HPE6-A71 Exam QuestionsBrowse all questions from this exam

HPE6-A71 Exam - Question 6


An administrator creates a user role that department A in a company uses. Various other roles exist for other departments. All employees connect to the same

ESSID, which authenticates to an external AAA server.

How should the administrator configure the controller to assign the appropriate roles to the employees?

Show Answer
Correct Answer: D

In this scenario, the administrator needs to assign specific roles to employees based on which department they belong to, even though they all connect to the same ESSID and authenticate via an external AAA server. The appropriate way to achieve this is by implementing server-derived roles. These roles can be assigned dynamically based on attributes returned by the authentication server or client attributes, allowing for the correct role to be assigned to each employee based on the department they are in.

Discussion

8 comments
Sign in to comment
ahmedsororOption: D
Sep 23, 2020

Answer is D

GoMGoMOption: D
Aug 6, 2020

should be D

skilliOption: C
Oct 8, 2020

why D? server-derivation rules are executed after client authentication, i think that C is correct response

dante90
Oct 29, 2020

if I'm not wrong they want to assign a different role for each department, lets asume that they have department B,C,D and E, if you can only use 1 AAA profile per ESSID and only 2 roles per AAA profile (Pre-authentication and Post-Authentication) How would you assign the roles for the other departments if every user is connecting to the same ESSID? For me The only way would be Server-Derivation rules. Please let me know if I am wrong , the porpuse of my comment is to learn. Best Regards.

ZaniOption: D
Nov 24, 2020

Answer should be D

SnakeF0ngOption: D
Nov 30, 2021

Answer should be D. Implement server-derived roles. The user role can be derived from attributes returned by the authentication server and certain client attributes (this is known as a server-derived role). If the client is authenticated via an authentication server, the user role for the client can be based on one or more attributes returned by the server during authentication, or on client attributes such as SSID (even if the attribute is not returned by the server). Server-derivation rules are executed after client authentication.

tdkr147Option: D
Aug 28, 2022

Answer should be D. Implement server-derived roles. The user role can be derived from attributes returned by the authentication server and certain client attributes (this is known as a server-derived role). If the client is authenticated via an authentication server, the user role for the client can be based on one or more attributes returned by the server during authentication, or on client attributes such as SSID (even if the attribute is not returned by the server). Server-derivation rules are executed after client authentication.

cjosephOption: D
Oct 15, 2022

Answer is D, e.g use an external RADIUS server solution such as ClearPass

AgentmagnetOption: D
Apr 11, 2023

D seems to be the right answer