100% Real HPE6-A78 dumps - Brilliant HPE6-A78 Exam Questions PDF
HPE6-A78 Exam PDF [2022] Tests Free Updated Today with Correct 62 Questions
HP HPE6-A78 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
NEW QUESTION 25
What is one way that WPA3-PerSonal enhances security when compared to WPA2-Personal?
- A. WPA3-Personai is more resistant to passphrase cracking Because it requires passphrases to be at least 12 characters
- B. WPA3-Personal is more complicated to deploy because it requires a backend authentication server
- C. WPA3-Perscn3i is more secure against password leaking Because all users nave their own username and password
- D. WPA3-Personai prevents eavesdropping on other users' wireless traffic by a user who knows the passphrase for the WLAN.
Answer: C
NEW QUESTION 26
What is a benefit or using network aliases in ArubaOS firewall policies?
- A. You can adjust the IP addresses in the aliases, and the rules using those aliases automatically update
- B. You can use the aliases to conceal the true IP addresses of servers from potentially untrusted clients.
- C. You can associate a reputation score with the network alias to create rules that filler traffic based on reputation rather than IP.
- D. You can use the aliases to translate client IP addresses to other IP addresses on the other side of the firewall
Answer: C
NEW QUESTION 27
What is a vulnerability of an unauthenticated Dime-Heliman exchange?
- A. A hacker can replace the public values exchanged by the legitimate peers and launch an MITM attack.
- B. Participants must agree on a passphrase in advance, which can limit the usefulness of Diffie- Hell man in practical contexts.
- C. A brute force attack can relatively quickly derive Diffie-Hellman private values if they are able to obtain public values
- D. Diffie-Hellman with elliptic curve values is no longer considered secure in modem networks, based on NIST recommendations.
Answer: A
NEW QUESTION 28
What is one way a noneypot can be used to launch a man-in-the-middle (MITM) attack to wireless clients?
- A. it uses ARP poisoning to disconnect wireless clients from the legitimate wireless network and force clients to connect to the hacker's wireless network instead.
- B. it uses a combination or software and hardware to jam the RF band and prevent the client from connecting to any wireless networks
- C. it examines wireless clients' probes and broadcasts the SSlDs in the probes, so that wireless clients will connect to it automatically.
- D. it runs an NMap scan on the wireless client to And the clients MAC and IP address. The hacker then connects to another network and spoofs those addresses.
Answer: A
NEW QUESTION 29
A company is deploying ArubaOS-CX switches to support 135 employees, which will tunnel client traffic to an Aruba Mobility Controller (MC) for the MC to apply firewall policies and deep packet inspection (DPI).
This MC will be dedicated to receiving traffic from the ArubaOS-CX switches.
What are the licensing requirements for the MC?
- A. one PEF license per-switch. and one WCC license per-switch
- B. one AP license per-switch
- C. one AP license per-switch. and one PEF license per-switch
- D. one PEF license per-switch
Answer: C
NEW QUESTION 30
How should admins deal with vulnerabilities that they find in their systems?
- A. They should classify the vulnerability as malware. a DoS attack or a phishing attack.
- B. They should notify the security team as soon as possible that the network has already been breached.
- C. They should add the vulnerability to their Common Vulnerabilities and Exposures (CVE).
- D. They should apply fixes, such as patches, to close the vulnerability before a hacker exploits it.
Answer: D
NEW QUESTION 31
You have been asked to rind logs related to port authentication on an ArubaOS-CX switch for events logged in the past several hours But. you are having trouble searching through the logs What is one approach that you can take to find the relevant logs?
- A. Specify a logging facility that selects for "port-access" messages.
- B. Add the "-C and *-c port-access" options to the "show logging" command.
- C. Configure a logging Tiller for the "port-access" category, and apply that filter globally.
- D. Enable debugging for "portaccess" to move the relevant logs to a buffer.
Answer: B
NEW QUESTION 32
What are some functions of an AruDaOS user role?
- A. The role determines which firewall policies and bandwidth contract apply to the clients traffic
- B. The role determines which wireless networks (SSiDs) a user is permitted to access
- C. The role determines which authentication methods the user must pass to gain network access
- D. The role determines which control plane ACL rules apply to the client's traffic
Answer: C
NEW QUESTION 33
You need to deploy an Aruba instant AP where users can physically reach It. What are two recommended options for enhancing security for management access to the AP? (Select two )
- A. Place a Tamper Evident Label (TELS) over its console port
- B. install a CA-signed certificate
- C. Configure WPA3-Enterpnse security on the AP
- D. Disable the Web Ul.
