Aruba Certified Switching Professional (ACSP) HPE6-A73 — Questions and Answers
Question 1: What is the difference between BPDU Guard and BPDU Filter on ArubaOS-CX switches?
- BPDU Guard drops inbound BPDUs; BPDU Filter drops outbound BPDUs only
- BPDU Guard is for access ports; BPDU Filter is for trunk ports only
- BPDU Guard disables the port on receipt; BPDU Filter silently drops BPDUs in both directions (Correct answer)
- BPDU Guard logs violations; BPDU Filter shuts the port down
Correct answer: BPDU Guard disables the port on receipt; BPDU Filter silently drops BPDUs in both directions
BPDU Guard err-disables the port if any BPDU is received, while BPDU Filter suppresses sending and receiving BPDUs without shutting down the port.
Question 2: What happens to OSPF routes when the OSPF process is restarted on an Aruba switch without graceful restart configured?
- Routes are moved to a backup routing table
- Routes remain until the process finishes restarting
- Only external OSPF routes are removed
- All OSPF routes are immediately removed from the routing table during convergence (Correct answer)
Correct answer: All OSPF routes are immediately removed from the routing table during convergence
Without graceful restart, restarting the OSPF process drops all OSPF-learned routes from the RIB until adjacencies re-form and SPF recalculates.
Question 3: Which command displays the current VSF topology, member roles, and software version for each member in AOS-CX?
- show stack-manager
- show redundancy status
- show vsf detail (Correct answer)
- show fabric topology
Correct answer: show vsf detail
The 'show vsf detail' command provides a comprehensive view of all VSF members, their roles, status, and running software.
Question 4: Which statement best describes IP Source Guard on an Aruba switch?
- It filters traffic based on IP and MAC from the DHCP snooping table (Correct answer)
- It blocks all non-IP traffic on a port
- It prevents IP fragmentation attacks
- It validates IP addresses against a static ACL
Correct answer: It filters traffic based on IP and MAC from the DHCP snooping table
IP Source Guard uses the DHCP snooping binding table to permit only traffic whose source IP and MAC match a valid binding.
Question 5: On an ArubaOS-CX switch, what action does port security take by default when a violation is detected?
- Generate a syslog alert only
- Drop the offending frame silently
- Send an SNMP trap only
- Shutdown the port (Correct answer)
Correct answer: Shutdown the port
The default port security violation action is to shut down the port (err-disable state), requiring manual intervention to restore connectivity.
Question 6: A network administrator configures VLAN translation on an Aruba CX switch. What does this feature accomplish?
- It duplicates frames across multiple VLANs simultaneously
- It converts 802.1Q tagged frames to 802.1ad (QinQ) frames
- It maps an incoming VLAN tag to a different VLAN ID as traffic enters the switch (Correct answer)
- It removes VLAN tags from all frames on a port
Correct answer: It maps an incoming VLAN tag to a different VLAN ID as traffic enters the switch
VLAN translation (also called VLAN mapping) rewrites the VLAN ID of incoming frames, enabling connectivity between networks using different VLAN numbering schemes.
Question 7: What is the main role of OSPF in a network?
- Network address translation
- Path selection
- IP address assignment
- Packet encryption
The main role of OSPF (Open Shortest Path First) in a network is efficient path selection. As a link-state routing protocol, OSPF builds a complete topology map of the network and uses Dijkstra's algorithm to calculate the shortest path to each destination based on a cost metric. This enables routers to make optimal forwarding decisions and quickly adapt to network changes.
Question 8: When configuring Control Plane Policing (CoPP) on ArubaOS-CX, what is the main goal?
- Enforce QoS policies on end-user ports
- Protect the switch CPU from excessive protocol traffic (Correct answer)
- Prioritize voice traffic in the data plane
- Limit bandwidth on uplink ports
Correct answer: Protect the switch CPU from excessive protocol traffic
CoPP protects the switch control plane (CPU) by rate-limiting traffic destined to the processor, preventing DoS attacks.
Question 9: Which command on ArubaOS-CX verifies that OSPF neighbors have reached the FULL adjacency state?
- show ospf interface
- show ospf neighbors
- show ip route ospf
- show ip ospf neighbor (Correct answer)
Correct answer: show ip ospf neighbor
The 'show ip ospf neighbor' command displays neighbor states, including whether adjacency has reached FULL.
