[May-2024] Use Real HPE6-A78 Dumps - 100% Free HPE6-A78 Exam Dumps [Q16-Q37]

Share

[May-2024] Use Real HPE6-A78 Dumps - 100% Free HPE6-A78 Exam Dumps

HPE6-A78 PDF Dumps Exam Questions – Valid HPE6-A78 Dumps

NEW QUESTION # 16
What is a guideline for managing local certificates on an ArubaOS-Switch?

  • A. Install an Online Certificate Status Protocol (OCSP) certificate to simplify the process of enrolling and re-enrolling for certificate
  • B. Generate the certificate signing request (CSR) with a program offline, then, install both the certificate and the private key on the switch in a single file.
  • C. Before installing the local certificate, create a trust anchor (TA) profile with the root CA certificate for the certificate that you will install
  • D. Create a self-signed certificate online on the switch because ArubaOS-Switches do not support CA-signed certificates.

Answer: B


NEW QUESTION # 17
What is one of the roles of the network access server (NAS) in the AAA framewonx?

  • A. It determines which resources authenticated users are allowed to access and monitors each users session
  • B. It authenticates legitimate users and uses policies to determine which resources each user is allowed to access.
  • C. It negotiates with each user's device to determine which EAP method is used for authentication
  • D. It enforces access to network services and sends accounting information to the AAA server

Answer: B


NEW QUESTION # 18
What is symmetric encryption?

  • A. It uses a Key that is double the size of the message which it encrypts.
  • B. It any form of encryption mat ensures that thee ciphertext Is the same length as the plaintext.
  • C. It uses the same key to encrypt plaintext as to decrypt ciphertext.
  • D. It simultaneously creates ciphertext and a same-size MAC.

Answer: C


NEW QUESTION # 19
From which solution can ClearPass Policy Manager (CPPM) receive detailed information about client device type OS and status?

  • A. ClearPass Guest
  • B. ClearPass Onboard
  • C. ClearPass OnGuard
  • D. ClearPass Access Tracker

Answer: C


NEW QUESTION # 20
What is a use case for tunneling traffic between an Aruba switch and an AruDa Mobility Controller (MC)?

  • A. securing the network infrastructure control plane by creating a virtual out-of-band-management network
  • B. simplifying network infrastructure management by using the MC to push configurations to the switches
  • C. enhancing the security of communications from the access layer to the core with data encryption
  • D. applying firewall policies and deep packet inspection to wired clients

Answer: D


NEW QUESTION # 21
What is an example or phishing?

  • A. An attacker sends TCP messages to many different ports to discover which ports are open.
  • B. An attacker checks a user's password by using trying millions of potential passwords.
  • C. An attacker lures clients to connect to a software-based AP that is using a legitimate SSID.
  • D. An attacker sends emails posing as a service team member to get users to disclose their passwords.

Answer: D


NEW QUESTION # 22
Refer to the exhibit.

A diem is connected to an ArubaOS Mobility Controller. The exhibit snows all Tour firewall rules that apply to this diem What correctly describes how the controller treats HTTPS packets to these two IP addresses, both of which are on the other side of the firewall
10.1 10.10
203.0.13.5

  • A. it permits both of the packets
  • B. It drops the packet to 10.1.10.10 and permits the packet to 203.0.13.5.
  • C. It drops both of the packets
  • D. It permits the packet to 10.1.10.10 and drops the packet to 203 0.13.5

Answer: A


NEW QUESTION # 23
An ArubaOS-CX switch enforces 802.1X on a port. No fan-through options or port-access roles are configured on the port The 802 1X supplicant on a connected client has not yet completed authentication Which type of traffic does the authenticator accept from the client?

  • A. DHCP, DNS and RADIUS only
  • B. EAP only
  • C. RADIUS only
  • D. DHCP, DNS, and EAP only

Answer: B


NEW QUESTION # 24
Refer to the exhibit.

You have set up a RADIUS server on an ArubaOS Mobility Controller (MC) when you created a WLAN named "MyEmployees .You now want to enable the MC to accept change of authorization (CoA) messages from this server for wireless sessions on this WLAN.
What Is a part of the setup on the MC?

  • A. Install the root CA associated with the 10 5.5.5 server's certificate as a Trusted CA certificate.
  • B. Configure a ClearPass username and password in the MyEmployees AAA profile.
  • C. Create a dynamic authorization, or RFC 3576, server with the 10.5.5.5 address and correct shared secret.
  • D. Enable the dynamic authorization setting in the "clearpass" authentication server settings.

Answer: A


NEW QUESTION # 25
Which correctly describes a way to deploy certificates to end-user devices?

  • A. ClearPass OnGuard can help to deploy certificates to end-user devices, whether or not they are members of a Windows domain
  • B. in a Windows domain, domain group policy objects (GPOs) can automatically install computer, but not user certificates
  • C. ClearPass Onboard can help to deploy certificates to end-user devices, whether or not they are members of a Windows domain
  • D. ClearPass Device Insight can automatically discover end-user devices and deploy the proper certificates to them

Answer: C


NEW QUESTION # 26
What is a benefit or Protected Management Frames (PMF). sometimes called Management Frame Protection (MFP)?

  • A. PMF helps to protect APs and MCs from unauthorized management access by hackers.
  • B. PMF prevents hackers from capturing the traffic between APs and Mobility Controllers.
  • C. PMF ensures trial traffic between APs and Mobility Controllers (MCs) is encrypted.
  • D. PMF protects clients from DoS attacks based on forged de-authentication frames

Answer: A


NEW QUESTION # 27
What is a benefit or using network aliases in ArubaOS firewall policies?

  • A. You can use the aliases to conceal the true IP addresses of servers from potentially untrusted clients.
  • B. You can adjust the IP addresses in the aliases, and the rules using those aliases automatically update
  • C. You can associate a reputation score with the network alias to create rules that filler traffic based on reputation rather than IP.
  • D. You can use the aliases to translate client IP addresses to other IP addresses on the other side of the firewall

Answer: C


NEW QUESTION # 28
What is a benefit of deploying Aruba ClearPass Device insight?

  • A. visibility into devices' 802.1X supplicant settings and automated certificate deployment
  • B. Highly accurate endpoint classification for environments with many devices types, including Internet of Things (loT)
  • C. Agent-based analysts of devices' security settings and health status, with the ability to implement quarantining
  • D. Simpler troubleshooting of ClearPass solutions across an environment with multiple ClearPass Policy Managers

Answer: A


NEW QUESTION # 29
What are some functions of an AruDaOS user role?

  • A. The role determines which authentication methods the user must pass to gain network access
  • B. The role determines which wireless networks (SSiDs) a user is permitted to access
  • C. The role determines which control plane ACL rules apply to the client's traffic
  • D. The role determines which firewall policies and bandwidth contract apply to the clients traffic

Answer: A


NEW QUESTION # 30
What is a reason to set up a packet capture on an Aruba Mobility Controller (MC)?

  • A. You want the MC to analyze wireless clients' traffic at a lower level, so that the ArubaOS firewall can control the traffic I based on application.
  • B. You want the MC to analyze wireless clients' traffic at a lower level, so that the ArubaOS firewall can control Web traffic based on the destination URL.
  • C. The company wants to use ClearPass Policy Manager (CPPM) to profile devices and needs to receive HTTP User-Agent strings from the MC.
  • D. The security team believes that a wireless endpoint connected to the MC is launching an attack and wants to examine the traffic more closely.

Answer: A


NEW QUESTION # 31
Refer to the exhibit.

Device A is establishing an HTTPS session with the Arubapedia web sue using Chrome. The Arubapedia web server sends the certificate shown in the exhibit What does the browser do as part of vacating the web server certificate?

  • A. It uses the private key in the DigiCert SHA2 Secure Server CA to check the certificate's signature.
  • B. It uses the private key in the Arubapedia web site's certificate to check that certificate's signature
  • C. It uses the public key in the DigCert root CA certificate to check the certificate signature
  • D. It uses the public key in the DigCen SHA2 Secure Server CA certificate to check the certificate's signature.

Answer: D


NEW QUESTION # 32
What is one difference between EAP-Tunneled Layer security (EAP-TLS) and Protected EAP (PEAP)?

  • A. EAP-TLS begins with the establishment of a TLS tunnel, but PEAP does not use a TLS tunnel as part of Its process
  • B. EAP-TLS requires the supplicant to authenticate with a certificate, hut PEAP allows the supplicant to use a username and password.
  • C. EAP-TLS creates a TLS tunnel for transmitting user credentials, while PEAP authenticates the server and supplicant during a TLS handshake.
  • D. EAP-TLS creates a TLS tunnel for transmitting user credentials securely while PEAP protects user credentials with TKIP encryption.

Answer: B


NEW QUESTION # 33
You need to deploy an Aruba instant AP where users can physically reach It. What are two recommended options for enhancing security for management access to the AP? (Select two )

  • A. Disable Its console ports
  • B. Disable the Web Ul.
  • C. Place a Tamper Evident Label (TELS) over its console port
  • D. Configure WPA3-Enterpnse security on the AP
  • E. install a CA-signed certificate

Answer: C,E


NEW QUESTION # 34
A company has an ArubaOS controller-based solution with a WPA3-Enterprise WLAN. which authenticates wireless clients to Aruba ClearPass Policy Manager (CPPM). The company has decided to use digital certificates for authentication A user's Windows domain computer has had certificates installed on it However, the Networks and Connections window shows that authentication has tailed for the user. The Mobility Controllers (MC's) RADIUS events show that it is receiving Access-Rejects for the authentication attempt.
What is one place that you can you look for deeper insight into why this authentication attempt is failing?

  • A. the RADIUS events within the CPPM Event Viewer
  • B. the reports generated by Aruba ClearPass Insight
  • C. the Alerts tab in the authentication record in CPPM Access Tracker
  • D. the packets captured on the MC control plane destined to UDP 1812

Answer: C


NEW QUESTION # 35
What are the roles of 802.1X authenticators and authentication servers?

  • A. The authenticator stores the user account database, while the server stores access policies.
  • B. The authenticator is a RADIUS client and the authentication server is a RADIUS server.
  • C. The authenticator supports only EAP, while the authentication server supports only RADIUS.
  • D. The authenticator makes access decisions and the server communicates them to the supplicant.

Answer: D


NEW QUESTION # 36
Which attack is an example or social engineering?

  • A. An attack exploits an operating system vulnerability and locks out users until they pay the ransom.
  • B. A user visits a website and downloads a file that contains a worm, which sell-replicates throughout the network.
  • C. A hacker eavesdrops on insecure communications, such as Remote Desktop Program (RDP). and discovers login credentials.
  • D. An email Is used to impersonate a Dank and trick users into entering their bank login information on a fake website page.

Answer: D


NEW QUESTION # 37
......

Ultimate HPE6-A78 Guide to Prepare Free Latest HP Practice Tests Dumps: https://www.practicematerial.com/HPE6-A78-exam-materials.html

Get Top-Rated HP HPE6-A78 Exam Dumps Now: https://drive.google.com/open?id=19ur4jR075b3OW9l3eN2nbJkT4LoqHalZ