- E. Disable Its console ports
Answer: A,B
NEW QUESTION 34
Refer to the exhibit.
You have set up a RADIUS server on an ArubaOS Mobility Controller (MC) when you created a WLAN named "MyEmployees .You now want to enable the MC to accept change of authorization (CoA) messages from this server for wireless sessions on this WLAN.
What Is a part of the setup on the MC?
- A. Create a dynamic authorization, or RFC 3576, server with the 10.5.5.5 address and correct shared secret.
- B. Configure a ClearPass username and password in the MyEmployees AAA profile.
- C. Install the root CA associated with the 10 5.5.5 server's certificate as a Trusted CA certificate.
- D. Enable the dynamic authorization setting in the "clearpass" authentication server settings.
Answer: C
NEW QUESTION 35
Refer to the exhibit.
This company has ArubaOS-Switches. The exhibit shows one access layer switch, Swllcn-2. as an example, but the campus actually has more switches. The company wants to slop any internal users from exploiting ARP What Is the proper way to configure the switches to meet these requirements?
- A. On Swltch-2, configure static PP-to-MAC bindings for all end-user devices on the network
- B. On Swltch-2, enable DHCP snooping globally and on VLAN 201 before enabling ARP protection
- C. On Switch-1, enable ARP protection globally, and enable ARP protection on ail VLANs.
- D. On Switch-2, make ports connected to employee devices trusted ports for ARP protection
Answer: A
NEW QUESTION 36
What is one practice that can help you to maintain a digital chain or custody In your network?
- A. Enable packet capturing on Instant AP or Mobility Controller (MC) control path on an ongoing basis.
- B. Enable packet capturing on Instant AP or Moodily Controller (MC) datepath on an ongoing basis
- C. Ensure that all network infrastructure devices receive a valid clock using authenticated NTP
- D. Ensure that all network Infrastructure devices use RADIUS rather than TACACS+ to authenticate managers
Answer: B
NEW QUESTION 37
From which solution can ClearPass Policy Manager (CPPM) receive detailed information about client device type OS and status?
- A. ClearPass OnGuard
- B. ClearPass Guest
- C. ClearPass Access Tracker
- D. ClearPass Onboard
Answer: A
NEW QUESTION 38
Refer to the exhibit.
How can you use the thumbprint?
- A. Copy the thumbprint to other Aruba switches to establish a consistent SSH Key for all switches this will enable managers to connect to the switches securely with less effort
- B. When you first connect to the switch with SSH from a management station, make sure that the thumbprint matches to ensure that a man-in-t he-mid die (MITM) attack is not occurring
- C. Install this thumbprint on management stations to use as two-factor authentication along with manager usernames and passwords, this will ensure managers connect from valid stations
- D. install this thumbprint on management stations the stations can then authenticate with the thumbprint instead of admins having to enter usernames and passwords.
Answer: B
NEW QUESTION 39
You are troubleshooting an authentication issue for Aruba switches that enforce 802 IX10 a cluster of Aruba ClearPass Policy Manager (CPPMs) You know that CPPM Is receiving and processing the authentication requests because the Aruba switches are showing Access-Rejects in their statistics However, you cannot find the record tor the Access-Rejects in CPPM Access Tracker What is something you can do to look for the records?
- A. Click Edit in Access viewer and make sure that the correct servers are selected.
- B. Make sure that CPPM cluster settings are configured to show Access-Rejects
- C. Go to the CPPM Event Viewer, because this is where RADIUS Access Rejects are stored.
- D. Verify that you are logged in to the CPPM Ul with read-write, not read-only, access
Answer: B
NEW QUESTION 40
What is a guideline for managing local certificates on an ArubaOS-Switch?
- A. Install an Online Certificate Status Protocol (OCSP) certificate to simplify the process of enrolling and re-enrolling for certificate
- B. Generate the certificate signing request (CSR) with a program offline, then, install both the certificate and the private key on the switch in a single file.