Question 10: Which ArubaOS-CX MAC authentication method allows a device that fails 802.1X to fall back to authenticating by its MAC address?
- MAC Authentication Bypass (MAB) (Correct answer)
- Guest VLAN assignment
- Multi-domain authentication
- Critical authentication
Correct answer: MAC Authentication Bypass (MAB)
MAC Authentication Bypass (MAB) allows non-802.1X-capable devices to authenticate using their MAC address as both the username and password sent to RADIUS.
Question 11: On an ArubaOS-CX switch, which ports are exempt from DAI validation by default?
- Trunk ports only
- Trusted ports (Correct answer)
- Ports in the default VLAN
- Ports with port security enabled
Correct answer: Trusted ports
DAI trusted ports (typically uplinks) bypass ARP inspection, while all untrusted ports have their ARP packets validated against the binding database.
Question 12: Which SNMPv3 security level provides both authentication and encryption?
- noAuthNoPriv
- privOnly
- authPriv (Correct answer)
- authNoPriv
Correct answer: authPriv
authPriv uses both an authentication protocol (MD5 or SHA) and a privacy protocol (DES or AES) to secure SNMP communications.
Question 13: On an Aruba CX switch, a security policy requires that all RADIUS packets use a specific source IP. Which configuration achieves this?
- Set the RADIUS server IP as the source address
- Apply an outbound ACL on the management port
- Configure 'radius-server host <ip> source-interface <intf>' (Correct answer)
- Use a loopback interface as the default route next-hop
Correct answer: Configure 'radius-server host <ip> source-interface <intf>'
The 'source-interface' option on the RADIUS server configuration forces all RADIUS packets to use the IP of the specified interface.
Question 14: Two ArubaOS-CX switches are configured in a VRRP group with the same priority value and preemption disabled. Which switch will become the VRRP Master?
- The switch with the higher IP address configured on the VRRP interface. (Correct answer)
- The switch that boots up first and initializes its VRRP instance.
- The election is random and non-deterministic.
- The switch with the lower physical MAC address.
Correct answer: The switch with the higher IP address configured on the VRRP interface.
When VRRP priorities are identical, the switch with the highest IP address on the interface participating in the VRRP group is elected as the Master. This is the standard tie-breaking mechanism.
Question 15: What does the 'no shutdown' command do when applied to an AOS-CX switch interface?
- Removes the interface from all VLANs
- Resets the interface counters
- Administratively enables the interface (Correct answer)
- Disables spanning tree on the interface
Correct answer: Administratively enables the interface
'no shutdown' administratively enables an interface that was previously disabled with the 'shutdown' command.
Question 16: When redistributing static routes into OSPF on an Aruba AOS-CX switch, which command is used and what default metric type is applied?
- redistribute static, Type 1 (E1) by default
- inject static, Type 2 (E2) by default
- redistribute static, Type 2 (E2) by default (Correct answer)
- import static, Type 1 (E1) by default
Correct answer: redistribute static, Type 2 (E2) by default
The 'redistribute static' command under router ospf injects static routes as OSPF external routes with Type 2 (E2) metric by default.
Question 17: In an Aruba OSPF deployment, which condition causes an OSPF router to transition from EXSTART to EXCHANGE state?
- Successful election of master/slave and agreement on initial sequence number (Correct answer)
- The dead interval expiring without a hello
- Completion of LSR/LSU/LSAck exchange
- Receipt of the first DBD packet from the neighbor
Correct answer: Successful election of master/slave and agreement on initial sequence number
The EXSTART-to-EXCHANGE transition occurs after master/slave negotiation completes and both routers agree on the initial DBD sequence number.
Question 18: An IT department uses Aruba NetEdit to manage its fleet of ArubaOS-CX switches. What is a primary function of Aruba NetEdit?
- On-box scripting and automated remediation of network events.
- Wireless LAN planning and RF heat map generation.
- Orchestrating multi-switch configuration changes with validation and auditing. (Correct answer)
- Real-time deep packet inspection and threat analysis.
Correct answer: Orchestrating multi-switch configuration changes with validation and auditing.
Aruba NetEdit is a network management platform designed to simplify and automate the configuration, validation, deployment, and auditing of ArubaOS-CX switches. It allows administrators to orchestrate changes across multiple devices, validate configurations for consistency, and maintain an audit trail.
Question 19: In what scenario is DHCPv6 stateless mode used in conjunction with SLAAC?
