Pass Your Aruba Certified ClearPass Expert (ACCX) HPE6-A77 Exam on Dec 28, 2021 with 60 Questions
HPE6-A77 Free Exam Study Guide! (Updated 60 Questions)
HP HPE6-A77 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
NEW QUESTION 16
Refer to the exhibit:
A customer has configured onboard in a cluster with two nodes All devices were onboarded in the network through node1but those clients tail to authenticate through node2 with the error shown. What steps would you suggest to make provisioning and authentication work across the entire cluster? (Select three.)
- A. Configure the Onboard Root CA to trust the Policy Manager EAP certificate root.
- B. Have all of the BYOD clients disconnect and reconnect to me network
- C. Make sure that the HTTPS certificate on both nodes is issued as a Code Signing certificate
- D. Make sure that the EAP certificates on both nodes are issued by one common root Certificate Authority (CA).
- E. Have all of the BYOD clients re-run the Onboard process
- F. Configure the Network Settings in Onboard to trust the Policy Manager EAP certificate
Answer: A,D,F
NEW QUESTION 17
A customer has a ClearPass cluster deployment with four servers, two servers at the data center and two servers at a large remote site connected over an SD-WAN solution The customer would like to implement OnGuard, Guest Self-Registration, and 802.1x authentication across their entire environment. During testing the customer is complaining that users connecting to an Instant Cluster Employee SSID at the remote site, with the OnGuard Persistent Agent installed are randomly getting their health check missed.
What could be a possible cause of this behavior?
- A. The OnGuard Clients are automatically mapped to the Policy Manager Zone based on their IP range but an ACL on the switch could be blocking access.
- B. The traffic on the TCP port 6658 is congested due to the fact that this port is also used by the IPsec keep-alive packets of the SD-WAN solution.
- C. The Aruba-user-role received by the IAP is filtering the TCP port 6658 to the ClearPass servers and after 10 seconds the SSL fallback gets activated and randomly generates the issue.
- D. The ClearPass Policy Manager zones have been defined but the local IP sub-nets have not been property mapped to the zones and the OnGuard Agent might connect to any of the servers in the cluster.
Answer: C
NEW QUESTION 18
You have recently implemented a serf-registration portal in ClearPass Guest to be used on a Guest SSID broadcast from an Aruba controller. Your customer has started complaining that the users are not able to reliably access the internet after clicking the login button on the receipt page. They tell you that the users willclick the login button multiple times and alter about a minute they gain access.
What could be causing this issue?
- A. The guest users are assigned a firewall user role that has a rate limit.
- B. The self-registration page is configured with a 1 minute login delay.
- C. The enforcement profile on ClearPass is set up with an lETF:session delay.
- D. The guest client is delayed getting an IP address from the DHCP server.
Answer: B
NEW QUESTION 19
A customer has created a Guest Sett-Registration page that they would like to use it as'template'for all the new pages that are going to be created from now on. Their goal is to ensure that the header and footer on every page are the same, and any edits made to them are automatically reflected on every Self-Registration Page.
What should be configured in order to accomplish this request?
- A. Save the "template" page as Master Self-Registration page
- B. Create child pages when creating new Self-Registration pages and select the "template" as Parent
- C. Save this "template" page as a new Skin to be used on other Self-Registration pages
- D. Copy the "template" page and edit it each time a new Self-Registration Page is needed
Answer: C
NEW QUESTION 20
Refer to the exhibit:



