HPE6-A71 Practice Test Questions

170 Questions


What are the responsibilities of a cluster leader in a cluster of Aruba Mobility Controllers (MCs)? (Choose two.)


A.

To identify primary and secondary Mobility Controllers for APs


B.

To create a table to determine how a wireless client maps to a cluster member


C.

To identify a backup cluster leader for redundancy


D.

To manage the configuration of cluster members


E.

To automatically load balance clients if the load across cluster members changes





B.
  

To create a table to determine how a wireless client maps to a cluster member



E.
  

To automatically load balance clients if the load across cluster members changes



What is true about Aruba controllers under normal operations in a Mobility Master (MM)- Mobility Controller (MC) architecture?


A.

The Mobility Master can push a full configuration to a Mobility Controller.


B.

ARM must be used to optimize wireless performance.


C.

The APs can terminate on both Mobility Masters and Mobility Controllers.


D.

Any controller can perform local configurations.





A.
  

The Mobility Master can push a full configuration to a Mobility Controller.



Refer to the exhibit.

An administrator configures policies to allow RAPs to connect to the corporate office and
remote users to access resources. Which function does the VPN address pool serve in this
situation?


A.

Assigns an inner IP address to the RAP used within the VPN


B.

Assigns a public IP address that the RAP should use on its internet port


C.

Assigns IP addresses for remote users


D.

Assigns a DHCP address pool for the RAP





A.
  

Assigns an inner IP address to the RAP used within the VPN



An administrator implements machine authentication in an 802.1X profile. Which user role
will be assigned to the user’s session if machine authentication passes, but the 802.1X
user authentication fails for a user who connects?


A.

802.1X default user role


B.

Machine authentication default machine role


C.

802.1X initial user role


D.

Machine authentication default user role





B.
  

Machine authentication default machine role



An administrator configures a port on a RAP through the association of an AAA profile with
802.1X authentication to a RAP Ethernet port. This port connects to a switch with user
desktops attached. The administrator notices that when users connect wirelessly to the
RAP, a user role correctly restricts their traffic. But, when users connect with their wired
desktops, they are assigned an initial role and routed to a Captive Portal page.
What must the administrator do to enable desktop usage based on the user’s role
assignment?


A.

Implement ACLs on the RAP port.


B.

Apply a server-derived role policy to the RAP port.


C.

Identify the RAP port as untrusted.


D.

Map the RAP port to an authentication profile.





C.
  

Identify the RAP port as untrusted.



On the Aruba Mobility Master (MM), when is an AP configured to act as Mesh Portal or
Mesh Point?


A.

when the mesh cluster profile is created


B.

at the time of the AP’s apboot mode CLI


C.

when the APs are provisioned


D.

when the mesh radio profile is created





C.
  

when the APs are provisioned



Explanation: References:
4. Configure the Mesh Role:To configure the AP as the mesh portal, select Mesh
Portal.To configure the AP as a mesh point, select Mesh Point

An administrator wants to implement bandwidth limits to restrict employee access to highrisk
web sites. On the Mobility Master (MM), where would the administrator define these
limits?


A.

802.1X policy


B.

User role


C.

Firewall policy


D.

AAA policy





B.
  

User role



Refer to the exhibit.

An administrator supports a RAP at a branch office shown in the exhibit. The company has
one Mobility Controller (MC) at the Primary DMZ site and one at the Secondary DMZ site.
The RAP is configured to connect to only the MC at the Primary DMZ site. A network
outage with the ISP at the Primary DMZ site causes the RAP to reboot. Upon reboot, the
RAP cannot build a tunnel to the Secondary DMZ site MC because the administrator forgot
to add the Second LMS IP address to the AP Group configuration. Once the RAP can
successfully connect, the administrator can add the Secondary DMZ MC as a backup LMS
to fix the AP Group.
What should the administrator implement to allow the RAP to connect to the MC at the
Secondary DMZ site while the outage at the primary site persists?


A.

Dynamic discovery through DHCP Option 43


B.

Static configuration from apboot mode


C.

Dynamic discovery through DHCP Option 60


D.

Dynamic discovery through multicast ADP





B.
  

Static configuration from apboot mode



An administrator implements the Aruba AitGroup feature to accommodate the Apple
Bonjour service. In this implementation, which protocol advertises devices such as printers,
computers, and their services?


A.

LLDP


B.

Multicast DHCP


C.

Multicast DNS


D.

Broadcast DNS





C.
  

Multicast DNS



In a VPN that uses certificate-based authentication, which component must be configured
on the Mobility Master (MM) to allow a RAP to successfully connect to a Mobility Controller
(MC)?


A.

RAP VPN username and password


B.

WLAN and new RAP group


C.

RAP IPSec pre-shared key


D.

RAP whitelist





D.
  

RAP whitelist



An administrator wants to implement 802.1X authentication on Ethernet ports on branch
office controllers. What must the administrator do to implement this policy?


A.

Define the port an untrusted, and assign an AAA policy to the port.


B.

Define the port as trusted, and assign an AAA policy to the port.


C.

Define the port as untrusted, and assign an AAA policy to the VLAN.


D.

Define the port as trusted, and assign an AAA policy to the VLAN.





A.
  

Define the port an untrusted, and assign an AAA policy to the port.



Which forwarding mode is used for a WLAN if a RAP needs to decrypt all user traffic and
forward it locally?


A.

Split-tunnel


B.

Bridge


C.

Tunnel


D.

Decrypt-tunnel





B.
  

Bridge




Page 3 out of 15 Pages
Previous