- When the network requires centralized tracking of all IPv6 address assignments
- When hosts must use only server-assigned addresses and SLAAC is disabled
- When hosts need additional parameters such as DNS server addresses that SLAAC RA messages do not provide (Correct answer)
- When SLAAC alone cannot assign any addresses to hosts
Correct answer: When hosts need additional parameters such as DNS server addresses that SLAAC RA messages do not provide
DHCPv6 stateless mode distributes configuration parameters like DNS server addresses to hosts that use SLAAC for address assignment, combining the benefits of both.
Question 20: An administrator wants to use sFlow on an Aruba switch to analyze traffic patterns. What does sFlow sample?
- A statistical sample of packets at a configurable rate (Correct answer)
- Only ICMP and ARP packets
- Every packet on monitored interfaces
- Only inter-VLAN routed traffic
Correct answer: A statistical sample of packets at a configurable rate
sFlow uses statistical packet sampling at a configurable rate (e.g., 1 in 1000 packets) to provide traffic visibility with minimal switch overhead.
Question 21: What is the primary difference between RIP and OSPF?
- RIP is faster
- OSPF uses link-state while RIP uses distance-vector
- RIP supports more routers
- OSPF uses less bandwidth
RIP (Routing Information Protocol) is a distance-vector protocol, meaning routers share their entire routing tables with neighbors, and routes are chosen based on hop count. OSPF (Open Shortest Path First) is a link-state protocol, where routers build a complete map of the network topology and calculate the shortest path using an algorithm like Dijkstra's. This fundamental difference allows OSPF to converge faster and scale better in larger, more complex networks compared to RIP.
Question 22: An administrator needs to verify that VLAN 100 exists and is active on an Aruba CX switch. Which command provides this information?
- show vlan summary
- show interface vlan 100
- show vlan 100 (Correct answer)
- show running-config vlan 100
Correct answer: show vlan 100
'show vlan 100' displays the status, name, and port membership of VLAN 100, confirming whether it exists and is active.
Question 23: An administrator wants to permit SSH (port 22) from a management subnet 10.0.0.0/24 only. Which ACL entry accomplishes this?
- permit udp 10.0.0.0/24 any eq 22
- permit tcp any 10.0.0.0/24 eq 22
- permit tcp 10.0.0.0/24 any eq 22 (Correct answer)
- permit ip 10.0.0.0/24 any
Correct answer: permit tcp 10.0.0.0/24 any eq 22
SSH uses TCP port 22; permitting tcp from the source subnet to any destination on port 22 correctly scopes the rule.
Question 24: A network manager receives sporadic syslog messages but cannot determine the exact sequence of events. What should they enable to improve log correlation?
- SNMP v2c community strings
- RSPAN for traffic mirroring
- NTP synchronization for accurate timestamps (Correct answer)
- Spanning tree PortFast
Correct answer: NTP synchronization for accurate timestamps
Accurate NTP-synchronized timestamps on all switches ensure syslog messages can be chronologically correlated across multiple devices.
Question 25: On an Aruba switch, what is the effect of setting a VLAN to 'voice' type on an access port?
- It assigns QoS markings to all frames on the port
- It enables LLDP-MED to automatically configure IP phones on a separate voice VLAN (Correct answer)
- It blocks all non-voice traffic on that port
- It encrypts all voice traffic on the VLAN
Correct answer: It enables LLDP-MED to automatically configure IP phones on a separate voice VLAN
Setting a VLAN type to 'voice' allows LLDP-MED to signal IP phones to use the designated voice VLAN automatically.
Question 26: An administrator is configuring DHCP Snooping on an ArubaOS-CX switch to mitigate rogue DHCP server attacks. What is the default state of all switch ports when DHCP Snooping is first enabled on a VLAN?
- Untrusted (Correct answer)
- Disabled
- Forwarding
- Trusted
Correct answer: Untrusted
When DHCP Snooping is enabled, all ports are considered untrusted by default. The administrator must explicitly configure the ports connected to legitimate DHCP servers or upstream switches as trusted to allow DHCP server messages to pass.
Question 27: An administrator configures VRRP on an ArubaOS-CX switch. What is the default priority value for a VRRP router?
- 150
- 255
- 100 (Correct answer)
- 1
Correct answer: 100
The default priority for a VRRP router is 100. A higher value indicates a higher priority for becoming the Master router. The priority can be configured to a value between 1 and 254. A priority of 255 is reserved for the router that owns the virtual IP address (IP address owner).
