# Introduction to the customerYou are helping a company add HPE Aruba Networking ClearPass to their network, which uses HPE Aruba Networking network infrastructure devices.The company currently has a Windows domain and Windows CA. The Window CA issues certificates to domain computers, domain users, and servers such as domain controllers. An example of a certificate issued by the Windows CA is shown here.# ClearPass cluster IP addressing and hostnamesA customer's ClearPass cluster has these IP addresses:• Publisher = 10.47.47.5• Subscriber 1 = 10.47.47.6• Subscriber 2 = 10.47.47.7• Virtual IP with Subscriber 1 and Subscriber 2 = 10.47.47.8The customer's DNS server has these entries• cp.acnsxtest.com = 10.47.47.5• cps1.acnsxtest.com = 10.47.47.6• cps2.acnsxtest.com = 10.47.47.7• radius.acnsxtest.com = 10.47.47.8• onboard.acnsxtest.com = 10.47.47.8Refer to the scenario.Assume that you have set up CPPM to assign HPE Aruba Networking ClearPass roles and AOS user roles as indicated in the scenario. However, a penetration tester was able to access the network with medical staff privileges on a client with a valid computer certificate but revoked medical user certificate. In this circumstance, the customer wants the client to receive computer-only access.What can you do to correct this issue while still meeting the other customer requirements?
A. Add a role mapping rule that assigns clients that have failed TEAP Method 2 to a "user-failed" role
B. Check the order of the enforcement policy rules
C. Change the authentication method configuration to use CRLs to validate certificates' status instead of OCSP
D. Adjust the authentication filter used in the authentication source