โ† All ACSP Flashcard Decks

Network Security & Traffic Management Flashcards

7 cards from real ACSP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Security & Traffic Management flashcards as text
  1. What is the purpose of Root Guard on an Aruba switch STP configuration?

    Answer: Ensure a port does not become a root port by blocking superior BPDUs

    Root Guard prevents a port from becoming a root port by placing it into a root-inconsistent state if it receives a superior BPDU.

  2. An Aruba CX switch has an ACL applied with 'deny ip any any' as the last entry. A packet matching no other ACE arrives. What happens?

    Answer: It is dropped by the explicit deny any any rule

    An explicit 'deny ip any any' at the end of an ACL drops all unmatched traffic, overriding no other behavior.

  3. Which Aruba switch feature uses a downloadable role returned by a RADIUS server to enforce per-user access policies?

    Answer: Downloadable User Role (role-based access control)

    Aruba's role-based access control allows RADIUS to return a user role containing ACLs and policies applied dynamically per user.

  4. When configuring storm control on an ArubaOS-CX access port, which traffic types can be rate-limited?

    Answer: Broadcast, multicast, and unknown unicast

    Storm control on ArubaOS-CX can rate-limit broadcast, multicast, and unknown unicast traffic to prevent storms from overwhelming the switch.

  5. An administrator configures 'spanning-tree port-type admin-edge' on an ArubaOS-CX access port. What is the effect?

    Answer: The port immediately transitions to forwarding without waiting for STP timers

    Admin-edge (equivalent to PortFast) allows the port to immediately move to forwarding state, bypassing STP listening and learning delays.

  6. Which mechanism on Aruba switches prevents an unauthorized host from using an IP address not assigned by DHCP?

    Answer: IP Source Guard

    IP Source Guard filters packets based on the DHCP snooping binding table, preventing hosts from using IP addresses not assigned by DHCP.

  7. In ArubaOS-CX, what is the default action when a port security violation occurs (MAC limit exceeded)?

    Answer: Err-disable the port immediately

    By default, when the MAC limit is exceeded on an ArubaOS-CX port, the port is placed into err-disabled state.