Skip to content

HPE6-A71 Aruba Certified Mobility Professional Exams demo

Exam A
QUESTION 1
An administrator deploys an AP at a branch office. The branch office has a private WAN circuit that provides
connectivity to a corporate office controller. An Ethernet port on the AP is connected to a network storage
device that contains sensitive information. The administrator is concerned about sending this traffic in clear-text
across the private WAN circuit.
What can the administrator do to prevent this problem?
A. Enable IPSec encryption on the AP's wired ports.
B. Convert the campus AP into a RAP.
C. Redirect the wired port traffic to an AP-to-controller GRE tunnel.
D. Enable AP encryption for wired ports.
Correct Answer: A
Section: (none)
Explanation
Explanation/Reference:
QUESTION 2
An administrator needs to modify a VAP used for a branch office RAP. The VAP's operating mode is currently
defined as backup and uses tunnel mode forwarding. The administrator wants to implement split-tunnel
forwarding mode in the VAP.
Which WLAN operating mode must the administrator define for the VAP before the tunnel forwarding mode
can be changed to split-tunnel?
A. Trusted
B. Always
C. Persistent
D. Standard
Correct Answer: D
Section: (none)
Explanation
Explanation/Reference:
QUESTION 3
The administrator expects the AP to connect to a cluster, but the AP fails to connect. The administrator
examines the configuration of an AP from apboot mode shown in the exhibit. What can the administrator
determine about the configuration of the AP?
96CE4376707A97CE80D4B1916F054522
A. The AP is configured to terminate on a Mobility Controller in a cluster.
B. The AP is configured as a RAP to terminate on a stand-alone controller.
C. The AP is configured as a RAP to terminate on a Mobility Master.
D. The AP is configured to terminate on a non-cluster Mobility Controller.
Correct Answer: D
Section: (none)
Explanation
Explanation/Reference:
QUESTION 4
An administrator creates service-based policies for AirGroup on the Mobility Master (MM). The administrator
can define location-based policy limits based on which information?
A. controller names, controller groups, and controller Fully Qualified Domain Names (FQDNs)
B. AP names, AP groups, controller names, and controller groups
C. AP Fully Qualified Location Names (FQLNs) and controller Fully Qualified Domain Names (FQDNs)
D. AP names, AP groups, and AP Fully Qualified Location Names (FQLNs)
Correct Answer: D
Section: (none)
Explanation
Explanation/Reference:
Reference: http://www.arubanetworks.com/techdocs/ArubaOS_81_Web_Help/Content/ArubaFrameStyles/
AirGroup/AirGroup_Features.htm
QUESTION 5
An administrator supports a RAP at a branch office. A user's device that is attached to the Ethernet port is
assigned an 802.1X AAA policy and is configured for tunneled node.
How is the user's traffic transmitted to the corporate office?
A. It is not encapsulated by GRE and not protected with IPSec.
96CE4376707A97CE80D4B1916F054522
B. It is encapsulated by GRE and protected with IPSec.
C. It is not encapsulated by GRE but is protected with IPSec.
D. It is encapsulated by GRE and not protected with IPSec.
Correct Answer: B
Section: (none)
Explanation
Explanation/Reference:
QUESTION 6
An administrator creates a user role that department A in a company uses. Various other roles exist for other
departments. All employees connect to the same ESSID, which authenticates to an external AAA server.
How should the administrator configure the controller to assign the appropriate roles to the employees?
A. Implement default roles.
B. Implement user roles.
C. Implement AAA profile roles.
D. Implement server-derived roles.
Correct Answer: B
Section: (none)
Explanation
Explanation/Reference:
QUESTION 7
An administrator implements two redundant Aruba Mobility Masters (MMs). Which protocol should the
administrator use to detect a failure in a single subnet?
A. PAPI
B. VRRP
C. SNMP
D. IPSec
Correct Answer: B
Section: (none)
Explanation
Explanation/Reference:
QUESTION 8
An administrator creates new pre- and post-authentication roles for a new WLAN. For which profile should the
administrator assign these new roles under the Managed Network section?
A. 802.1X
B. AAA profile
C. Server Groups
D. Virtual AP
Correct Answer: B
96CE4376707A97CE80D4B1916F054522
Section: (none)
Explanation
Explanation/Reference:
QUESTION 9
Which forwarding mode is used for a WLAN if a RAP needs to decrypt all user traffic and forward it locally?
A. Bridge
B. Decrypt-tunnel
C. Tunnel
D. Split-tunnel
Correct Answer: A
Section: (none)
Explanation
Explanation/Reference:
QUESTION 10
A company opens a new branch office and a RAP is used to connect to a corporate office Aruba Mobility
