HPE6-A47 Exam QuestionsBrowse all questions from this exam

HPE6-A47 Exam - Question 18


Scenario:

An architect proposes these products for a customer who wants a wireless and wired upgrade:

✑ Aruba 2930M switches at the access layer

✑ Aruba 5406R switches at the core

✑ Aruba AP-325s

✑ Aruba 7205 Mobility Controllers (MCs), deployed in a cluster

✑ Aruba Mobility Master (MM)

✑ Aruba ClearPass Cx000V

✑ Aruba AirWare

The architect also needs to propose a security plan for the solution. The customer has 900 employees and up to 30 guests a day. The customer wants to protect the internal perimeter of the network with authentication and simple access controls. The customer is most concerned about wireless security, but also wants to ensure that only trusted users connect on the wire. However, the customer also wants all wired traffic to be forwarded locally on access layer switches. The customer already has a third-party firewall that protects the data center.

The customer wants to use certificates to authenticate user devices, but is concerned about the complexity of deploying the solution. The architect should recommend a way to simplify. For the most part users connect company-issued laptops to the network. However, users can bring their own devices and connect them to the network. The customer does not know how many devices each user will connect, but expects about two or three per-user. DHCP logs indicate that the network supports a maximum of 2800 devices.

Refer to the provided scenario.

Which solution should the architect recommend on the 2930M switches to authenticate and control wired employee devices?

Show Answer
Correct Answer: AC

To authenticate and control wired employee devices on the 2930M switches, 802.1X on edge ports without tunneled node should be used. The customer wants to use certificates for authenticating user devices, which aligns with 802.1X authentication. Additionally, the customer wants all wired traffic to be forwarded locally on access layer switches, which means that tunneled node should not be used.

Discussion

6 comments
Sign in to comment
fredexamOption: C
Nov 26, 2020

Answer is C. The customer wants to use certificates to authenticate user devices. No Mac Auth

JeeFOption: C
May 13, 2022

Agree with C: "However, the customer also wants all wired traffic to be forwarded locally on access layer switches" means no tunneled mode "The customer wants to use certificates to authenticate user devices" means 802.1x

split_rumblesOption: C
Jun 30, 2022

Agree. Got to be C

DorcomPSOption: C
Aug 23, 2022

The answer is C - Not tunneled node - that for sure. As it says the wired client should be forward locally. That gives us MAC-auth and 802.1x - since certificate is needed - 802.1x is the chosen one.

mpj_quickOption: C
Sep 25, 2022

C. certificates = 802.1x wired traffic forwarded locally = no tunneled mode

moundirrOption: C
Jul 20, 2023

C is correct