[Oct-2023] Download Real HP HPE6-A78 Exam Dumps Test Engine Exam Questions
New HPE6-A78 exam dumps Use Updated HP Exam
HP HPE6-A78 certification exam is ideal for network security professionals who want to advance their careers in the field of cybersecurity. Aruba Certified Network Security Associate Exam certification validates the candidate's ability to design, implement and manage secure network solutions. Aruba Certified Network Security Associate Exam certification is recognized globally, and it is highly respected by employers in the industry.
NEW QUESTION # 20
A company has Aruba Mobility Controllers (MCs). Aruba campus APs. and ArubaOS-CX switches. The company plans to use ClearPass Policy Manager (CPPM) to classify endpoints by type The ClearPass admins tell you that they want to run Network scans as part of the solution What should you do to configure the infrastructure to support the scans?
- A. Create SNMPv3 users on ArubaOS-CX switches, and make sure that the credentials match those configured on CPPM
- B. Create remote mirrors on the ArubaOS-Swrtches that collect traffic on edge ports, and mirror it to CPPM's IP address.
- C. Create a TA profile on the ArubaOS-Switches with the root CA certificate for ClearPass's HTTPS certificate
- D. Create device fingerprinting profiles on the ArubaOS-Switches that include SNMP. and apply the profiles to edge ports
Answer: D
NEW QUESTION # 21
What are some functions of an AruDaOS user role?
- A. The role determines which wireless networks (SSiDs) a user is permitted to access
- B. The role determines which control plane ACL rules apply to the client's traffic
- C. The role determines which firewall policies and bandwidth contract apply to the clients traffic
- D. The role determines which authentication methods the user must pass to gain network access
Answer: D
NEW QUESTION # 22
What is one practice that can help you to maintain a digital chain or custody In your network?
- A. Ensure that all network infrastructure devices receive a valid clock using authenticated NTP
- B. Enable packet capturing on Instant AP or Moodily Controller (MC) datepath on an ongoing basis
- C. Ensure that all network Infrastructure devices use RADIUS rather than TACACS+ to authenticate managers
- D. Enable packet capturing on Instant AP or Mobility Controller (MC) control path on an ongoing basis.
Answer: B
NEW QUESTION # 23
What is an Authorized client as defined by ArubaOS Wireless Intrusion Prevention System (WIP)?
- A. a client that is not on the WIP blacklist
- B. a client that has a certificate issued by a trusted Certification Authority (CA)
- C. a client that has successfully authenticated to an authorized AP and passed encrypted traffic
- D. a client that is on the WIP whitelist.
Answer: C
NEW QUESTION # 24
What is one difference between EAP-Tunneled Layer security (EAP-TLS) and Protected EAP (PEAP)?
- A. EAP-TLS requires the supplicant to authenticate with a certificate, hut PEAP allows the supplicant to use a username and password.
- B. EAP-TLS creates a TLS tunnel for transmitting user credentials, while PEAP authenticates the server and supplicant during a TLS handshake.
- C. EAP-TLS begins with the establishment of a TLS tunnel, but PEAP does not use a TLS tunnel as part of Its process
- D. EAP-TLS creates a TLS tunnel for transmitting user credentials securely while PEAP protects user credentials with TKIP encryption.
Answer: A
NEW QUESTION # 25
What is one way a noneypot can be used to launch a man-in-the-middle (MITM) attack to wireless clients?
- A. it uses a combination or software and hardware to jam the RF band and prevent the client from connecting to any wireless networks
- B. it examines wireless clients' probes and broadcasts the SSlDs in the probes, so that wireless clients will connect to it automatically.
- C. it runs an NMap scan on the wireless client to And the clients MAC and IP address. The hacker then connects to another network and spoofs those addresses.
- D. it uses ARP poisoning to disconnect wireless clients from the legitimate wireless network and force clients to connect to the hacker's wireless network instead.
Answer: D
NEW QUESTION # 26
What is a benefit of deploying Aruba ClearPass Device insight?