Controller (MC). The company needs to provide connectivity to the office across the street. There is an AP
across the street. However, there is no wired connectivity between the buildings.
Which actions can the administrator select to provide the required connectivity? (Choose two.)
A. Implement two mesh clusters.
B. Provision the RAP as a Remote Mesh Portal.
C. Provision all APs at the branch offices as Mesh Points.
D. Provision all APs at the branch offices as Mesh Portals.
E. Implement one of the APs as a Mesh Point.
Correct Answer: BC
Section: (none)
Explanation
Explanation/Reference:
QUESTION 11
An administrator supports a group of employees that connect to the corporate office using the VIA client. An
Aruba Mobility Controller (MC), behind a corporate firewall, terminates the user's VPN sessions. The VPN
sessions fail to establish because of the existing firewall rules.
Which connections must the administrator allow on the firewall? (Choose three.)
A. TCP 443
B. UDP 8211
C. UDP 8202
D. UDP 500
E. UDP 4500
F. TCP 4443
96CE4376707A97CE80D4B1916F054522
Correct Answer: ADE
Section: (none)
Explanation
Explanation/Reference:
QUESTION 12
Refer to the exhibit.
The Branch office RAP shown in the exhibit provides secure wireless employee access. Because of security
concerns, the company's security policy does not allow wireless guest access. Some customers that visit the
Branch office need Internet access. A RAP's Ethernet Port 3 is used for wired guest access and Port 2 is used
for wired employee access. When employees connect to Port 2, they are authenticated successfully and a
split-tunnel policy allows them access to both corporate and Internet resources from the Branch office. Guest
users, however, cannot access Internet resources on Port 3.
How can the administrator provide guest users Internet access?
A. Create a guest VAP that allows wired RAP port access.
B. Implement ClientMatch to handle the employee and guest user traffic correctly.
C. Configure a bridge role for the wired RAP port.
D. Implement the MultiZone feature on the RAP.
Correct Answer: A
Section: (none)
Explanation
Explanation/Reference:
QUESTION 13
An administrator wants to temporarily deny login access to users who fail 802.1x authentication functions three
or more times. Which process will the administrator need to configure?
A. fail through
B. captive portal
C. EAP termination
D. blacklisting
96CE4376707A97CE80D4B1916F054522
Correct Answer: D
Section: (none)
Explanation
Explanation/Reference:
QUESTION 14
A network of Mobility Controllers (MCs) is managed by a Mobility Master (MM). An administrator misconfigures
the IP addressing on an MC and the MC loses connectivity to the MM.
How should the administrator fix this problem?
A. Restore the previous configuration on the Mobility Master.
B. Use the disaster recovery mode on the Mobility Master.
C. Use the auto-recovery mode on the Mobility Master.
D. Use the disaster recovery mode on the Mobility Controller.
Correct Answer: D
Section: (none)
Explanation
Explanation/Reference:
QUESTION 15
An administrator implements a standalone controller that runs ArubaOS 8.x. Which feature should the
administrator configure to optimize the RF operation for the company's WLAN?
A. Clustering
B. Zones
C. AirMatch
D. ARM
Correct Answer: D
Section: (none)
Explanation
Explanation/Reference:
QUESTION 16
An administrator wants to implement the MultiZone feature in a company's network to segregate corporate and
guest traffic. Corporate traffic will have APs establish connections to a cluster managed by a Mobility Master
(MM), and guest traffic will have the same APs establish connections to a standalone controller at the
company's DMZ.
Given this scenario, what is true about the implementation of MultiZone?
A. Only the primary zone can reboot, upgrade, or provision MultiZone APs.
B. A management session is established only with the primary zone, but data sessions are established to all
zones.
C. The primary and data zones must be in the same L2 subnet.
D. A MultiZone AP can initially connect to any zone to obtain its configuration.
96CE4376707A97CE80D4B1916F054522
Correct Answer: A
Section: (none)
Explanation
Explanation/Reference:
QUESTION 17
Which configuration command needs to be executed on an Aruba Mobility Controller (MC) to forward AP
statistical data to an AirWave Management Platform (AMP)?
A. snmp-server
B. ssh-server
C. mgmt-server
D. tunneled-node-server
Correct Answer: C
Section: (none)
Explanation
Explanation/Reference:
QUESTION 18
An administrator configures two Mobility Masters (MMs) for redundancy and database synchronization. Which
protocol transports database information between the two MMs?
A. VRRP
