Black Friday Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

HP Certification HPE7-A01 Dumps PDF

Page: 6 / 8
Question 24

A customer wants to provide wired security as close to the source as possible The wired security must meet the following requirements:

-allow ping from the IT management VLAN to the user VLAN

-deny ping sourcing from the user VLAN to the IT management VLAN

The customer is using Aruba CX 6300s

What is the correct way to implement these requirements?

Options:

A.

Apply an outbound ACL on the user VLAN allowing temp echo-reply traffic toward the IT management VLAN

B.

Apply an inbound ACL on the user VLAN allowing icmp echo-reply traffic toward the IT management VLAN

C.

Apply an inbound ACL on the user VLAN denying icmp echo traffic toward the IT management VLAN

D.

Apply an outbound ACL on the user VLAN denying icmp echo traffic toward the IT management VLAN

Question 25

Your customer is having connectivity issues with a newly-deployed Microbranch group The access points in this group are online in Aruba Central, but no VPN tunnels are forming.

What is the most likely cause of this issue?

Options:

A.

There is a time difference between the AP and the gateways The gateways should have NTP added

B.

The SSL certificate on the gateway used to encrypt the connection has not been added to the APs trust list

C.

There may be a firewall blocking GRE tunneling between the AP and the gateway

D.

The gateway group is running in automatic cluster mode and should be in manual cluster mode

Question 26

A company deployed Dynamic Segmentation with their CX switches and Gateways After performing a security audit on their network, they discovered that the tunnels built between the CX switch and the Aruba Gateway are not encrypted. The company is concerned that bad actors could try to insert spoofed messages on the Gateway to disrupt communications or obtain information about the network.

Which action must the administrator perform to address this situation?

Options:

A.

Enable Secure Mode Enhanced

B.

Enable Enhanced security

C.

Enable Enhanced PAPI security

D.

Enable GRE security

Question 27

Which component is used by the Aruba Network Analytics Engine (NAE)?

Options:

A.

JSON-based scripts

B.

Lisp-based agents

C.

Ruby-based scripts

D.

Current State Database

Page: 6 / 8
Exam Code: HPE7-A01
Exam Name: Aruba Certified Campus Access Professional Exam
Last Update: Nov 24, 2024
Questions: 119
HPE7-A01 pdf

HPE7-A01 PDF

$25.5  $84.99
HPE7-A01 Engine

HPE7-A01 Testing Engine

$28.5  $94.99
HPE7-A01 PDF + Engine

HPE7-A01 PDF + Testing Engine

$40.5  $134.99