← All ACSP Flashcard Decks

Network Security & Traffic Management Flashcards

7 cards from real ACSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Network Security & Traffic Management flashcards as text
  1. An Aruba switch is configured with Port Access Control (PAC). A device fails 802.1X authentication but succeeds with MAC authentication. Which role will the device receive?

    Answer: The MAC-authenticated role

    When 802.1X fails and MAC authentication succeeds, the switch assigns the role associated with the MAC-auth success.

  2. Which ArubaOS-CX command enables DHCP snooping on a specific VLAN?

    Answer: ip dhcp snooping vlan

    The correct ArubaOS-CX syntax to enable DHCP snooping on a VLAN is 'ip dhcp snooping vlan ' entered in global configuration mode.

  3. What is the primary function of Dynamic ARP Inspection (DAI) on an Aruba switch?

    Answer: Validate ARP packets against the DHCP snooping binding table

    DAI intercepts ARP packets on untrusted ports and validates them against the DHCP snooping binding table to prevent ARP spoofing.

  4. An administrator wants to prevent a rogue DHCP server on an access port. Which Aruba switch feature should be enabled, and how should the uplink be configured?

    Answer: Enable DHCP snooping; configure uplink as trusted

    DHCP snooping prevents rogue DHCP servers by marking only trusted ports (uplinks) as allowed to send DHCP offers.

  5. When configuring Control Plane Policing (CoPP) on ArubaOS-CX, what is the main goal?

    Answer: Protect the switch CPU from excessive protocol traffic

    CoPP protects the switch control plane (CPU) by rate-limiting traffic destined to the processor, preventing DoS attacks.

  6. Which statement best describes IP Source Guard on an Aruba switch?

    Answer: It filters traffic based on IP and MAC from the DHCP snooping table

    IP Source Guard uses the DHCP snooping binding table to permit only traffic whose source IP and MAC match a valid binding.

  7. A network engineer must limit the number of MAC addresses learned on an access port to 5. Which ArubaOS-CX feature accomplishes this?

    Answer: Port security with a MAC limit

    Port security on ArubaOS-CX allows limiting MAC addresses per port and defining violation actions when the limit is exceeded.