B. AMON
C. SNMP
D. IPSec
Correct Answer: A
Section: (none)
Explanation
Explanation/Reference:
QUESTION 19
A Microsoft RADIUS server is used to centralize AAA functions by a company. Upon a successful
authentication lookup performed by an Aruba Mobility Controller (MC), the administrator wants to have the
RADIUS server pass back the correct post-authentication role name that the controller should apply to the
user's traffic.
Which additional task must the administrator perform for the controller's configuration to implement this
process?
A. Configure the server-derived rules on the controller.
B. Install ClearPass's VSA file on the controller.
C. Install Microsoft's VSA file on the controller.
D. Enable AAA on the controller.
Correct Answer: A
Section: (none)
Explanation
96CE4376707A97CE80D4B1916F054522
Explanation/Reference:
QUESTION 20
Refer to the exhibit.
Controllers are configured in a cluster as shown in the exhibit. These are the network details.
A Mobility Master (MM) manages the cluster.
The cluster contains two controllers C1 and C2.
AP1 and AP2 use C1 as their Active AP Anchor Controller (A-AAC), with C2 as their Standby AAC (S-AAC).
AP3 and AP4 use C2 as their A-AAC, with C1 as their S-AAC.
User1 establishes a wireless connection via AP1, where the Active User Anchor Controller (A-UAC) assigned
is C1, with C2 as the standby. What happens when User1 roams the wireless network and eventually their
session is handled by AP3?
A. The AP3's A-AAC switches to C1, and the user's A-UAC switches to C2.
B. The AP3's A-AAC switches to C1, and the user's A-UAC remains on C1.
C. The AP3's A-AAC remains on C2, and the user's A-UAC switches to C2.
D. The AP3's A-AAC remains on C2, and the user's A-UAC remains on C1.
Correct Answer: D
Section: (none)
Explanation
Explanation/Reference:
QUESTION 21
An administrator configures the MultiZone feature for a company network, where a mobility cluster is the
primary zone and a standalone controller in the company's DMZ represents a secondary data zone. The
administrator configures two AP Groups and respective VAPs for the zones on the Mobility Master (MM) in the
primary zone. When the APs boot up and establish connections to both zones, the administrator notices that
96CE4376707A97CE80D4B1916F054522
no data connections are established to the data zone.
What must the administrator do to fix this problem?
A. Configure the same AP Groups and VAPs on the standalone controller, and associate the MultiZone APs to
both groups.
B. Configure the same AP Group in the data zone as it is in the primary zone, and configure the VAPs in the
data zone.
C. Have the MultiZone APs initially boot from the standalone controller in the data zone.
D. Create different AP Groups and VAPs on the Mobility Master and standalone controllers, and associate the
MuttiZone APs to both groups.
Correct Answer: B
Section: (none)
Explanation
Explanation/Reference:
QUESTION 22
An administrator troubleshoots a roaming problem where a user loses connectivity to the network during the
roaming process. To help troubleshoot this problem, which device or devices in a wireless network initiates the
roaming process?
A. the AP
B. both the client and the controller
C. the client
D. the controller
Correct Answer: C
Section: (none)
Explanation
Explanation/Reference:
QUESTION 23
Which RAP WLAN operation mode should an administrator configure if the SSID should only be advertised if
controller connectivity is lost?
A. Standard
B. Persistent
C. Always
D. Backup
Correct Answer: D
Section: (none)
Explanation
Explanation/Reference:
QUESTION 24
An administrator supports a cluster of four Aruba Mobility Controllers (MCs) with management addresses of
10.1.100.101, 10.1.100.102, 10.1.100.103, and 10.1.305.114. The administrator accesses an AP associated
with this cluster, reboots it, and accesses apboot mode. The administrator executes the printenv command.
96CE4376707A97CE80D4B1916F054522
Which AP parameter contains the IP addresses of the cluster members that the AP should use to connect to
the cluster?
A. master_ip
B. cfg_lms
C. servername
D. nodelist
Correct Answer: D
Section: (none)
Explanation
Explanation/Reference:
QUESTION 25
Which ArubaOS CLI command can an administrator execute to determine if AP load balancing is enabled in a
cluster?
A. show switches
B. show ap active
C. show lc-cluster group-membership
D. show aaa cluster essid
Correct Answer: C
Section: (none)
Explanation
Explanation/Reference:

Buy full version for more questions
Previous article DP-100 Designing and Implementing a Data Science Solution on Azure exams demo
Next article NSE5_FAZ-6.2 Fortinet NSE 5 - FortiAnalyzer 6.2 exams demo

Leave a comment

* Required fields