Switch Security Features Flashcards
7 cards from real ACSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Switch Security Features flashcards as text
What does the ArubaOS-CX 'port-access authenticator' command with 'reauthenticate' enforce?
Answer: Clients must re-authenticate after a configured time interval
The reauthentication timer forces clients to periodically re-authenticate with the RADIUS server, ensuring continued authorization validity.
Which ArubaOS-CX feature allows a downloadable ACL (dACL) to be applied to a port after successful 802.1X authentication?
Answer: RADIUS-assigned ACL via Filter-Id or Aruba VSA
After 802.1X authentication, RADIUS can return a Filter-Id or Aruba VSA attribute containing an ACL name, which the switch applies to the authenticated port.
What is the effect of enabling 'loop protection' on an ArubaOS-CX access port?
Answer: Detect and disable ports that create Layer 2 loops by sending probe frames
Loop protection sends probe frames and disables a port if it receives its own probes back, detecting loops even on ports where STP BPDUs are filtered.
In ArubaOS-CX, which command applies a previously defined user-role to an authenticated port-access session?
Answer: aaa authentication port-access dot1x authenticator role
User-roles in ArubaOS-CX define access policies (ACLs, QoS, VLAN) that can be assigned dynamically to ports after 802.1X or MAB authentication.
Which ArubaOS-CX switch security feature prevents rogue devices from sending gratuitous ARP replies to poison ARP caches?
Answer: Dynamic ARP Inspection (DAI)
DAI validates all ARP packets including gratuitous ARPs against the DHCP snooping binding table, dropping those with mismatched IP-to-MAC bindings.
What is the recommended ArubaOS-CX configuration to secure the management access interface against brute force login attacks?
Answer: Configure login delay and maximum login attempts with lockout
Configuring login delay and lockout thresholds (maximum failed attempts before lockout) directly mitigates brute force attacks on management interfaces.
On ArubaOS-CX, which feature ensures that only traffic from authenticated clients is forwarded while traffic from unauthenticated clients is dropped or redirected?
Answer: Port-access authentication with client roles
Port-access authentication with client roles enforces that unauthenticated clients have no forwarding access or are placed in a restricted VLAN until they complete authentication.