- C. Create a self-signed certificate online on the switch because ArubaOS-Switches do not support CA-signed certificates.
- D. Before installing the local certificate, create a trust anchor (TA) profile with the root CA certificate for the certificate that you will install
Answer: B
NEW QUESTION 41
You have deployed a new Aruba Mobility Controller (MC) and campus APs (CAPs). One of the WLANs enforces 802.IX authentication lo Aruba ClearPass Policy Manager {CPPM) When you test connecting the client to the WLAN. the test falls You check Aruba ClearPass Access Tracker and cannot find a record of the authentication attempt You ping from the MC to CPPM. and the ping is successful.
What is a good next step for troubleshooting?
- A. Check connectivity between CPPM and a backend directory server
- B. Reset the user credentials
- C. Check CPPM Event viewer.
- D. Renew CPPM's RADIUS/EAP certificate
Answer: C
NEW QUESTION 42
You have detected a Rogue AP using the Security Dashboard Which two actions should you take in responding to this event? (Select two)
- A. There is no need to locale the AP If you manually contain It.
- B. You should receive permission before containing an AP. as this action could have legal Implications.
- C. There is no need to locate the AP If the Aruba solution is properly configured to automatically contain it.
- D. This is a serious security event, so you should always contain the AP immediately regardless of your company's specific policies.
- E. For forensic purposes, you should copy out logs with relevant information, such as the time mat the AP was detected and the AP's MAC address.
Answer: D,E
NEW QUESTION 43
What is an Authorized client as defined by ArubaOS Wireless Intrusion Prevention System (WIP)?
- A. a client that has a certificate issued by a trusted Certification Authority (CA)
- B. a client that is on the WIP whitelist.
- C. a client that is not on the WIP blacklist
- D. a client that has successfully authenticated to an authorized AP and passed encrypted traffic
Answer: D
NEW QUESTION 44
What is a benefit of deploying Aruba ClearPass Device insight?
- A. Agent-based analysts of devices' security settings and health status, with the ability to implement quarantining
- B. visibility into devices' 802.1X supplicant settings and automated certificate deployment
- C. Highly accurate endpoint classification for environments with many devices types, including Internet of Things (loT)
- D. Simpler troubleshooting of ClearPass solutions across an environment with multiple ClearPass Policy Managers
Answer: B
NEW QUESTION 45
What role does the Aruba ClearPass Device Insight Analyzer play in the Device Insight architecture?
- A. It resides in the cloud and manages licensing and configuration for Collectors
- B. It resides on-prem and is responsible for running active SNMP and Nmap scans
- C. It resides In the cloud and applies machine learning and supervised crowdsourcing to metadata sent by Collectors
- D. It resides on-prem and provides the span port to which traffic is mirrored for deep analytics.
Answer: C
NEW QUESTION 46
What is symmetric encryption?
- A. It any form of encryption mat ensures that thee ciphertext Is the same length as the plaintext.
- B. It uses a Key that is double the size of the message which it encrypts.
- C. It uses the same key to encrypt plaintext as to decrypt ciphertext.
- D. It simultaneously creates ciphertext and a same-size MAC.
Answer: C
NEW QUESTION 47
Refer to the exhibit.
You need to ensure that only management stations in subnet 192.168.1.0/24 can access the ArubaOS-Switches' CLI. Web Ul. and REST interfaces The company also wants to let managers use these stations to access other parts of the network What should you do?
- A. Specify 192.168.1.0.255.255.255.0 as authorized IP manager address
- B. Specify vlan 100 as the management vlan for the switches.
- C. Establish a Control Plane Policing class that selects traffic from 192.168 1.0/24.
- D. Configure the switch to listen for these protocols on OOBM only.
Answer: C
NEW QUESTION 48
What is an example or phishing?
- A. An attacker sends TCP messages to many different ports to discover which ports are open.
- B. An attacker checks a user's password by using trying millions of potential passwords.
- C. An attacker lures clients to connect to a software-based AP that is using a legitimate SSID.
- D. An attacker sends emails posing as a service team member to get users to disclose their passwords.
Answer: D
NEW QUESTION 49
......
Verified & Correct HPE6-A78 Practice Test Reliable Source Oct 20, 2022 Updated: https://crucialexams.lead1pass.com/HP/HPE6-A78-practice-exam-dumps.html