Switch Security Features Flashcards
7 cards from real ACSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Switch Security Features flashcards as text
What is the role of Root Guard in ArubaOS-CX Spanning Tree security?
Answer: Prevent a connected switch from becoming the STP root bridge
Root Guard places a port in root-inconsistent state if it receives a superior BPDU, preventing external devices from taking over the root bridge role.
Which ArubaOS-CX MAC authentication method allows a device that fails 802.1X to fall back to authenticating by its MAC address?
Answer: MAC Authentication Bypass (MAB)
MAC Authentication Bypass (MAB) allows non-802.1X-capable devices to authenticate using their MAC address as both the username and password sent to RADIUS.
In ArubaOS-CX, what is a 'critical authentication VLAN' used for in 802.1X deployments?
Answer: Place clients in a designated VLAN when the RADIUS server is unreachable
The critical authentication VLAN ensures that when the RADIUS server is down, clients are placed in a predefined VLAN allowing limited access rather than being denied completely.
Which ArubaOS-CX feature prevents unauthorized devices from connecting to a switch port by storing specific allowed MAC addresses?
Answer: Sticky MAC (port security with sticky learning)
Sticky MAC learning allows port security to dynamically learn and permanently save MAC addresses to the running configuration, locking those addresses to the port.
What does the ArubaOS-CX 'auth-priority' setting control in port-access configurations?
Answer: The order in which authentication methods (802.1X, MAB) are attempted
Auth-priority defines the sequence in which authentication methods are tried on a port, such as trying 802.1X first and falling back to MAB if it times out.
Which security feature on ArubaOS-CX switches monitors and rate-limits control plane traffic to protect the switch CPU?
Answer: Control Plane Policing (CoPP)
Control Plane Policing (CoPP) protects the switch CPU from DoS attacks by rate-limiting or dropping excessive control plane traffic destined for the CPU.
In ArubaOS-CX, what is the purpose of configuring a 'guest VLAN' in 802.1X port-access settings?
Answer: Provide limited network access to clients that do not respond to 802.1X EAP requests
The guest VLAN places clients that send no EAP response (non-802.1X-capable devices) into a restricted VLAN with limited network access.