Question 28: Which VRRP state is a router in when it is actively forwarding traffic on behalf of the virtual router?
- Initialize
- Master (Correct answer)
- Active
- Backup
Correct answer: Master
The Master state is the active forwarding state in VRRP; only the master router forwards traffic for the virtual IP and responds to ARP requests.
Question 29: On an Aruba switch, which DSCP value is associated with the Expedited Forwarding (EF) per-hop behavior used for voice traffic?
- DSCP 46 (Correct answer)
- DSCP 34
- DSCP 0
- DSCP 10
Correct answer: DSCP 46
DSCP 46 (101110 binary) is defined as Expedited Forwarding (EF) and is the standard marking for voice traffic requiring low latency.
Question 30: A network engineer wants to ensure that only one specific MAC address is allowed on an access port. Which combination of features is most appropriate on an Aruba CX switch?
- 802.1X with MAC authentication bypass only
- DHCP snooping with binding limit of 1
- IP Source Guard with a single static entry
- Port security with a static allowed MAC and MAC limit of 1 (Correct answer)
Correct answer: Port security with a static allowed MAC and MAC limit of 1
Port security with a static allowed MAC and a limit of 1 ensures only that single device can communicate on the port.
Question 31: What action does BPDU Guard take when it receives a BPDU on a protected PortFast-enabled access port?
- Increases the STP bridge priority
- Transitions the port to the STP root state
- Places the port into an err-disabled state (Correct answer)
- Sends a BPDU trap to the NMS and continues
Correct answer: Places the port into an err-disabled state
BPDU Guard immediately disables (err-disables) a PortFast port upon receiving any BPDU, protecting the STP topology.
Question 32: A network administrator is configuring a link aggregation group (LAG) between two ArubaOS-CX switches. The administrator wants to ensure that the LAG is formed only if LACP negotiations are successful between the two switches. Which LACP mode combination should be configured on the two switches to achieve this?
- Active on one switch and Passive on the other switch. (Correct answer)
- Active on both switches and Static on one switch.
- Static on both switches.
- Passive on both switches.
Correct answer: Active on one switch and Passive on the other switch.
For a dynamic LACP LAG to form, at least one side must be in 'active' mode to initiate the LACP negotiation. An active-passive combination is a standard and valid configuration where the active side sends LACPDU packets, and the passive side responds, successfully forming the aggregation. Two passive sides will never form a LAG because neither will initiate the negotiation.
Question 33: What is the purpose of the 'vsx-sync' configuration on an AOS-CX VSX switch?
- It specifies which protocol state (e.g., VLANs, OSPF, ACLs) is synchronized across the ISL (Correct answer)
- It sets the ISL keepalive interval
- It forces both peers to share a single management session
- It defines the MCLAG system-MAC address
Correct answer: It specifies which protocol state (e.g., VLANs, OSPF, ACLs) is synchronized across the ISL
The 'vsx-sync' stanza lists the specific protocol and configuration domains (VLANs, ACLs, OSPF, etc.) that should be synchronized between VSX peers over the ISL.
Question 34: What is the standard format of the virtual MAC address used by an IPv4 VRRP group?
- 00-00-5E-00-02-{VRID}
- It is inherited from the physical MAC address of the Master router.
- 00-00-5E-00-01-{VRID} (Correct answer)
- 00-00-0C-07-AC-{VRID}
Correct answer: 00-00-5E-00-01-{VRID}
The IETF standard for VRRPv2 and VRRPv3 for IPv4 defines the virtual MAC address as 00-00-5E-00-01-{VRID}, where the first part is the IANA-assigned OUI and the last octet is the Virtual Router Identifier (VRID).
Question 35: Which AOS-CX VSF command allows an administrator to manually trigger a failover and promote the Standby to Conductor?
- vsf failover (Correct answer)
- vsf promote member 2
- vsf move-role standby conductor
- redundancy switchover
Correct answer: vsf failover
The 'vsf failover' command initiates a graceful failover, promoting the Standby member to Conductor and demoting the current Conductor.
Question 36: What distinguishes an 'accept mode' configuration in VRRPv3 on Aruba switches?
- The switch accepts VRRP configuration changes without a reload
- The master accepts routing updates from backup routers
- Non-IP-owner master routers accept and respond to packets destined for the virtual IP (Correct answer)
- Backup routers accept advertisement packets from any source
Correct answer: Non-IP-owner master routers accept and respond to packets destined for the virtual IP
In accept mode, a VRRP master that does not own the virtual IP (non-owner) will still accept and process packets destined for the virtual IP address.
Question 37: What is the primary purpose of the 'qos trust' command on an Aruba access port?
- Enables LLDP for QoS negotiation
- Instructs the switch to honor incoming DSCP or CoS markings (Correct answer)
- Resets all packet markings to default
- Enables policing on ingress traffic
Correct answer: Instructs the switch to honor incoming DSCP or CoS markings
'qos trust dscp' or 'qos trust cos' tells the switch to use the packet's existing markings rather than overriding them with a default value.
Question 38: Which ArubaOS-CX feature allows administrators to write custom Python scripts that react to network events and automatically remediate issues?
- SNMP inform messages
- Network Analytics Engine (NAE) (Correct answer)
- OpenConfig streaming telemetry
- REST API webhooks
Correct answer: Network Analytics Engine (NAE)
NAE on ArubaOS-CX enables Python-based monitoring agents that can trigger automated actions in response to network events and threshold violations.
Question 39: An Aruba switch administrator wants to limit a specific application's bandwidth to 10 Mbps and remarked excess traffic rather than drop it. Which policer action should be configured?
- action exceed drop
- action exceed remark dscp <value> (Correct answer)
- action exceed queue lowest
- action exceed shape 10m
Correct answer: action exceed remark dscp <value>
The 'action exceed remark dscp' option allows traffic above the committed rate to be forwarded with a lower DSCP value instead of being dropped.
Question 40: An Aruba CX switch administrator needs to prioritize voice traffic end-to-end. At the ingress access port, which action should be taken to trust the phone's DSCP markings?
- Enable LLDP-MED to automatically trust all QoS markings
- Apply 'qos trust dscp' on the access port (Correct answer)
- Apply 'qos trust cos' on the uplink port only
- Use a policy map to remark all traffic to DSCP 0
Correct answer: Apply 'qos trust dscp' on the access port
'qos trust dscp' on the access port instructs the switch to honor the DSCP markings applied by the IP phone.
Question 41: What is the recommended underlay MTU configuration for a VXLAN deployment to prevent fragmentation of encapsulated tenant frames?
- 1550 bytes (standard MTU plus estimated VXLAN overhead)
- 9000 bytes or larger (jumbo frames) (Correct answer)
- 1600 bytes (standard MTU plus a 100-byte buffer)
- 1500 bytes (standard Ethernet MTU)
Correct answer: 9000 bytes or larger (jumbo frames)
VXLAN adds approximately 50 bytes of overhead (outer IP/UDP/VXLAN headers); jumbo frames (9000 bytes) in the underlay are strongly recommended to carry full-size tenant frames without fragmentation.
Question 42: Which address does an IPv6 host use when communicating with the DHCPv6 server during stateful address assignment?
- The all-nodes multicast address ff02::1
- The global unicast address assigned by SLAAC
- The link-local address as the source (Correct answer)
- The loopback address ::1
Correct answer: The link-local address as the source
DHCPv6 messages are sourced from the host's link-local address since a global unicast address has not yet been assigned.
Question 43: On an Aruba CX switch, which VLAN configuration is required before a port can be assigned to that VLAN?
- The VLAN must be created in the global VLAN database (Correct answer)
- The VLAN must be assigned a name
- The VLAN must have an SVI configured
- The VLAN must be added to an uplink trunk first
Correct answer: The VLAN must be created in the global VLAN database
A VLAN must exist in the global VLAN database before it can be assigned to any port as an access or trunk VLAN.
Question 44: An administrator is configuring VRRP on two ArubaOS-CX switches to provide gateway redundancy for a critical VLAN. Switch-A is configured with a priority of 110 and Switch-B is configured with the default priority. Preemption is enabled on both switches. Initially, Switch-A is the Master. If Switch-A fails and then later recovers, what will be its final VRRP state?
- Init
- Standby
- Backup
- Master (Correct answer)
Correct answer: Master
With preemption enabled, a VRRP router with a higher priority will always attempt to become the Master. Since Switch-A has a higher priority (110) than Switch-B (default 100), it will take over the Master role from Switch-B once it recovers and its VRRP process is fully initialized.
Question 45: What does an IP address of 192.168.1.1/24 represent?
- Private IP address with a /24 subnet
- Private IP address with a /32 subnet
- Public IP address with a /24 subnet
- Public IP address
The IP address 192.168.1.1 falls within the 192.168.0.0/16 range, which is reserved for private IP addresses as defined by RFC 1918. The /24 notation, also known as CIDR (Classless Inter-Domain Routing), specifies that the first 24 bits of the IP address represent the network portion. This means the subnet mask is 255.255.255.0, defining a network with 254 usable host addresses.
Question 46: What STP feature disables a PortFast-enabled port when it receives a BPDU, protecting against accidental switch connections?
- BPDU Filter
- Loop Guard
- Root Guard
- BPDU Guard (Correct answer)
Correct answer: BPDU Guard
BPDU Guard err-disables a port upon receiving any BPDU, preventing switches from being connected to PortFast ports and disrupting the topology.
Question 47: On an ArubaOS-CX switch, which REST API method is used to retrieve the current running configuration?
- POST /rest/v10.08/system/config/running
- PATCH /rest/v10.08/system/config
- PUT /rest/v10.08/system/full-configuration
- GET /rest/v10.08/system?depth=2 (Correct answer)
Correct answer: GET /rest/v10.08/system?depth=2
A GET request to the system endpoint with appropriate depth parameter retrieves the current running configuration via the ArubaOS-CX REST API.
Question 48: On Aruba AOS-CX, which protocol is used to synchronize time across the switch for accurate logging and security?
- NTP (Correct answer)
- Chrony
- SNTP only
- PTP only
Correct answer: NTP
AOS-CX supports NTP (Network Time Protocol) to synchronize the system clock for accurate logging, certificates, and security policies.
Question 49: Which Aruba Central feature allows an administrator to set up automated alerts when a switch CPU exceeds a defined threshold?
- Threshold-based alerts in the Alerts & Events module (Correct answer)
- Traffic Analysis
- AI Insights
- Audit Trails
Correct answer: Threshold-based alerts in the Alerts & Events module
Aruba Central's Alerts & Events module allows configuring threshold-based alerts that trigger notifications when metrics like CPU utilization exceed defined limits.
Question 50: What is the purpose of VPNs?
- To speed up the internet
- To secure communication over the internet
- To block access to websites
- To share data between users
Virtual Private Networks (VPNs) are designed to create a secure, encrypted connection over a public network, such as the internet. This secure tunnel protects data from eavesdropping and tampering, ensuring privacy and integrity for communications. VPNs are essential for remote access to corporate networks and for users seeking enhanced online privacy.
Question 51: A switch receives a BPDU with a lower bridge ID than its own on a designated port. What action does STP take?
- The port transitions to Blocking state (Correct answer)
- The port transitions to Forwarding state immediately
- The switch becomes the new root bridge
- The BPDU is discarded and the topology remains unchanged
Correct answer: The port transitions to Blocking state
When a designated port receives a superior BPDU, it yields and transitions to Blocking (or Discarding in RSTP), losing its designated role.
Question 52: In ArubaOS-CX, what is the default action when a port security violation occurs (MAC limit exceeded)?
- Send an SNMP trap only and continue learning
- Restrict new MACs and send a log message
- Err-disable the port immediately (Correct answer)
- Block only the offending MAC address
Correct answer: Err-disable the port immediately
By default, when the MAC limit is exceeded on an ArubaOS-CX port, the port is placed into err-disabled state.
Question 53: Which Aruba ACL type is specifically designed to filter traffic based on EtherType values such as ARP or IPv6?
- VLAN ACL
- MAC ACL with EtherType matching (Correct answer)
- Standard IP ACL
- Extended IP ACL
Correct answer: MAC ACL with EtherType matching
MAC ACLs on Aruba switches support EtherType matching, enabling filtering of specific Layer 2 protocols like ARP (0x0806) or IPv6 (0x86DD).
Question 54: A network administrator configures an ArubaOS-CX switch for OSPF. The administrator wants to advertise the network associated with interface 1/1/5 into OSPF, but prevent the switch from forming OSPF adjacencies on that interface. Which command sequence achieves this goal?
- switch(config)# interface 1/1/5 switch(config-if)# ip ospf passive (Correct answer)
- switch(config)# interface 1/1/5 switch(config-if)# ip ospf shutdown
- switch(config)# router ospf 1 switch(config-ospf-1)# passive-interface 1/1/5
- switch(config)# router ospf 1 switch(config-ospf-1)# passive-interface default
Correct answer: switch(config)# interface 1/1/5 switch(config-if)# ip ospf passive
On ArubaOS-CX switches, the `ip ospf passive` command, configured under a specific interface, is the correct method to prevent OSPF Hello packets from being sent on that interface while still allowing the interface's network to be advertised. The `passive-interface <interface>` command is not a valid syntax in the router OSPF context on ArubaOS-CX. `passive-interface default` would make all interfaces passive, and `ip ospf shutdown` would disable OSPF entirely on the interface.
Question 55: Which SNMP operation does a management station use to retrieve a series of consecutive MIB variables from a switch?
- SNMP GetBulk (Correct answer)
- SNMP Get
- SNMP Set
- SNMP Inform
Correct answer: SNMP GetBulk
GetBulk retrieves multiple MIB variables in a single request, making it more efficient than issuing repeated GetNext operations for table data.
Question 56: When configuring LACP system priority on an Aruba CX switch, which value results in the switch having higher authority in LAG negotiations?
- System priority is irrelevant when ports have equal priority
- Higher system priority value
- System priority of 32768 always wins
- Lower system priority value (Correct answer)
Correct answer: Lower system priority value
A lower LACP system priority value gives the switch higher authority to determine which ports are active when there are more ports than the LAG maximum allows.
Question 57: Which AOS-CX command verifies that LLDP is receiving neighbor information on interface 1/1/5?
- show lldp neighbors interface 1/1/5 (Correct answer)
- show lldp neighbor-info 1/1/5
- debug lldp interface 1/1/5
- show lldp 1/1/5 detail
Correct answer: show lldp neighbors interface 1/1/5
'show lldp neighbors interface 1/1/5' displays LLDP neighbor information discovered on that specific interface.
Question 58: Which routing protocol is used for dynamic routing in small to medium-sized networks?
- OSPF
- RIP
- EIGRP
- BGP
RIP (Routing Information Protocol) is a distance-vector routing protocol commonly used for dynamic routing in small to medium-sized networks. It is known for its simplicity and ease of configuration, using hop count as its metric to find the best path. While less scalable than protocols like OSPF or EIGRP, RIP's straightforward nature makes it suitable for less complex network environments.
Question 59: A network uses the address block 10.0.0.0/8 and needs to create 100 subnets with at least 500 hosts each. Which subnet mask satisfies both requirements?
- /23 (Correct answer)
- /25
- /22
- /24
Correct answer: /23
A /23 provides 512 host addresses (510 usable) and allows up to 128 subnets within 10.0.0.0/8, satisfying both requirements.
Question 60: An ArubaOS-CX switch needs to be configured to participate in OSPF Area 0. Which of the following is the minimum required configuration to establish an OSPF process and assign an interface to Area 0?
- switch(config)# router ospf 1 switch(config-ospf-1)# router-id 10.1.1.1 switch(config-ospf-1)# area 0 switch(config)# interface 1/1/1 switch(config-if)# ip ospf 1 area 0 (Correct answer)
- switch(config)# router ospf 1 switch(config-ospf-1)# area backbone switch(config)# interface 1/1/1 switch(config-if)# ip address 192.168.1.1/24
- switch(config)# enable ospf switch(config)# interface 1/1/1 switch(config-if)# ospf area 0
- switch(config)# router ospf 1 area 0 switch(config-ospf-1)# network 192.168.1.0/24
Correct answer: switch(config)# router ospf 1 switch(config-ospf-1)# router-id 10.1.1.1 switch(config-ospf-1)# area 0 switch(config)# interface 1/1/1 switch(config-if)# ip ospf 1 area 0
To configure OSPF on an ArubaOS-CX switch, you must first create the OSPF process using `router ospf <PROCESS-ID>`. A `router-id` must be configured for the process to start. Then, you must explicitly enable OSPF on an interface and assign it to an area using the `ip ospf <PROCESS-ID> area <AREA-ID>` command under the interface configuration context.
Aruba Certified Switching Professional (ACSP) HPE6-A73
The ACSP exam validates the ability to implement and operate enterprise-level HPE Aruba campus switching solutions, covering wired network planning, installation and configuration of AOS-CX switches, troubleshooting, and network management and monitoring.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds