 2 ports.
Question 39: What is the purpose of Root Guard on an Aruba switch STP configuration?
- Ensure a port does not become a root port by blocking superior BPDUs (Correct answer)
- Enable BPDU filtering on non-root ports
- Prevent inferior BPDUs from causing port flapping
- Speed up convergence on root bridge ports
Correct answer: Ensure a port does not become a root port by blocking superior BPDUs
Root Guard prevents a port from becoming a root port by placing it into a root-inconsistent state if it receives a superior BPDU.
Question 40: Which AOS-CX show command displays the multicast routing table with (S,G) and (*,G) entries?
- show multicast routing-table
- show ip multicast route
- show ip pim mroute
- show ip mroute (Correct answer)
Correct answer: show ip mroute
The `show ip mroute` command displays the multicast routing table, showing source-specific (S,G) and shared tree (*,G) entries on AOS-CX switches.
Question 41: A switch's root port has failed. In RSTP, which port transitions to Forwarding most quickly to restore connectivity?
- The Designated port
- A newly elected Designated port
- The Backup port
- The Alternate port (Correct answer)
Correct answer: The Alternate port
The RSTP Alternate port already holds a pre-computed alternate path to the root and can immediately transition to Forwarding when the root port fails, without waiting for timers.
Question 42: On an Aruba switch, which DSCP value is typically used to mark voice bearer (RTP) traffic per Aruba QoS best practices?
- DSCP 46 (EF) (Correct answer)
- DSCP 34 (AF41)
- DSCP 0 (Best Effort)
- DSCP 26 (AF31)
Correct answer: DSCP 46 (EF)
DSCP EF (Expedited Forwarding, value 46) is the standard marking for real-time voice traffic requiring low latency and jitter.
Question 43: Which ArubaOS-CX switch security feature prevents rogue devices from sending gratuitous ARP replies to poison ARP caches?
- IP Source Guard
- Port security
- DHCP snooping
- Dynamic ARP Inspection (DAI) (Correct answer)
Correct answer: Dynamic ARP Inspection (DAI)
DAI validates all ARP packets including gratuitous ARPs against the DHCP snooping binding table, dropping those with mismatched IP-to-MAC bindings.
Question 44: Which encryption standard is commonly used for wireless networks?
- WEP
- TKIP
- WPA2
- WPA
WPA2 (Wi-Fi Protected Access II) is the most widely adopted and recommended encryption standard for securing wireless networks. It uses the Advanced Encryption Standard (AES) for strong encryption, providing robust protection against unauthorized access and data interception. While WPA3 is newer, WPA2 remains the prevalent standard in use today.
Question 45: In a network using 802.1X for port-based access control, what is the role of the ArubaOS-CX switch?
- Authenticator (Correct answer)
- Authentication Server
- Supplicant
- RADIUS Client
Correct answer: Authenticator
In the 802.1X framework, the switch or access point that controls physical access to the network is the Authenticator. The end device (e.g., a laptop) is the Supplicant, and the server performing the credential check (e.g., ClearPass or a RADIUS server) is the Authentication Server.
Question 46: Two Aruba CX switches, SW1 and SW2, are connected. Both are configured with the default STP priority. The MAC address of SW1 is 00:00:00:00:00:AA and the MAC address of SW2 is 00:00:00:00:00:BB. Which switch will be elected as the root bridge, and why?
- SW2, because it has a higher MAC address.
- The switch that boots up first will become the root.
- SW1, because it has a lower MAC address. (Correct answer)
- The election will fail due to a tie in priority.
Correct answer: SW1, because it has a lower MAC address.
The STP root bridge election process selects the switch with the lowest Bridge ID (BID). The BID is composed of the bridge priority (default is 32768) and the switch's MAC address. When the priorities are the same, the switch with the lowest MAC address will have the lower BID and will be elected as the root bridge. In this scenario, SW1 has the lower MAC address.
Question 47: In traditional VXLAN without EVPN (flood-and-learn mode), what mechanism handles BUM (Broadcast, Unknown unicast, Multicast) traffic?
- OSPF flooding redistributed into the overlay network
- Statically configured ingress replication lists or multicast groups on each VTEP (Correct answer)
- BGP EVPN Type-3 routes advertising VTEP membership per VNI
- Unicast encapsulation of all BUM traffic to a centralized SDN controller
Correct answer: Statically configured ingress replication lists or multicast groups on each VTEP
Without EVPN, traditional VXLAN relies on either IP multicast groups in the underlay or statically configured head-end replication lists to flood BUM traffic to all VTEPs in a VNI.
Question 48: In an Aruba VRRP deployment, what does a VRRP priority value of 0 in an advertisement indicate?
- The router has detected a failure in the virtual router group
- The router's tracking object has decremented priority to zero
- The router is initializing and not yet ready
- The router is intentionally releasing the master role (Correct answer)
Correct answer: The router is intentionally releasing the master role
A VRRP advertisement with priority 0 is sent by the current master to signal that it is voluntarily giving up the master role, prompting an immediate election.
Question 49: What is the primary function of Dynamic ARP Inspection (DAI) on an Aruba switch?
- Rate-limit ARP requests from untrusted ports only
- Prevent unauthorized DHCP servers from responding
- Validate ARP packets against the DHCP snooping binding table (Correct answer)
- Block flooding of ARP broadcasts on access ports
Correct answer: Validate ARP packets against the DHCP snooping binding table
DAI intercepts ARP packets on untrusted ports and validates them against the DHCP snooping binding table to prevent ARP spoofing.
Question 50: On an Aruba switch, 'burst size' in a traffic policer configuration refers to what?
- The interval between token bucket refills
- The minimum guaranteed bandwidth for the flow
- The maximum number of bytes allowed to exceed the committed rate instantaneously (Correct answer)
- The maximum queue depth before tail drop activates
Correct answer: The maximum number of bytes allowed to exceed the committed rate instantaneously
Burst size (Bc) defines how many bytes above the committed rate a flow can send instantaneously before packets are dropped or remarked.
Question 51: In an Aruba CX MLAG deployment, what is the purpose of the ISL (Inter-Switch Link)?
- To provide a backup path for spanning tree
- To carry management traffic between the switches
- To synchronize MLAG state and forward traffic between the two MLAG peers (Correct answer)
- To replicate VLAN databases between the switches
Correct answer: To synchronize MLAG state and forward traffic between the two MLAG peers
The ISL carries both MLAG control plane synchronization and dataplane traffic that needs to traverse from one MLAG peer to the other.
Question 52: What is the maximum number of physical ports that can be members of a single LAG on most Aruba CX switches?
- 32
- 16
- 4
- 8 (Correct answer)
Correct answer: 8
Aruba CX switches typically support up to 8 active member ports per LAG, with additional standby ports possible when using LACP.
Question 53: Which AOS-CX command displays all currently active user sessions on the switch, including SSH and console sessions?
- show users (Correct answer)
- show login
- show who
- show sessions
Correct answer: show users
'show users' lists all currently logged-in users along with their session type (SSH, console), idle time, and remote IP.
Question 54: What is the primary difference between SNMP traps and SNMP informs?
- Informs require an acknowledgment from the receiver; traps do not (Correct answer)
- Traps use TCP while informs use UDP
- Informs can only be sent to one destination; traps support multiple
- Traps support SNMPv3 encryption; informs do not
Correct answer: Informs require an acknowledgment from the receiver; traps do not
SNMP informs are acknowledged by the receiving NMS, providing delivery confirmation; traps are unacknowledged fire-and-forget messages.
Question 55: In EVPN-VXLAN, which BGP address family is used to distribute MAC and IP reachability information between VTEPs?
- IPv6 Unicast (AFI 2, SAFI 1)
- L2VPN EVPN (AFI 25, SAFI 70) (Correct answer)
- IPv4 Unicast (AFI 1, SAFI 1)
- VPNv4 (AFI 1, SAFI 128)
Correct answer: L2VPN EVPN (AFI 25, SAFI 70)
EVPN uses the L2VPN EVPN address family (AFI 25, SAFI 70) to distribute MAC/IP reachability, multicast group info, and other overlay control-plane data via BGP.
Question 56: An Aruba switch is configured with Port Access Control (PAC). A device fails 802.1X authentication but succeeds with MAC authentication. Which role will the device receive?
- The default unauthenticated role
- The MAC-authenticated role (Correct answer)
- The critical role
- The 802.1X-authenticated role
Correct answer: The MAC-authenticated role
When 802.1X fails and MAC authentication succeeds, the switch assigns the role associated with the MAC-auth success.
Question 57: Which Aruba switch feature uses a downloadable role returned by a RADIUS server to enforce per-user access policies?
- MAC-based VLAN assignment
- Static VLAN assignment
- Downloadable User Role (role-based access control) (Correct answer)
- RADIUS VSA VLAN tagging only
Correct answer: Downloadable User Role (role-based access control)
Aruba's role-based access control allows RADIUS to return a user role containing ACLs and policies applied dynamically per user.
Question 58: A /30 subnet is used for a point-to-point WAN link. How many usable host addresses does this subnet provide?
- 4
- 1
- 2 (Correct answer)
- 6
Correct answer: 2
A /30 subnet contains 4 total addresses: one network address, two usable hosts, and one broadcast.
Question 59: When applying an IPv4 ACL on an ArubaOS-CX interface, which direction applies the ACL to traffic entering the switch from a host?
- Management plane direction
- Inbound (ingress) (Correct answer)
- Outbound (egress)
- Both directions simultaneously
Correct answer: Inbound (ingress)
Ingress (inbound) ACLs are applied to traffic arriving at the switch interface from an external host before it is forwarded.
Question 60: In OSPF area design on Aruba switches, what is the primary purpose of a stub area?
- To reduce LSA flooding by blocking Type 5 external LSAs from entering the area (Correct answer)
- To prevent inter-area routes from being advertised
- To eliminate the need for a DR/BDR election
- To allow only Type 1 LSAs within the area
Correct answer: To reduce LSA flooding by blocking Type 5 external LSAs from entering the area
Stub areas block Type 5 AS-external LSAs, reducing the LSDB size by replacing external routes with a default route from the ABR.
Aruba Certified Switching Professional (ACSP) HPE6-A73
The ACSP exam validates the ability to implement and operate enterprise-level HPE Aruba campus switching solutions, covering wired network planning, installation and configuration of AOS-CX switches, troubleshooting, and network management and monitoring.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds