Get Latest Jan-2022 Conduct effective penetration tests using SurePassExams HPE6-A68 exam [Q34-Q55]

Share

Get Latest [Jan-2022] Conduct effective penetration tests using  SurePassExams HPE6-A68

Penetration testers simulate HPE6-A68 exam PDF


HP HPE6-A68 Exam Syllabus Topics:

TopicDetails
Topic 1
  • External Authentication
  • ClearPass for AAA
Topic 2
  • Clustering and Redundancy
  • Intro to ClearPass
Topic 3
  • Endpoint Analysis
  • Operations and Admin Users

 

NEW QUESTION 34
Use this form to make changes to the RADIUS Web Login Guest Network.

A Web Login page is configured in Clear Pass Guest as shown.
What is the purpose of the Pre-Auth Check?

  • A. To replace the need for the NAD to send an authentication request to ClearPass
  • B. To authenticate users before the client sends the credentials to the NAD
  • C. To authenticate users when they are roaming from one NAD to another
  • D. To authenticate users before they launch the Web Login Page
  • E. To authenticate users after the NAD sends an authentication request to ClerPass

Answer: B

 

NEW QUESTION 35
Which use cases will require a ClearPass Guest application license? (Select two.)

  • A. Sponsor based guest user access
  • B. Guest endpoint health assessment
  • C. Guest user self-registration for access
  • D. Guest personal device onboarding
  • E. Guest device fingerprinting

Answer: A,C

 

NEW QUESTION 36
Refer to the exhibit.

Based on the configuration for 'maximum devices' shown, which statement accurately describes its settings?

  • A. It limits the number of devices that a single user can connect to the network.
  • B. It limits the total number of devices that can be provisioned by ClearPass.
  • C. It limits the total number of Onboarded devices connected to the network.
  • D. It limits the number of devices that a single user can Onboard.
  • E. The user cannot Onboard any devices.

Answer: D

 

NEW QUESTION 37
Based on the Policy configuration shown, which VLAN will be assigned when a user with ClearPass role Engineer authenticates to the network successfully using connection protocol WEBAUTH?

  • A. Deny Access
  • B. Full Access VLAN
  • C. Internet VLAN
  • D. Employee VLAN

Answer: D

 

NEW QUESTION 38
Which components of a ClearPass is mandatory?

  • A. Posture
  • B. Role Mapping Policy
  • C. Enforcement
  • D. Profiler
  • E. Authorization Source

Answer: C

 

NEW QUESTION 39
Which component of a ClearPass Service is mandatory?

  • A. Posture
  • B. Role Mapping Policy
  • C. Enforcement
  • D. Profiler
  • E. Authorization Source

Answer: C

Explanation:
Explanation
An enforcement policy is a way to organize enforcement profiles and apply them to users or Policy Manager roles. Based on the enforcement policy assigned to the role, enforcement profiles are applied to the service request.

 

NEW QUESTION 40
Refer to the exhibit.

An employee connects a corporate laptop to the network and authenticates for the first time using EAP-TLS.
Based on the Enforcement Policy configuration shown, which Enforcement Profile will be sent?

  • A. Deny Access Profile
  • B. Onboard Device Repository
  • C. Onboard Pre-Provisioning - Aruba
  • D. Onboard Post-Provisioning - Aruba

Answer: D

 

NEW QUESTION 41
What are Operator Profiles used for?

  • A. To enforce role based access control for ClearPass Policy Manager users.
  • B. To map AD attributes to admin privilege levels in ClearPass Guest.
  • C. To assign ClearPass roles to guest users.
  • D. To enforce role based access control for Aruba Controllers.
  • E. To enforce role based access control for ClearPass Guest Admin users.

Answer: E

 

NEW QUESTION 42
Refer to the exhibit.

In the Aruba RADIUS dictionary shown, what is the purpose of the RADIUS attributes?

  • A. to send CoA packets from ClearPass to the Aruba NAD
  • B. to send information via RADIUS packets to Aruba NADs
  • C. to gather information about Aruba NADs for ClearPass
  • D. to gather and send Aruba NAD information to ClearPass
  • E. to send information via RADIUS packets to clients

Answer: E

 

NEW QUESTION 43
Why is a terminate session enforcement profile used during posture checks with 802.1x authentication?

  • A. To send a RADIUS CoA message from the ClearPass server to the client
  • B. To force the user to re-authenticate and run through the service flow again
  • C. To remediate the client applications and firewall do that updates can be installed
  • D. To blacklist the user when they are in an unhealthy posture state
  • E. To disconnect the user for 30 seconds when they are in an unhealthy posture state

Answer: A

 

NEW QUESTION 44
ClearPass and a wired switch are configured for 802.1x authentication with RADIUS CoA (RFC 3576) on UDP port 3799. This port has been blocked by a firewall between the wired switch and ClearPass.
What will be the outcome of this state?

  • A. During RADIUS Authentication, certificate exchange between the wired switch and ClearPass will fail.
  • B. RADIUS Authentication will succeed, but Post-Authentication Disconnect-Requests from ClearPass to the wired switch will not be delivered.
  • C. RADIUS Authentication will succeed, but RADIUS Access-Accept messages from ClearPass to the wired switch for Change of Role will not be delivered.
  • D. RADIUS Authentications will timeout because the wired switch will not be able to reach the ClearPass server.
  • E. RADIUS Authentications will fail because the wired switch will not be able to reach the ClearPass server.

Answer: B

 

NEW QUESTION 45
In which ways can ClearPass derive client roles during policy service processing? (Select two.)

  • A. Through a role mapping policy
  • B. From the Aruba Network Access Device
  • C. From the server derivation rule in the Aruba Controller server group for the client
  • D. From the attributes configured in a Network Access Device
  • E. From the attributes configured in Active Directory

Answer: A,E

 

NEW QUESTION 46
Which steps are required to use ClearPass as a TACACS+ Authentication server for a network device? (Select two.)

  • A. Configure a TACACS Enforcement Profile on ClearPass for the desired privilege level.
  • B. Configure a RADIUS Enforcement Profile on ClearPass for the desired privilege level.
  • C. Configure ClearPass roles on the network device.
  • D. Enable RADIUS accounting on the NAD.
  • E. Configure ClearPass as an Authentication server on the network device.

Answer: A,E

Explanation:
Explanation
You need to make sure you modify your policy (Configuration Enforcement Policies) Edit - [Admin Network Login Policy]) and add your AD group settings in to the corresponding privilege level.

 

NEW QUESTION 47
Which authorization servers are supported by ClearPass? (Select two.)

  • A. LDAP server
  • B. Aruba Controller
  • C. Aruba Mobility Access Switch
  • D. Active Directory
  • E. Cisco Controller

Answer: A,D

Explanation:
Explanation
Authentication Sources can be one or more instances of the following examples:
* Active Directory
* LDAP Directory
* SQL DB
* Token Server
* Policy Manager local DB
References: ClearPass Policy Manager 6.5 User Guide (October 2015), page 114
https://community.arubanetworks.com/aruba/attachments/aruba/SoftwareUserReferenceGuides/52/1/ClearPass%

 

NEW QUESTION 48
What is the purpose of RADIUS CoA (RFC 3576)?

  • A. to apply firewall policies based on authentication credentials
  • B. to force the client to re-authenticate upon roaming to a new Controller
  • C. to authenticate users or devices before granting them access to a network
  • D. to transmit messages to the NAD/NAS to modify a user's session status
  • E. to validate a host MAC address against a whitelist or a blacklist

Answer: D

Explanation:
Explanation
CoA messages modify session authorization attributes such as data filters.
References: https://tools.ietf.org/html/rfc3576

 

NEW QUESTION 49
Refer to the exhibit.

Based on the Authentication sources configuration shown, which statement accurately describes the outcome if the user is not found?

  • A. If the user is not found in the local user repository but is present in the remotelab AD, a reject message is sent back to the NAD.
  • B. If the user is not found in the remotelab AD but is present in the local user repository, a reject message is sent back to the NAD.
  • C. If the user is not found in the local user repository and remotelab AD, a reject message is sent back to the NAD.
  • D. If the user is not found in the local user repository a timeout message is sent back to the NAD.
  • E. If the user is not found in the local user repository a reject message is sent back to the NAD.

Answer: C

Explanation:
Policy Manager looks for the device or user by executing the first filter associated with the authentication source.
After the device or user is found, Policy Manager then authenticates this entity against this authentication source. The flow is outlined below:
* On successful authentication, Policy Manager moves on to the next stage of policy evaluation, which collects role mapping attributes from the authorization sources.
* Where no authentication source is specified (for example, for unmanageable devices), Policy Manager passes the request to the next configured policy component for this service.
* If Policy Manager does not find the connecting entity in any of the configured authentication sources, it rejects the request.
References: ClearPass Policy Manager 6.5 User Guide (October 2015), page 134
https://community.arubanetworks.com/aruba/attachments/aruba/SoftwareUserReferenceGuides/52/1/ClearPass%20Policy%20Manager%206.5%20User%20Guide.pdf

 

NEW QUESTION 50
Refer to the exhibit.

The ClearPass Event Viewer displays an error when a user authenticates with EAP-TLS to ClearPass through an Aruba Controller Wireless Network.
What is the cause of this error?

  • A. The controller's shared secret used during the certificate exchange is incorrect.
  • B. The NAS source interface IP is incorrect.
  • C. The controller used an incorrect shared secret for the RADIUS authentication.
  • D. The client's shared secret used during the certificate exchange is incorrect.
  • E. The client sent an incorrect shared secret for the 802.1X authentication.

Answer: C

 

NEW QUESTION 51
Refer to the exhibit.

Which statement accurately describes the cp82 ClearPass node? (Choose two.)

  • A. It operates as a Publisher in the same cluster as the primary Publisher when the primary is active.
  • B. It operates as a Publisher in a separate cluster when the Publisher is active.
  • C. It becomes the Publisher when the primary Publisher fails.
  • D. It stays as a Subscriber when the Publisher fails.
  • E. It operates as a Subscriber when the Publisher is active.

Answer: D,E

 

NEW QUESTION 52
Which statement accurately describes configuration of Data and Management ports on the ClearPass appliance? (Select two.)

  • A. Static IP addresses are only allowed on the management port.
  • B. Configuration of the data port is mandatory.
  • C. Configuration on the management port is mandatory.
  • D. Configuration of the management port is optional.
  • E. Configuration of the data port if optional.

Answer: C,E

Explanation:
Explanation
The Management port (ethernet 0) provides access for cluster administration and appliance maintenance using the WebUI, CLI, or internal cluster communication. This configuration is mandatory.
The configuration of the data port is optional. If this port is not configured, requests are redirected to the Management port.
References:
http://www.arubanetworks.com/techdocs/ClearPass/Aruba_DeployGd_HTML/Content/1%20About%20ClearPas

 

NEW QUESTION 53
Refer to the exhibit.

Based on the Posture Policy configuration shown, above, which statement is true?

  • A. This Posture Policy can use either the persistent or dissolvable Onguard agent to obtain the statement of health.
  • B. This Posture Policy checks for presence of a firewall application in Windows devices.
  • C. This Posture Policy can only be applied to an 802.1x wired service not 802.1x wireless.
  • D. This Posture Policy checks with a Windows NPS server for posture tokens.
  • E. This Posture Policy checks the health status of devices running Windows, Linux and Mac OS X.

Answer: A

 

NEW QUESTION 54
Refer to the exhibit.

What is the purpose of the 'Clock Skew Allowance' setting? (Choose tow.)

  • A. to set start time in client certificate to a few minutes before current time
  • B. to adjust clock time on client device to a few minutes before current time
  • C. to set expiry time in client certificate to a few minutes longer that the default setting
  • D. to ensure server certificate validation does not fail due to client clock sync issues
  • E. to ensure client certificate validation does not fail due to client clock sync issues

Answer: E

 

NEW QUESTION 55
......

Tested Material Used To HPE6-A68 Test Engine: https://www.surepassexams.com/HPE6-A68-exam-bootcamp.html