Latest HPE6-A77 Actual Free Exam Questions Updated 60 Questions
Free HPE6-A77 Exam Braindumps certification guide Q&A
HP HPE6-A77 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
NEW QUESTION 30
There is an Aruba Controller configured to send Guest AAA requests to ClearPass. If the customer would like the most effective way to ensure the lowest license usage counts, how should the controller be configured?
- A. Configure EAP Termination on the Aruba Controller and the client will send a stop message.
- B. Aruba Controller will send stop messages only if EAP termination and Interim accounting are enabled.
- C. Aruba Controller will send stop messages only if both accounting and interim accounting are enabled.
- D. Aruba Controller will send stop messages if RADIUS Accounting Server Group is defined in the authentication profile.
Answer: A
NEW QUESTION 31
Refer to the exhibit:


The customer configured an 802.1x service with different enforcement actions for personal and corporate laptops. The corporate laptops are always being redirected to the BYOD Portal. The customer has sent you the above screenshots.
How would you resolve the issue? (Select two)
- A. Remove the EAP-PEAP with [user authenticated] condition for Onboard and create another service
- B. Modify the enforcement policy and change the rule evaluation algorithm to select first match
- C. Modify the enforcement policy and re-order the EAP-PEAP with [user authenticated] rule to the last condition.
- D. Modify the enforcement policy and re-order the condition with Posture - Unknown as the fifth condition
- E. Modify the enforcement policy and re-order the condition with posture not_equals to healthy as the sixth condition
Answer: C,D
NEW QUESTION 32
A Customer has these requirements:
* 2.000 loT endpoints that use MAC authentication
* 6,000 endpoints using a mix of username/password and certificate (Corporate/BYOD) based authentication
* 1,000 guest endpoints at peak usage that use guest self-registration
* 1500 BYOD devices estimated as 3 devices per User (500 users)
* 2,500 endpoints that have OnGuard installed and connect on a daily basis What licenses should be installed to meet customer requirements?
- A. 11,500 Access, 1,500 Onboard, 2.500 Onguard
- B. 9,000 Access, 500 Onboard. 2.500 Onguard
- C. 13.000 Access, 1.500 Onboard, 2,500 Onguard
- D. 11,500 Access, 500 Onboard, 2,500 Onguard
Answer: A
NEW QUESTION 33
What is the Open SSID (otherwise referred to as Dual SSID) Onboard deployment service workflow?
- A. OnBoard Pre-Auth Application service, OnBoard Authorization Application service. OnBoard Provisioning RADIUS service
- B. OnBoard Authorization Application service, OnBoard Pre-Auth Application service, OnBoard Provisioning RADIUS service
- C. OnBoard Authorization RADIUS service, OnBoard Pre-Auth Application service, OnBoard Provisioning RADIUS service
- D. OnBoard Pre-Auth RADIUS service. OnBoard Authorization Application service. OnBoard Provisioning RADIUS service
Answer: B
NEW QUESTION 34
A customer has created a Guest Sett-Registration page that they would like to use it as'template'for all the new pages that are going to be created from now on. Their goal is to ensure that the header and footer on every page are the same, and any edits made to them are automatically reflected on every Self-Registration Page.
What should be configured in order to accomplish this request?
- A. Save this "template" page as a new Skin to be used on other Self-Registration pages
- B. Save the "template" page as Master Self-Registration page
- C. Copy the "template" page and edit it each time a new Self-Registration Page is needed
- D. Create child pages when creating new Self-Registration pages and select the "template" as Parent
Answer: A
NEW QUESTION 35
Refer to the exhibit:
A customer with multiple Aruba Controllers has just installed a new certificate for "*.customerdomain com" on all Aruba Controllers. While testing the existing guest Self-Registration page the customer noticed that the logins are failing. While troubleshooting they are finding no entries in the Event Viewer or Access Tracker for the tests. Suspecting that the Aruba Controllers may not be properly posting the credentials from the guest browser, they open the NAS Vendor Settings for the Guest Self-Registration Page. From the screen shown, how can you fix the errors?
- A. Change the "Secure Login:" field to "Use Vendor Default".
- B. Add PTR records on the DNS server for "securelogin.arubanetworks.com".
- C. Change the "IP Address: field to" securelogin.customerdomain.com.
- D. Change the "IP Address field to "captiveportal-login.customerdomain.com".
Answer: A
NEW QUESTION 36
Refer to the exhibit:
A customer has configured Onboard in a cluster. After the Primary server's failure, the BYOD devices fail to connect to the network. What would you do to troubleshoot?
- A. Reboot the active ClearPass server and reconnect the client to the SSID by selecting the correct certificate when prompted
- B. Check EAP certificate on the secondary node is issued by the same common root Certificate Authority (CA)
- C. Check if a DNS entry is available for the ClearPass hostname in the certificate, resolvable from the DNS server assigned to the client
- D. Verify
the OSCP URL under TLS authentication method is mapped to http://localhost/guestmdps_ocsp.php/2
Answer: A
NEW QUESTION 37
Refer to the exhibit:


You are doing a ClearPass PoC at a customer site with a single Aruba Mobility Controller. The customer asked for a demonstration of a simple Web Login functionality. You used a service template to create the guest services. During testing, the usergets redirected back to the weblogin page with an Authentication failed message. The guest configurations on the Aruba Mobility Controller are configured correctly.
Why would the guest fail to authenticate successfully?
- A. The Unique-Device-Count does not allow any Client devices.Update the Enforcement policy condition:
Unique-Device-Count. - B. The authentication source mapped in the service is incorrect, it should be mapped as (Guest Device Repository] [Local SQL DB].
- C. The username and/or password used for authentication is incorrect Re-enter the correct password on the weblogin page.
- D. The username used for authentication does not exist in the Guest User Database Create a new user and authenticate again.
Answer: B
NEW QUESTION 38
Refer to the exhibit:
What is true about the Insight Master Server? {Select two)
- A. There is no need to configure an insight Master Server when using default reports and alerts.
- B. It Is recommended to have an insight server for every zone to limit the traffic between sites.
- C. The Publisher is selected by default as Insight Master Server but It can be changed.
- D. An insight Master Server should be selectedin order to configure reports and alerts.
- E. When enabling a server to be the insight Master any existing insight Master is overwritten.
Answer: C,D
NEW QUESTION 39
Refer to the exhibit:


The customer created a new enforcement policy condition to allow VIP Users access without additional security compliance checks hut cannot gel it working. The customer has sent you the above screenshots.
How would you resolve the issue?
- A. Include VIP User role along with the Healthy posture enforcement condition.
- B. Modify the Enforcement Policy and re-order the VIPuser condition to the lop.
- C. Set the Enforcement Policy rules evaluation algorithm to evaluate all.
- D. Ask the VIP user to complete the one time webhealthcheck to get the VIP profile.
Answer: A
NEW QUESTION 40
Refer to the exhibit:
The customer complains that the user shown cannot log into the ClearPass Server as an administrator using the
[Policy Manager Admin Network Login Service]. What could be the reason for this?
- A. The local user authentication might be disabled
- B. The account created does not fit this purpose.
- C. The mapping on the role should be changed to [RADIUS Super Admin]
- D. The user might be used for a TACACS authentication
Answer: B
NEW QUESTION 41
Where is the following information stored in ClearPass?
- Roles and Posture for Connected Clients - System Health for OnGuard - Machine authentication State - CoA session info - Mapping of connected clients to NAS/NAD
- A. ClearPass system cache
- B. Multi-Master cache
- C. Endpoint database
- D. insight database
Answer: A
NEW QUESTION 42
You have recently implemented a serf-registration portal in ClearPass Guest to be used on a Guest SSID broadcast from an Aruba controller. Your customer has started complaining that the users are not able to reliably access the internet after clicking the login button on the receipt page. They tell you that the users willclick the login button multiple times and alter about a minute they gain access.
What could be causing this issue?
- A. The guest client is delayed getting an IP address from the DHCP server.
- B. The guest users are assigned a firewall user role that has a rate limit.
- C. The self-registration page is configured with a 1 minute login delay.
- D. The enforcement profile on ClearPass is set up with an lETF:session delay.
Answer: C
NEW QUESTION 43
You have integrated ClearPass Onboard with Active Directory Certificate Services (ADCS) web enrollment to sign the final device TLS certificates. The customer wouldalso like to use ADCS for centralized management of TLS certificates including expiration, revocation, and deletion through ADCS.
What steps will you follow to complete the requirement?
- A. Edit the [EAP-TLS with OSCP Enabled) authentication method and set the correct ADCS server OCSP URL. remove EAP-TLS and map the [EAP-TLS with OSCP Enabled) method to the Onboard Provisioning Service.
- B. Copy the default [EAP-TLS with OSCP Enabled] authentication method and update the correct ADCS server OCSP URL. remove EAP-TLS and map the custom created method to the OnBoard Authorization Service.
- C. Remove the EAP-TLS authentication method and add "EAP-TLS with OCSP Enabled' authentication method in the OnBoard Provisioning service. No other configuration changes are required.
- D. Copy the [EAP-TLS with OSCP Enabled) authentication method and set the correct ADCS server OCSP URL, remove EAP-TLS and map the custom created method to the Onboard Provisioning Service.
Answer: C
NEW QUESTION 44
Refer to the exhibit:
You have configured Onboard but me customer could not onboard one of his devices and has sent you the above screenshots. How could you resolve the issue?
- A. Increase the maximum number ofdevices allowed by the individual user account.
- B. Instruct the user to delete the profile on one of their other BYOD devices.
- C. Instruct the user to run the Quick connect application in Sponsor Mode.
- D. Increase the maximum number ofdevices that all users can provision to 3.
Answer: D
NEW QUESTION 45
A customer has configured Onboard with Single SSID provision for Aruba IAP Windows devices work as expected but cannot get the Apple iOS devices to work. The Apple iOS devices automatically get redirected to a blank page and do not get the Onboard portal page. What would you check to fix the issue?
- A. Verify if the Onboard URL is updated correctly in the external captive portal profile.
- B. Verify if the external captive portal profile is enabled to use HTTPS with port 443.
- C. Verify if Onboard Pre-Provisioning enforcement profile sends the correct Aruba user role.
- D. Verify if the checkbox "Enable bypassing the Apple Captive Network Assistant" is checked.
Answer: A
NEW QUESTION 46
......
HPE6-A77 Certification Overview Latest HPE6-A77 PDF Dumps: https://www.pass4cram.com/HPE6-A77_free-download.html