Aruba Certified Switching Professional (ACSP) HPE6-A73 — Questions and Answers
Question 1: What is the primary purpose of GRE (Generic Routing Encapsulation) tunneling?
- To provide QoS priority marking for traffic crossing the WAN
- To encrypt traffic between two network endpoints
- To replace VLANs as the primary network segmentation mechanism
- To encapsulate packets of one protocol inside IP packets for transport across a network (Correct answer)
Correct answer: To encapsulate packets of one protocol inside IP packets for transport across a network
GRE encapsulates a wide variety of network layer protocols inside IP packets, creating a virtual point-to-point link between two tunnel endpoints.
Question 2: Which SNMPv3 security level provides both authentication and encryption?
- noAuthNoPriv
- authPriv (Correct answer)
- privOnly
- authNoPriv
Correct answer: authPriv
authPriv uses both an authentication protocol (MD5 or SHA) and a privacy protocol (DES or AES) to secure SNMP communications.
Question 3: A trunk port on an Aruba CX switch is receiving frames tagged with VLAN 10, but VLAN 10 is not in the allowed VLAN list. What happens to these frames?
- They trigger a VLAN mismatch SNMP trap
- They are forwarded in the native VLAN
- They are forwarded to the management VLAN
- They are dropped by the switch (Correct answer)
Correct answer: They are dropped by the switch
Frames tagged with a VLAN not in the trunk's allowed VLAN list are dropped at ingress on the trunk port.
Question 4: What is the primary function of Dynamic ARP Inspection (DAI) on an Aruba switch?
- Prevent unauthorized DHCP servers from responding
- Validate ARP packets against the DHCP snooping binding table (Correct answer)
- Block flooding of ARP broadcasts on access ports
- Rate-limit ARP requests from untrusted ports only
Correct answer: Validate ARP packets against the DHCP snooping binding table
DAI intercepts ARP packets on untrusted ports and validates them against the DHCP snooping binding table to prevent ARP spoofing.
Question 5: A static LAG is configured between two Aruba CX switches. One switch is rebooted. What happens to traffic on the LAG during the reboot?
- Traffic is dropped because no negotiation protocol re-establishes the bundle (Correct answer)
- The remaining switch forwards traffic on the surviving physical links
- Traffic is rerouted via STP backup paths immediately
- LACP automatically re-establishes the bundle within 30 seconds
Correct answer: Traffic is dropped because no negotiation protocol re-establishes the bundle
Static LAGs have no negotiation protocol, so when one end goes down all links in the bundle lose connectivity until the rebooted switch returns.
Question 6: On an Aruba switch, which of the following is the correct sequence to add VRRP tracking for an uplink interface?
- Configure VRRP priority → enable object tracking → bind by VLAN
- Apply VRRP group → enable tracking globally → configure decrement
- Define track object → apply track object to VRRP group with priority decrement (Correct answer)
- Enable VRRP preemption → add tracked interface → set advertisement interval
Correct answer: Define track object → apply track object to VRRP group with priority decrement
The correct process is to first define the tracking object (e.g., track interface or IP SLA), then reference it in the VRRP group configuration with a priority decrement value.
Question 7: A /30 subnet is used for a point-to-point WAN link. How many usable host addresses does this subnet provide?
- 6
- 4
- 2 (Correct answer)
- 1
Correct answer: 2
A /30 subnet contains 4 total addresses: one network address, two usable hosts, and one broadcast.
Question 8: When troubleshooting an ACL on an Aruba AOS-Switch, which command clears the ACE hit counters so you can observe fresh traffic patterns?
- clear access-list <name> statistics (Correct answer)
- debug acl clear <name>
- no access-list <name> statistics
- reset acl counters <name>
Correct answer: clear access-list <name> statistics
'clear access-list <name> statistics' resets all hit counters for the specified ACL, allowing fresh observation of traffic matching each ACE.
Question 9: A network engineer wants to ensure that only one specific MAC address is allowed on an access port. Which combination of features is most appropriate on an Aruba CX switch?
- IP Source Guard with a single static entry
- 802.1X with MAC authentication bypass only
- DHCP snooping with binding limit of 1
- Port security with a static allowed MAC and MAC limit of 1 (Correct answer)
Correct answer: Port security with a static allowed MAC and MAC limit of 1
Port security with a static allowed MAC and a limit of 1 ensures only that single device can communicate on the port.
Question 10: In an Aruba AOS-CX VSX environment, what is the primary purpose of the keepalive connection?
- To forward user data traffic if the Inter-Switch Link (ISL) fails.
- To synchronize the running configuration between the primary and secondary VSX peers.
- To carry control plane traffic for routing protocols like OSPF and BGP.
- To provide a heartbeat mechanism to detect a split-brain scenario when the ISL is down. (Correct answer)
Correct answer: To provide a heartbeat mechanism to detect a split-brain scenario when the ISL is down.
The VSX keepalive is a lightweight, out-of-band heartbeat mechanism (typically a UDP-based probe) that runs between the two VSX switches. Its sole purpose is to distinguish between a secondary switch failure and an Inter-Switch Link (ISL) failure. If the ISL goes down but the keepalive is still up, the secondary switch knows the primary is still active and will disable its own VSX LAG interfaces to prevent a network loop, thus avoiding a split-brain condition.
Question 11: In Aruba AOS-CX, which command verifies the current QoS schedule profile applied to a specific interface?
- show interface <port> qos
- show qos interface <port> (Correct answer)
- show qos schedule-profile applied
- show run interface <port>
Correct answer: show qos interface <port>
'show qos interface <port>' displays the QoS settings, queue statistics, and schedule profile currently active on the specified interface.
Question 12: Which Aruba ACL type is specifically designed to filter traffic based on EtherType values such as ARP or IPv6?
- Extended IP ACL
- MAC ACL with EtherType matching (Correct answer)
- VLAN ACL
- Standard IP ACL
Correct answer: MAC ACL with EtherType matching
MAC ACLs on Aruba switches support EtherType matching, enabling filtering of specific Layer 2 protocols like ARP (0x0806) or IPv6 (0x86DD).
Question 13: What is the VRRP skew time used for?
- Staggering master-down timers among backup routers based on priority (Correct answer)
- Setting advertisement intervals
- Delaying preemption after a topology change
- Synchronizing clocks between routers
Correct answer: Staggering master-down timers among backup routers based on priority
Skew time staggers master-down timers among backup routers so that higher-priority backups take over before lower-priority ones.
Question 14: What is the purpose of configuring a 'preemption delay' in VRRP on Aruba switches?
- To synchronize advertisement intervals between master and backup
- To delay sending advertisements after a topology change
- To prevent the master from responding to ARP until it is stable
- To allow a higher-priority router time to populate its routing table before taking the master role (Correct answer)
Correct answer: To allow a higher-priority router time to populate its routing table before taking the master role
Preemption delay gives the preempting router time to converge its routing table or STP topology before it takes over as the active gateway, preventing traffic blackholes.
Question 15: An Aruba switch administrator wants to limit a specific application's bandwidth to 10 Mbps and remarked excess traffic rather than drop it. Which policer action should be configured?
- action exceed remark dscp <value> (Correct answer)
- action exceed shape 10m
- action exceed drop
- action exceed queue lowest
Correct answer: action exceed remark dscp <value>
The 'action exceed remark dscp' option allows traffic above the committed rate to be forwarded with a lower DSCP value instead of being dropped.
Question 16: Which QoS scheduling mechanism guarantees a minimum bandwidth percentage for each traffic class on an ArubaOS-CX switch?
- Deficit Weighted Round Robin (DWRR) (Correct answer)
- Strict Priority Queuing (SPQ)
- Deficit Round Robin with no weights
- First-In First-Out (FIFO)
Correct answer: Deficit Weighted Round Robin (DWRR)
DWRR allocates bandwidth to queues proportionally based on assigned weights, guaranteeing minimums for each class.
Question 17: Which Aruba feature continuously monitors network health and uses AI/ML to identify anomalies in baseline behavior?
- RMON probes
- ArubaOS-CX Analytics Framework
- Aruba Central AI Insights (Correct answer)
- NetEdit
Correct answer: Aruba Central AI Insights
Aruba Central AI Insights uses machine learning to establish behavioral baselines and flag anomalies that deviate from normal network patterns.
Question 18: Which Aruba QoS mechanism is most appropriate when an ISP requires traffic to be shaped to a specific rate before sending it across a WAN link to avoid ingress policing drops at the ISP edge?
- DSCP remarking to CS0
- Egress traffic shaping (Correct answer)
- Ingress traffic policing
- Strict priority queuing only
Correct answer: Egress traffic shaping
Egress traffic shaping smooths traffic to match the ISP's contracted rate using token buckets, preventing drops at the ISP's ingress policer.
Question 19: Which protocol replaces ARP in IPv6 networks for resolving IPv6 addresses to MAC addresses?
- IGMPv3
- DHCPv6
- RARP
- ICMPv6 Neighbor Discovery Protocol (NDP) (Correct answer)
Correct answer: ICMPv6 Neighbor Discovery Protocol (NDP)
IPv6 uses ICMPv6 Neighbor Discovery Protocol (NDP) instead of ARP, using multicast Neighbor Solicitation and Neighbor Advertisement messages for address resolution.
Question 20: What does Dynamic ARP Inspection (DAI) use to validate ARP packets on ArubaOS-CX switches?
- 802.1X authentication state
- The DHCP snooping binding database (Correct answer)
- The MAC address table
- Static ARP entries configured on the switch
Correct answer: The DHCP snooping binding database
DAI checks ARP packets against the DHCP snooping binding table to verify that IP-to-MAC mappings are legitimate before forwarding.
Question 21: An administrator wants to permit SSH (port 22) from a management subnet 10.0.0.0/24 only. Which ACL entry accomplishes this?
- permit tcp any 10.0.0.0/24 eq 22
- permit tcp 10.0.0.0/24 any eq 22 (Correct answer)
- permit ip 10.0.0.0/24 any
- permit udp 10.0.0.0/24 any eq 22
Correct answer: permit tcp 10.0.0.0/24 any eq 22
SSH uses TCP port 22; permitting tcp from the source subnet to any destination on port 22 correctly scopes the rule.
Question 22: Which ArubaOS-CX command verifies that a static route has been successfully installed in the forwarding plane?
- show running-config | include ip route
- show interface statistics
- show ip route static
- show ip fib (Correct answer)
Correct answer: show ip fib
The 'show ip fib' command displays the Forwarding Information Base, confirming routes are programmed into hardware for actual packet forwarding.
Question 23: What is the effect of enabling 'loop protection' on an ArubaOS-CX access port?
- Prevent VLAN loops by disabling trunk negotiation
- Detect and disable ports that create Layer 2 loops by sending probe frames (Correct answer)
- Shut down the port if STP topology changes occur
- Block all BPDU traffic on the port
Correct answer: Detect and disable ports that create Layer 2 loops by sending probe frames
Loop protection sends probe frames and disables a port if it receives its own probes back, detecting loops even on ports where STP BPDUs are filtered.
Question 24: A network administrator applies an ACL to filter traffic. The ACL contains two access control entries (ACEs): `10 permit tcp 10.1.10.5 host 192.168.1.100 eq 80` and `20 deny ip 10.1.10.0/24 any`. A user at 10.1.10.5 reports they cannot access a web server at 192.168.1.100. What is the most likely reason for this issue?
- The ACL is applied in the outbound direction on the client's interface.
- An implicit deny rule at the end of the ACL is blocking the traffic.
- The switch is processing the ACE with sequence number 20 before sequence number 10.
- The ACL is missing a rule to permit the return traffic from the web server. (Correct answer)
Correct answer: The ACL is missing a rule to permit the return traffic from the web server.
ACLs on ArubaOS-CX switches are stateless. While the ACE with sequence number 10 correctly permits the initial TCP SYN packet from the client to the server on port 80, there is no corresponding rule to allow the return traffic (TCP SYN-ACK) from the server (source 192.168.1.100) back to the client (destination 10.1.10.5). The `20 deny ip 10.1.10.0/24 any` rule or the final implicit deny would block this return traffic, preventing the TCP session from being established.
Question 25: Which OSPFv3 feature distinguishes it from OSPFv2 when operating in an IPv6 environment?
- OSPFv3 uses MD5 authentication natively in the protocol
- OSPFv3 supports only stub areas
- OSPFv3 uses TCP instead of IP protocol 89
- OSPFv3 runs per-link rather than per-subnet and uses link-local addresses for adjacency (Correct answer)
Correct answer: OSPFv3 runs per-link rather than per-subnet and uses link-local addresses for adjacency
OSPFv3 forms adjacencies using link-local addresses and operates on a per-link basis rather than per-subnet as in OSPFv2.
Question 26: A network administrator is configuring a multi-area OSPF network on ArubaOS-CX switches. An interface on a switch connects to Area 0.0.0.0. What is the common name for this area?
- The Backbone Area (Correct answer)
- The Stub Area
- The Not-So-Stubby Area (NSSA)
- The Transit Area
Correct answer: The Backbone Area
In OSPF, Area 0 (or 0.0.0.0) has a special designation as the backbone area. All other areas in a multi-area OSPF design must connect to the backbone area, either directly or through a virtual link, to ensure that routing information can be exchanged between non-backbone areas.
Question 27: What is the primary purpose of IPv6 link-local addresses (FE80::/10)?
- To provide globally routable IPv6 connectivity to the internet
- To replace IPv4 DHCP for address assignment
- To assign addresses to loopback interfaces only
- To enable communication between nodes on the same link without requiring a router (Correct answer)
Correct answer: To enable communication between nodes on the same link without requiring a router
Link-local addresses are used for communication between devices on the same network segment and are automatically configured on every IPv6-enabled interface.
Question 28: An extended ACL entry reads: 'deny tcp 192.168.10.0/24 172.16.0.0/16 eq 80'. Which traffic does this block?
- TCP port 80 from 192.168.10.0/24 to 172.16.0.0/16 (Correct answer)
- UDP port 80 from 192.168.10.0/24
- All TCP from 192.168.10.0/24
- TCP port 80 from 172.16.0.0/16 to 192.168.10.0/24
Correct answer: TCP port 80 from 192.168.10.0/24 to 172.16.0.0/16
The ACE matches TCP traffic sourced from 192.168.10.0/24 destined for port 80 on any host in 172.16.0.0/16.
Question 29: In AOS-CX QoS, what does the 'strict' scheduling mode mean when applied to a queue?
- The queue randomly drops packets to avoid congestion
- The queue is always serviced before lower-priority queues, regardless of their content (Correct answer)
- The queue uses token buckets to shape traffic
- The queue shares bandwidth equally with all other queues
Correct answer: The queue is always serviced before lower-priority queues, regardless of their content
Strict priority scheduling always services the strict queue before moving to lower-priority queues, which can starve lower queues if the strict queue is always busy.
Question 30: What does the 'debug destination' command control on an Aruba switch?
- The SNMP trap destination server
- The severity level of debug messages
- Where debug log output is sent (session, syslog, or buffer) (Correct answer)
- The interface on which debugging is enabled
Correct answer: Where debug log output is sent (session, syslog, or buffer)
The 'debug destination' command specifies where debug output is directed, such as to the current session, a buffer, or a syslog server.
Question 31: Which AOS-CX command verifies that VSX peers are synchronized and shows the synchronization status of routing protocols?
- show vsx status (Correct answer)
- show redundancy peers
- show fabric sync detail
- show lacp peer
Correct answer: show vsx status
The 'show vsx status' command displays the VSX peer state, ISL and keepalive status, and which protocols are currently synchronized between peers.
Aruba Certified Switching Professional (ACSP) HPE6-A73
The ACSP exam validates the ability to implement and operate enterprise-level HPE Aruba campus switching solutions, covering wired network planning, installation and configuration of AOS-CX switches, troubleshooting, and network management and monitoring.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds