DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free HP HPE6-A84 Practice Questions & Answers 2026 Part2 | Aruba Certified

Are you preparing for the Aruba HPE6-A84 certification exam? SPOTO offers the Aruba HPE6-A84 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
Refer to the scenario.
A. As Kerberos type
B. As Active Directory type
C. As HTTP type, referencing the Intune extension
D. AS HTTP type, referencing Azure AD's FODN
View answer
Correct Answer: D
Question #2
Refer to the scenario.A hospital has an AOS10 architecture that is managed by Aruba Central. The customer has deployed apair of Aruba 9000 Series gateways with Security licenses at each clinic. The gateways implementIDS/IPS in IDS mode.The Security Dashboard shows these several recent events with the same signature, as shown below:Which step could give you valuable context about the incident?
A. iew firewall sessions on the APs and record the threat sources' type and OS
B. iew the user-table on APs and record the threat sources' 802
C. iew the RAPIDS Security Dashboard and see if the threat sources are listed as rogues
D. ind the Central client profile for the threat sources and note their category and family
View answer
Correct Answer: C
Question #3
Refer to the scenario.A customer is migrating from on-prem AD to Azure AD as its sole domain solution. The customer also manages both wired and wireless devices with Microsoft Endpoint Manager (Intune).The customer wants to improve security for the network edge. You are helping the customer design a ClearPass deployment for this purpose. Aruba network devices will authenticate wireless and wired clients to an Aruba ClearPass Policy Manager (CPPM) cluster (which uses version 6.10).The customer has several requirements for authentication. The clients should only pass EAP-TLS authentication if a query to Azure AD shows that they have accounts in Azure AD. To further refine the clients' privileges, ClearPass also should use information collected by Intune to make access control decisions.The customer wants you to configure CPPM to collect information from Intune on demand during the authentication process.What should you tell the Intune admins about the certificates issued to clients?
A. hey must be issued by a well-known, trusted CA
B. hey must be issued by a ClearPass Onboard CA
C. hey must include the Intune ID in the subject name
D. hey must include the client MAC address in the subject name
View answer
Correct Answer: C
Question #4
You are setting up Aruba ClearPass Policy Manager (CPPM) to enforce EAP-TLS authentication with Active Directory as the authentication source. The company wants to prevent users with disabled accounts from connecting even if those users still have valid certificates.
A. Add an Endpoint Context Server to the domain controller with actions for querying the domain controller for account status
B. Enable OCSP in the EAP-TLS authentication method settings and configure an OCSP override to the domain controller FQDN
C. Add a custom attribute for userAccountControl to the filters in the AD authentication source
D. Install a Microsoft Active Directory extension in Aruba ClearPass Guest and set up an HTTP authentication source that points to that extension
View answer
Correct Answer: C
Question #5
How does Aruba Central handle security for site-to-site connections between AOS 10 gateways?
A. t uses an Aruba proprietary integrity and encryption technologies to secure site-to-site connections, making them resistant to zero day attacks
B. t automatically establishes IPsec tunnels for all site-to-site (all HUBs and Branches) connections using keys securely distributed by Central
C. t automatically steers traffic away from Internet-based connections to more secure MPLS connections to reduce encryption overhead
D. t automatically establishes simple-to-manage and highly secure TLSv1
View answer
Correct Answer: B
Question #6
A customer has an AOS 10 architecture, consisting of Aruba AP and AOS-CX switches, managed by Aruba Central. The customer wants to obtain information about the clients, such as their general category and OS.What should you explain?
A. he customer must deploy Aruba gateways in order to receive any client profiling information
B. ou will need to set up Aruba Central as a secondary IP helper for client VLANs, but this will not interfere with existing operations
C. ruba Central will automatically derive this information using telemetry from the Aruba devices
D. he customer should set up a dedicated switch VSX group to sniff packets and direct them to Aruba Central
View answer
Correct Answer: C
Question #7
A customer's admins have added RF Protect licenses and enabled WIDS for a customer's AOS 8-based solution. The customer wants to use the built-in capabilities of APs without deploying dedicated air monitors (AMs). Admins tested rogue AP detection by connecting an unauthorized wireless AP to a switch. The rogue AP was not detected even after several hours.What is one point about which you should ask?
A. Whether APs' switch ports support all the VLANs that are accessible at the edge
B. Whether admins enabled wireless containment
C. Whether admins set at least one radio on each AP to air monitor mode
D. Whether the customer is using non-standard Wi-Fi channels in the deployment
E. Reveal Answer
View answer
Correct Answer: C
Question #8
Refer to the scenario.
A. An app registration on Azure AD that references the CPPM's FQDN
B. Windows 365 subscriptions
C. CPPM's RADIUS certificate was imported as trusted in the Azure AD directory
D. Azure AD Domain Services
View answer
Correct Answer: A
Question #9
Refer to the scenario.A customer has an Aruba ClearPass cluster. The customer has AOS-CX switches that implement802.1X authentication to ClearPass Policy Manager (CPPM).Switches are using local port-access policies.The customer wants to start tunneling wired clients that pass user authentication only to an Arubagateway cluster. The gateway cluster should assign these clients to the “eth-internet" role. Thegateway should also handle assigning clients to their VLAN, which is VLAN 20.The plan for the enforcement policy and profiles is shown below:The gateway cluster has two gateways with these IP addresses:• Gateway 1o VLAN 4085 (system IP) = 10.20.4.21o VLAN 20 (users) = 10.20.20.1o VLAN 4094 (WAN) = 198.51.100.14• Gateway 2o VLAN 4085 (system IP) = 10.20.4.22o VLAN 20 (users) = 10.20.20.2o VLAN 4094 (WAN) = 198.51.100.12• VRRP on VLAN 20 = 10.20.20.254The customer requires high availability for the tunnels between the switches and the gateway cluster.If one gateway falls, the other gateway should take over its tunnels. Also, the switch should be ableto discover the gateway cluster regardless of whether one of the gateways is in the cluster.Assume that you are using the “myzone” name for the UBT zone.Which is a valid minimal configuration for the AOS-CX port-access roles?
A. ort-access role eth-internet gateway-zone zone myzone gateway-role eth-user
B. ort-access role internet-only gateway-zone zone myzone gateway-role eth-internet
C. ort-access role eth-internet gateway-zone zone myzone gateway-role eth-internet vlan access 20
D. ort-access role internet-only gateway-zone zone myzone gateway-role eth-internet vlan access
View answer
Correct Answer: B
Question #10
Refer to the scenario.
A. Let the RADIUS server confiqure VLANs on LAG 1 dynamically
B. Use MDS instead of SHA1 for the NTP authentication key
C. Encrypt the certificate in the TA-profile
D. Create a control plane ACL to limit the sources that can access the switch with SSH
View answer
Correct Answer: D
Question #11
Refer to the scenario.A customer is migrating from on-prem AD to Azure AD as its sole domain solution. The customer alsomanages both wired and wireless devices with Microsoft Endpoint Manager (Intune).The customer wants to improve security for the network edge. You are helping the customer design aClearPass deployment for this purpose. Aruba network devices will authenticate wireless and wiredclients to an Aruba ClearPass Policy Manager (CPPM) cluster (which uses version 6.10).The customer has several requirements for authentication. The clients should only pass EAP-TLSauthentication if a query to Azure AD shows that they have accounts in Azure AD. To further refinethe clients’ privileges, ClearPass also should use information collected by Intune to make accesscontrol decisions.You are planning to use Azure AD as the authentication source in 802.1X services.What should you make sure that the customer understands is required?
A. n app registration on Azure AD that references the CPPM's FQDN
B. indows 365 subscriptions
C. PPM's RADIUS certificate was imported as trusted in the Azure AD directory
D. zure AD Domain Services
View answer
Correct Answer: A
Question #12
A customer has an AOS 10-based mobility solution, which authenticates clients to Aruba ClearPass Policy Manager (CPPM). The customer has some wireless devices that support WPA2 in personal mode only.How can you meet these devices’ needs but improve security?
A. Use MPSK on the WLAN to which the devices connect
B. Configure WIDS policies that apply extra monitoring to these particular devices
C. Connect these devices to the same WLAN to which 802
D. Enable dynamic authorization (RFC 3576) in the AAA profile for the devices
E. Reveal Answer
View answer
Correct Answer: A
Question #13
You are setting up Aruba ClearPass Policy Manager (CPPM) to enforce EAP-TLS authentication with Active Directory as the authentication source. The company wants to prevent users with disabled accounts from connecting even if those users still have valid certificates.As the first part of meeting these criteria, what should you do to enable CPPM to determine where accounts are enabled in AD or not?
A. Add an Endpoint Context Server to the domain controller with actions for querying the domain controller for account status
B. Enable OCSP in the EAP-TLS authentication method settings and configure an OCSP override to the domain controller FQDN
C. Add a custom attribute for userAccountControl to the filters in the AD authentication source
D. Install a Microsoft Active Directory extension in Aruba ClearPass Guest and set up an HTTP authentication source that points to that extension
E. Reveal Answer
View answer
Correct Answer: C
Question #14
Refer to the scenario.An organization wants the AOS-CX switch to trigger an alert if its RADIUS server (cp.acnsxtest.local) rejects an unusual number of client authentication requests per hour. After some discussions with other Aruba admins, you are still not sure how many rejections are usual or unusual. You expect that the value could be different on each switch.You are helping the developer understand how to develop an NAE script for this use case.You are helping a customer define an NAE script for AOS-CX switches. The script will monitor statistics from a RADIUS server defined on the switch. You want to future proof the script by enabling admins to select a different hostname or IP address for the monitored RADIUS server when they create an agent from the script.What should you recommend?
A. Use this variable, %{radius-ipV when defining the monitor URI in the NAE agent script
B. Define a parameter for the RADIUS server; reference that parameter instead of the server name/ip when defining the monitor URI
C. Use a callback action to collect the name of any RADIUS servers defined on the switch at the time the agent is created
D. Make the script editable so that admins can edit it on demand when they are creating scripts
E. Reveal Answer
View answer
Correct Answer: B
Question #15
Refer to the scenario.A customer is migrating from on-prem AD to Azure AD as its sole domain solution. The customer also manages both wired and wireless devices with Microsoft Endpoint Manager (Intune).The customer wants to improve security for the network edge. You are helping the customer design a ClearPass deployment for this purpose. Aruba network devices will authenticate wireless and wired clients to an Aruba ClearPass Policy Manager (CPPM) cluster (which uses version 6.10).The customer has several requirements for authentication. The clients should only pass EAP-TLS authentication if a query to Azure AD shows that they have accounts in Azure AD. To further refine the clients' privileges, ClearPass also should use information collected by Intune to make access control decisions.Assume that the Azure AD deployment has the proper prerequisites established.You are planning the CPPM authentication source that you will reference as the authentication source in802.1X services.How should you set up this authentication source?
A. s Kerberos type
B. s HTTP type, referencing the Intune extension
C. s Active Directory type
D. S HTTP type, referencing Azure AD's FODN
View answer
Correct Answer: D
Question #16
You are designing an Aruba ClearPass Policy Manager (CPPM) solution for a customer. You learn that the customer has a Palo Alto firewall that filters traffic between clients in the campus and the data center.Which integration can you suggest?
A. Sending Syslogs from the firewall to CPPM to signal CPPM to change the authentication status for misbehaving clients
B. Importing clients’ MAC addresses to configure known clients for MAC authentication more quickly
C. Establishing a double layer of authentication at both the campus edge and the data center DMZ
D. Importing the firewall's rules to program downloadable user roles for AOS-CX switches more quickly
View answer
Correct Answer: A
Question #17
Refer to the scenario.A customer requires these rights for clients in the “medical-mobile” AOS firewall role on Aruba Mobility Controllers (MCs):Permitted to receive IP addresses with DHCPPermitted access to DNS services from 10.8.9.7 and no other serverPermitted access to all subnets in the 10.1.0.0/16 range except denied access to 10.1.12.0/22Denied access to other 10.0.0.0/8 subnetsPermitted access to the InternetDenied access to the WLAN for a period of time if they send any SSH trafficDenied access to the WLAN for a period of time if they send any Telnet trafficDenied access to all high-risk websitesExternal devices should not be permitted to initiate sessions with “medical-mobile” clients, only send return traffic.The exhibits below show the configuration for the role.There are multiple issues with this configuration. What is one change you must make to meet the scenario requirements? (In the options, rules in a policy are referenced from top to bottom. For example, “medical-mobile” rule 1 is “ipv4 any any svc-dhcp permit,” and rule 8 is “ipv4 any any any permit”.)
A. n the “medical-mobile” policy, move rules 2 and 3 between rules 7 and 8
B. n the “medical-mobile” policy, change the subnet mask in rule 3 to 255
C. ove the rule in the “apprf-medical-mobile-sacl” policy between rules 7 and 8 in the “medical-mobile” policy
D. n the “medical-mobile” policy, change the source in rule 8 to “user
View answer
Correct Answer: B
Question #18
A customer requires a secure solution for connecting remote users to the corporate main site. Youare designing a client-to-site virtual private network (VPN) based on Aruba VIA and Aruba MobilityControllers acting as VPN Concentrators (VPNCs). Remote users will first use the VIA client to contactthe VPNCs and obtain connection settings.The users should only be allowed to receive the settings if they are the customer's“RemoteEmployees” AD group. After receiving the settings, the VIA clients will automaticallyestablish VPN connections, authenticating to CPPM with certificates.What should you do to help ensure that only authorized users obtain VIA connection settings?
A. et up the VPNCs' VIA web authentication profile to use CPPM as the authentication server; set up a service on CPPM that uses AD as the authentication source
B. et up the VPNCs' VIA web authentication profile to use an AD domain controller as the LDAP server
C. et up the VPNCs' VIA connection profile to use two authentication profiles, one RADIUS profile to CPPM and one LDAP profile to AD
D. et up the VPNCs' VIA connection profile to use one authentication profile, which is set to the AD domain controller's hostname
View answer
Correct Answer: A
Question #19
A company has an Aruba ClearPass server at 10.47.47.8, FQDN radius.acnsxtest.local. This exhibit shows ClearPass Policy Manager's (CPPM's) settings for an Aruba Mobility Controller (MC).The MC is already configured with RADIUS authentication settings for CPPM, and RADIUS requests between the MC and CPPM are working. A network admin enters and commits this command to enable dynamic authorization on the MC: aaa rfc-3576-server 10.47.47.8But when CPPM sends CoA requests to the MC, they are not working. This exhibit shows the RFC 3576 server statistics on the MC:How could you fix this issue?
A. hange the UDP port in the MCs’ RFC 3576 server config to 3799
B. nable RadSec on the MCs’ RFC 3676 server config
C. onfigure the MC to obtain the time from a valid NTP server
D. ake sure that CPPM is using an ArubaOS Wireless RADIUS CoA enforcement profile
View answer
Correct Answer: A
Question #20
Refer to the scenario.A customer requires these rights for clients in the “medical-mobile” AOS firewall role on Aruba Mobility Controllers (MCs):Permitted to receive IP addresses with DHCPPermitted access to DNS services from 10.8.9.7 and no other serverPermitted access to all subnets in the 10.1.0.0/16 range except denied access to 10.1.12.0/22Denied access to other 10.0.0.0/8 subnetsPermitted access to the InternetDenied access to the WLAN for a period of time if they send any SSH trafficDenied access to the WLAN for a period of time if they send any Telnet trafficDenied access to all high-risk websitesExternal devices should not be permitted to initiate sessions with “medical-mobile” clients, only send return traffic.The exhibits below show the configuration for the role.There are multiple issues with this configuration. What is one change you must make to meet the scenario requirements? (In the options, rules in a policy are referenced from top to bottom. For example, “medical-mobile” rule 1 is “ipv4 any any svc-dhcp permit,” and rule 8 is “ipv4 any any any permit”.)
A. In the “medical-mobile” policy, move rules 2 and 3 between rules 7 and 8
B. In the “medical-mobile” policy, change the subnet mask in rule 3 to 255
C. Move the rule in the “apprf-medical-mobile-sacl” policy between rules 7 and 8 in the “medical-mobile” policy
D. In the “medical-mobile” policy, change the source in rule 8 to “user
View answer
Correct Answer: B
Question #21
You are configuring gateway IDS/IPS settings in Aruba Central.
A. To permit traffic if the IPS engine falls to inspect It
B. To enable the gateway to honor the allowlist settings configured in IDS/IPS policies
C. To tell gateways to stop enforcing IDS/IPS policies if they lose connectivity to the Internet
D. To avoid wasting IPS engine resources on filtering traffic for unauthenticated clients
View answer
Correct Answer: A
Question #22
When would you implement BPDU protection on an AOS-CX switch port versus BPDU filtering?
A. Use BPDU protection on edge ports to protect against rogue devices when the switch implements MSTP; use BPDU filtering to protect against rogue devices when the switch implements PVSTP+
B. Use BPDU protection on edge ports to prevent rogue devices from connecting; use BPDU filtering on inter-switch ports for specialized use cases
C. Use BPDU protection on inter-switch ports to ensure that they are selected as root; use BPDU
D. filtering on edge ports to prevent rogue devices from connecting
E. Use BPDU protection on edge ports to permanently lock out rogue devices; use BPDU filtering on edge ports to temporarily lock out rogue devices
F. Reveal Answer
View answer
Correct Answer: B
Question #23
Refer to the scenario.A customer requires these rights for clients in the “medical-mobile” AOS firewall role on ArubaMobility Controllers (MCs):Permitted to receive IP addresses with DHCPPermitted access to DNS services from 10.8.9.7 and no other serverPermitted access to all subnets in the 10.1.0.0/16 range except denied access to 10.1.12.0/22Denied access to other 10.0.0.0/8 subnetsPermitted access to the InternetDenied access to the WLAN for a period of time if they send any SSH trafficDenied access to the WLAN for a period of time if they send any Telnet trafficDenied access to all high-risk websitesExternal devices should not be permitted to initiate sessions with “medical-mobile” clients, onlysend return traffic.The line below shows the effective configuration for the role.There are multiple issues with this configuration. What is one change you must make to meet thescenario requirements? (In the options, rules in a policy are referenced from top to bottom. Forexample, “medical-mobile” rule 1 is “ipv4 any any svc-dhcp permit,” and rule 6 is “ipv4 any any anypermit’.)
A. pply the "apprf-medical-mobile-sjcT policy explicitly to the 'medical-mobile' user-role under the 'medical-mobile" policy
B. n the "medical-mobile" policy, change the action for rules 2 and 3 to reject
C. n the "medical-mobile" policy, move rule 5 under rule 6
D. n the "medical-mobile* policy, change the subnet mask in rule 5 to 255
View answer
Correct Answer: D
Question #24
Refer to the scenario.A customer has an Aruba ClearPass cluster. The customer has AOS-CX switches that implement802.1X authentication to ClearPass Policy Manager (CPPM).Switches are using local port-access policies.The customer wants to start tunneling wired clients that pass user authentication only to an Arubagateway cluster. The gateway cluster should assign these clients to the “eth-internet" role. Thegateway should also handle assigning clients to their VLAN, which is VLAN 20.The plan for the enforcement policy and profiles is shown below:The gateway cluster has two gateways with these IP addresses:• Gateway 1o VLAN 4085 (system IP) = 10.20.4.21o VLAN 20 (users) = 10.20.20.1o VLAN 4094 (WAN) = 198.51.100.14• Gateway 2o VLAN 4085 (system IP) = 10.20.4.22o VLAN 20 (users) = 10.20.20.2o VLAN 4094 (WAN) = 198.51.100.12• VRRP on VLAN 20 = 10.20.20.254The customer requires high availability for the tunnels between the switches and the gateway cluster.If one gateway falls, the other gateway should take over its tunnels. Also, the switch should be ableto discover the gateway cluster regardless of whether one of the gateways is in the cluster.What is one change that you should make to the solution?
A. hange the ubt-client-vlan to VLAN 13
B. onfigure edge ports in VLAN trunk mode
C. emove VLAN assignments from role configurations on the gateways
D. onfigure the UBT solution to use VLAN extend mode
View answer
Correct Answer: C
Question #25
You are reviewing an endpoint entry in ClearPass Policy Manager (CPPM) Endpoints Repository.What is a good sign that someone has been trying to gain unauthorized access to the network?
A. he entry shows an Unknown status
B. he entry lacks a hostname or includes a hostname with long seemingly random characters
C. he entry shows a profile conflict of having a new profile of Computer for a profiled Printer
D. he entry shows multiple DHCP options under the fingerprints
View answer
Correct Answer: C
Question #26
Refer to the scenario.A customer is migrating from on-prem AD to Azure AD as its sole domain solution. The customer also manages both wired and wireless devices with Microsoft Endpoint Manager (Intune).The customer wants to improve security for the network edge. You are helping the customer design a ClearPass deployment for this purpose. Aruba network devices will authenticate wireless and wired clients to an Aruba ClearPass Policy Manager (CPPM) cluster (which uses version 6.10).The customer has several requirements for authentication. The clients should only pass EAP-TLS authentication if a query to Azure AD shows that they have accounts in Azure AD. To further refine the clients’ privileges, ClearPass also should use information collected by Intune to make access control decisions.Assume that the Azure AD deployment has the proper prerequisites established.You are planning the CPPM authentication source that you will reference as the authentication source in 802.1X services.How should you set up this authentication source?
A. As Kerberos type
B. As Active Directory type
C. As HTTP type, referencing the Intune extension
D. AS HTTP type, referencing Azure AD's FODN
E. Reveal Answer
View answer
Correct Answer: D
Question #27
You are configuring gateway IDS/IPS settings in Aruba Central.For which reason would you set the Fail Strategy to Bypass?
A. o tell gateways to stop enforcing IDS/IPS policies if they lose connectivity to the Internet
B. o permit traffic if the IPS engine falls to inspect It
C. o enable the gateway to honor the allowlist settings configured in IDS/IPS policies
D. o avoid wasting IPS engine resources on filtering traffic for unauthenticated clients
View answer
Correct Answer: B
Question #28
Refer to the scenario. A customer requires these rights for clients in the “medical - mobile” AOS firewall role on Aruba Mobility Controllers (MCs) Permitted to receive IP addresses with DHCP Permitted access to DNS services from 10.8.9.7 and no other server Permitted access to all subnets in the 10.1.0.0/16 range except denied access to 10.1.12.0/22 Denied access to other 10.0.0.0/8 subnets Permitted access to the Internet Denied access to the WLAN for a period of time if they send any SSH traffic Denied access to the WLAN for a period of time if they send any Telnet traffic Denied access to all high - risk websites External devices should not be permitted to initiate sessions with “medical - mobile” clients, only send return traffic. The exhibits below show the configuration for the role.There are multiple issues with this configuration. What is one change you must make to meet the scenario requirements? (In the options, rules in a policy are referenced from top to bottom. For example, “medical - mobile” rule 1 is “ipv4 any any svc - dhcp permit,” and rule 8 is “ipv4 any any any permit”.)
A. In the “medical - mobile” policy, move rules 2 and 3 between rules 7 and 8
B. In the “medical - mobile” policy, change the subnet mask in rule 3 to 255
C. Move the rule in the “apprf - medical - mobile - sacl” policy between rules 7 and 8 in the “medical - mobile” policy
D. In the “medical - mobile” policy, change the source in rule 8 to “user
View answer
Correct Answer: B
Question #29
Refer to the scenario.A customer has an Aruba ClearPass cluster. The customer has AOS - CX switches that implement 802.1X authentication to ClearPass Policy Manager (CPPM). Switches are using local port - access policies. The customer wants to start tunneling wired clients that pass user authentication only to an Aruba gateway cluster. The gateway cluster should assign these clients to the “eth - internet" role. The gateway should also handle assigning clients to their VLAN, which is VLAN 20. The plan for the enforcement policy and profiles is shown belowThe gateway cluster has two gateways with these IP addresses • Gateway 1 o VLAN 4085 (system IP) = 10.20.4.21 o VLAN 20 (users) = 10.20.20.1 o VLAN 4094 (WAN) = 198.51.100.14 • Gateway 2 o VLAN 4085 (system IP) = 10.20.4.22 o VLAN 20 (users) = 10.20.20.2 o VLAN 4094 (WAN) = 198.51.100.12 • VRRP on VLAN 20 = 10.20.20.254 The customer requires high availability for the tunnels between the switches and the gateway cluster. If one gateway falls, the other gateway should take over its tunnels. Also, the switch should be able to discover the gateway cluster regardless of whether one of the gateways is in the cluster. You are setting up the UBT zone on an AOS - CX switch. Which IP addresses should you define in the zone?
A. Primary controller = 10
B. [Primary controller = 198
C. Primary controller = 10 20 4 21 backup controller not defined
D. Primary controller = 10
View answer
Correct Answer: A
Question #30
What is a common characteristic of a beacon between a compromised device and a command and control server?
A. Use of IPv6 addressing instead of IPv4 addressing
B. Lack of encryption
C. Use of less common protocols such as SNAP
D. Periodic transmission of small, identically sized packets
E. Reveal Answer
View answer
Correct Answer: D
Question #31
Refer to the scenario.
A. In rule 1 change Subject-CN to Issuer-CN
B. Move rules 2 and 3 to the top of the list
C. Change the rules evaluation mechanism to first applicable
D. Change the default role to 'mobile-onboarded*
View answer
Correct Answer: A

View The Updated Aruba Exam Questions

SPOTO Provides 100% Real Aruba Exam Questions for You to Pass Your Aruba Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us