After the helpdesk revoked the certificate of a device reported to be lost oy an employee, the lost device was seen as connected successfully to the secure network. Further testing has shown that device revocation is not working.
What steps should you follow to make device revocations work?
- A. copy the default [EAP-TLS with OSCP Enabled] authentication method and set the verify certificate using OSCP: option as "required" then configure the correct OSCF URL link for the OnBoard CA.
Remove EAP-TLS and map the new [EAP-TLS with OSCP Enabled] method to the 802 1X Radius Service. - B. Remove the EAP-TLS authentication method configuration changes are required and add "EAP-TLS with OCSP Enabled" authentication method in the OnBoard Provisioning service.
No other configuration changes are required. - C. Edit the default [EAP-TLS with OSCP Enabled] authentication method and set the Verify certificate using OSCP option as required then update the correct OSCP URL link of the OnBoard CA Remove EAP-TLS and map the new [EAP-TLS with OSCP Enabled] method to the OnBoard Provisioning Service.
- D. Copy the default [EAP-TLS with OSCP Enabled] authentication method and set The Verify certificate using OSCP option as required then update the correct OSCP URL link of the OnBoard CA. Remove EAP-TLS and map the custom created method to the OnBoard Authorization Service.
Answer: B
NEW QUESTION 21
A customer is looking to implement a Web-Based Health Check solution with the following requirements:
* for the HR user's client devices, check if a USB stick is mounted.
* for the R&D user's client devices, check if the hard disk is fully encrypted.
The Web-Based Health Check service has been configured but the customer it is not sure how to design the Profile Policy How can be accomplished this customer request?
- A. create two Posture Policies and customize the OnGuard Agent (Persistent or Dissolvable) to select the correct SHV checks
- B. create two Posture Policies and use the Restrict by Roles option to filter for HR and R&D user roles and apply the correct SHV checks
- C. create one Posture Policy and define Rules Conditions that will apply different Tokens for each SHV check condition
- D. create one Posture Policy to check the HR users client devices and use the NAP Agent to check R&D users client devices
Answer: A
NEW QUESTION 22
Refer to the exhibit:
You have configured Onboard but me customer could not onboard one of his devices and has sent you the above screenshots. How could you resolve the issue?
- A. Instruct the user to delete the profile on one of their other BYOD devices.
- B. Increase the maximum number ofdevices that all users can provision to 3.
- C. Increase the maximum number ofdevices allowed by the individual user account.
- D. Instruct the user to run the Quick connect application in Sponsor Mode.
Answer: B
NEW QUESTION 23
Refer to the exhibit:
A customer has configured Onboard and Windows devices workas expected but cannot get the Apple iOS devices to Onboard successfully. Where would you look to troubleshoot the Issued (Select two)
- A. Check if the customer has Instated a custom HTTPS certificate for IDS and another internal PKl HTTPS certificate for other devices.
- B. Check if the ClearPass HTTPS server certificate installed in the server is issued by a trusted commercial certificate authority.
- C. Check if the customer installed the internal PKl Root certificate presented by the ClearPass during the provisioning process.
- D. Check if the customer has installed the sameinternal PKl signed RADIUS server certificate as the HTTPS server certificate.
- E. Check if a DNS entryis available for the ClearPass hostname in the certificate, resolvable from the DNS server assigned to the client.
Answer: B,E
NEW QUESTION 24
Refer to the exhibit:

You configuring an 802 1x service endpoint profiling. When the client connects to the network, ClearPass successfully profiles the client and sends Radius Change of Authorization (RCoA) but Radius Change of Authorization {RCoA) fails for the client You manually clicked on the Change Status button in the access tracker to force an RCoA but that failed too.
What must you check to ensure that the RCoA will work? (Select two.)
- A. RFC 3576 option is enabled for Aruba Controller under Network devicein ClearPass.
- B. The RFC 3576 shared secret on ClearPass should match the Authentication Server shared secret
- C. RFC 3576 server IPs and the Authentication server IPs should be same in the AAA profile
- D. RFC 3576 server should be mapped in the server group on the Aruba Controller
Answer: A,B
NEW QUESTION 25
You are deploying ClearPass Policy Manager with Guest functionality for a customer withmultiple Aruba Networks Mobility Controllers The customer wants to avoid SSL errors during guest access but due to company security policy cannot use a wildcard certificate on ClearPass or the Controllers.
What is the most efficient way to configure the customers guest solution? (Select two.)
- A. Install multiple public certificates with a different Common Name on each controller
- B. Install the same public certificate on all Controllers with the common name "controller {company domain}"
- C. Build one Web Login page with vendor settings for controller {company domain)
- D. Build multiple Web Login pages with vendor settings configured for each controller
Answer: B,D
NEW QUESTION 26
Where is the following information stored in ClearPass?
- Roles and Posture for Connected Clients - System Health for OnGuard - Machine authentication State - CoA session info - Mapping of connected clients to NAS/NAD
- A. insight database
- B. Endpoint database
- C. ClearPass system cache
- D. Multi-Master cache
Answer: C
NEW QUESTION 27
A customer has completed all the required configurations in the Windows server in order for Active Directory Certificate Services (ADCS) to sign Onboard device TLS certificates. The Onboard portal and the Onboard services are also configured. Testing shows that the Client certificates ate still signed by the Onboard Certificate Authority and not ADCS.
How can you help the customer with the situation?
- A. Configure
the identity certificate signer as Active Directory Certificate Services and enter the ADCS URL
http://ADCSVVeoEnrollmentServemostname/certsrv in the OnBoard Provisioning settings. - B. Enable access to SCEP servers from the Certificate Authority to make ClearPass Onboard to use of the Active Directory Certificate Services (ADCS) web enrollment to sign the device TLS certificates.
- C. Educate the customer that, when integrating with Active Directory Certificate Services (ADCS) the Onboard CA will the same authority used for signing me final TLS certificate of the device.
- D. Enable access to EST servers from the Certificate Authority to make ClearPass Onboard to use of the Active Directory Certificate Services (ADCS) web enrollment to sign the device TLS certificates.
Answer: D
NEW QUESTION 28
Refer to the Exhibit:

A customer wants to integrate posture validationinto an Aruba Wireless 802.1X authentication service During testing, the client connects to the Aruba Employee Secure SSID and is redirected to the Captive Portal page where the user can download the OnGuard Agent After the Agent is installed, the client receives the Healthy token the client remains connected to the Captive Portal page ClearPass is assigning the endpoint the following roles: T2-Staff-User. (Machine Authenticated! and T2-SOL-Device.
What could cause this behavior?
- A. The Enforcement Policy conditions for rule 1 are not configured correctly.
- B. The Enforcement Profile should bounce the connection instead of a Terminate session
- C. Used Cached Results: has not been enabled In the Aruba 802.1X Wireless Service
- D. RFC-3576 Is not configured correctly on the Aruba Controller and does not update the role.
Answer: C
NEW QUESTION 29
What type of EAP certificate are you able to use on ClearPass? (Select two.)
- A. Self signed, when all the clients are part of the organization domain.
- B. Private signed, when some clients are onboarded and some are not part of the organization.
- C. Self signed, when all the clients are Onboarded with the same Root CA as the Self signed certificate.
- D. Public signed, when not all of the clients are part of the organization domain.
- E. Private signed, when the clients are onboarded or are part of the organization domain.
Answer: B,D
NEW QUESTION 30
A customer has deployed an OnGuard Solution to all the corporate devices using a group policy rule to push the OnGuard Agents. The network administrator is complaining that some of the agents are communicating to the ClearPass server that is located in a DMZ, outside the firewall The network administrator wants all of the agents System Health Validation traffic to stay inside the Management subnets.
What can the ClearPass administrator do to move the traffic only to the ClearPass Management Ports?
- A. Filter TCP port 6658 on the firewall, forcing the OnGuard agent to use the ClearPass Management port.
- B. Edit the agent.conf file being deployed to the clients to use the ClearPass Management Port for SHV updates.
- C. Configure a Policy Manager Zone mapping so the OnGuard agent will use the Management Port IP.
- D. Select the correct OnGuard Agent installer, and use the one configured for Management Port for the clients.
Answer: C
NEW QUESTION 31
Refer to the exhibit:



What could be causing the error message received on the OnGuard client?
- A. The client'sOnGuardAgent has not been configured with the correct Policy Manager Zone
- B. The Web-BasedHealth Check service needs to be configured to use the Posture Policy
- C. There is a firewall policy not allowing the OnGuard Agent to connect to ClearPass
- D. The Service Selection Rules for the service are not configured correctly
Answer: A
NEW QUESTION 32
Refer to the exhibit:
A customer has just configured a Posture Policy and the T2-Healthcheck Service. Next they installed the OnGuard Agent on Secure_Employee SSID. When they check Access Tracker they see many WEBAUTH requests are being triggered.
What could be the reason?
- A. TCP port 6658 is not allowed between the client and the ClearPass server
- B. The OnGuard Agent trigger the events based on changing the Health Status
- C. OnGuard Web-Based Health Check interval has been wrongly configured to three minutes.
- D. The OnGuard Agent is connecting to the Data Port interface on ClearPass
Answer: C
NEW QUESTION 33
Refer to the exhibit:
When creating a new report, there is an option to send report Notifications by Email. Where is the email server configured?
- A. In the insight report on the next screen of the report definition.
- B. In the ClearPass Policy Manager Messaging setup under Administration.
- C. In the Insight Reports Interface under Administration on the sidebar menu.
- D. In the ClearPass Policy Manager Endpoint Context servers under Administration.
Answer: C
NEW QUESTION 34
Refer to the exhibit:

A customer has configured a Guest Self registration page for their Cisco Wireless network with the settings shown. What should be changed in order to successfully authenticate guests users?
- A. Login Method should be Controller-initiated - using HTTPs form submit
- B. Change the Vendor Settings to Airespace Networks
- C. Change \he IP Address to the Cisco Controller DNS name
- D. Secure Login should use HTTP
Answer: C
NEW QUESTION 35
Refer to the exhibit:



Your company has a postgres SQL database with the MAC addresses of the company-owned tablets You have configured a role mapping condition to tag the SQL devices. When one of the tablets connects to the network, it does not get the correct role and receives a deny access profile.
How would you resolve the issue?
- A. Enable authorization tab in the service and add the SQL server as an authorization source.
- B. Add the SQL server as an authentication source and map .t under the authentication tab in the service.
- C. Remove SQL condition from role mapping policy and add it under the enforcement policy conditions.
- D. Edit the SQL authentication source niter attributes and modify the SQL server filter query.
Answer: D
NEW QUESTION 36
A customer is planning to implement machine and user authentication on infrastructure with one Aruba Controller and a single ClearPass Server What should the customer consider while designing this solution?
(Select three.)
- A. The Windows User must log off, restart or disconnect their machine to initiate a machine authentication before the cache expires.
- B. The customer does not need to worry about Multi-Master Cache Survivability because the Controller will also cache the machine state.
- C. The machine authentication status is written in the Multi-master cache on the ClearPass Server for 24 hrs.
- D. The Customer should enable Multi-Master Cache Survivability as the Aruba Controller will not cache the machine state.
- E. Machine Authentication only uses EAP TLS, as such a PKI infrastructure should be in place for machine authentication.
- F. Onboard must be used to install the Certificates on the personal devices to do the user and machine authentication.
Answer: C,E,F
NEW QUESTION 37
......
HPE6-A77 Dumps for Aruba Certified ClearPass Expert (ACCX) Certified Exam Questions & Answer: https://www.testkingpass.com/HPE6-A77-testking-dumps.html