- A. Simpler troubleshooting of ClearPass solutions across an environment with multiple ClearPass Policy Managers
- B. Agent-based analysts of devices' security settings and health status, with the ability to implement quarantining
- C. visibility into devices' 802.1X supplicant settings and automated certificate deployment
- D. Highly accurate endpoint classification for environments with many devices types, including Internet of Things (loT)
Answer: C
NEW QUESTION # 27
You have deployed a new Aruba Mobility Controller (MC) and campus APs (CAPs). One of the WLANs enforces 802.IX authentication lo Aruba ClearPass Policy Manager {CPPM) When you test connecting the client to the WLAN. the test falls You check Aruba ClearPass Access Tracker and cannot find a record of the authentication attempt You ping from the MC to CPPM. and the ping is successful.
What is a good next step for troubleshooting?
- A. Renew CPPM's RADIUS/EAP certificate
- B. Check CPPM Event viewer.
- C. Check connectivity between CPPM and a backend directory server
- D. Reset the user credentials
Answer: B
NEW QUESTION # 28
What is a correct guideline for the management protocols that you should use on ArubaOS-Switches?
- A. Disable Telnet and use SSH instead
- B. Disable Telnet and use TFTP instead.
- C. Disable HTTPS and use SSH instead
- D. Disable SSH and use https instead.
Answer: D
NEW QUESTION # 29
You have been instructed to look in the ArubaOS Security Dashboard's client list Your goal is to find clients mat belong to the company and have connected to devices that might belong to hackers Which client fits this description?
- A. MAC address d8:50:e6 f3;6e;c5; Client Classification Interfering. AP Classification Neighbor
- B. MAC address d8:50:e6:f3;6e;60; Client Classification Interfering. AP Classification Interfering
- C. MAC address d8:50:e6:f3;6d;a4; Client Classification Authorized; AP Classification, interfering
- D. MAC address d8:50:e6:f3;TO;ab; Client Classification Interfering. AP Classification Rogue
Answer: B
NEW QUESTION # 30
What is a reason to set up a packet capture on an Aruba Mobility Controller (MC)?
- A. The security team believes that a wireless endpoint connected to the MC is launching an attack and wants to examine the traffic more closely.
- B. The company wants to use ClearPass Policy Manager (CPPM) to profile devices and needs to receive HTTP User-Agent strings from the MC.
- C. You want the MC to analyze wireless clients' traffic at a lower level, so that the ArubaOS firewall can control the traffic I based on application.
- D. You want the MC to analyze wireless clients' traffic at a lower level, so that the ArubaOS firewall can control Web traffic based on the destination URL.
Answer: C
NEW QUESTION # 31
What is an example or phishing?
- A. An attacker sends TCP messages to many different ports to discover which ports are open.
- B. An attacker lures clients to connect to a software-based AP that is using a legitimate SSID.
- C. An attacker sends emails posing as a service team member to get users to disclose their passwords.
- D. An attacker checks a user's password by using trying millions of potential passwords.
Answer: C
NEW QUESTION # 32
You need to deploy an Aruba instant AP where users can physically reach It. What are two recommended options for enhancing security for management access to the AP? (Select two )
- A. install a CA-signed certificate
- B. Disable the Web Ul.
- C. Configure WPA3-Enterpnse security on the AP
- D. Disable Its console ports
- E. Place a Tamper Evident Label (TELS) over its console port
Answer: A,E
NEW QUESTION # 33
What is one way that WPA3-PerSonal enhances security when compared to WPA2-Personal?
- A. WPA3-Personai prevents eavesdropping on other users' wireless traffic by a user who knows the passphrase for the WLAN.
- B. WPA3-Personal is more complicated to deploy because it requires a backend authentication server
- C. WPA3-Perscn3i is more secure against password leaking Because all users nave their own username and password
- D. WPA3-Personai is more resistant to passphrase cracking Because it requires passphrases to be at least 12 characters
Answer: C
NEW QUESTION # 34
You are managing an Aruba Mobility Controller (MC). What is a reason for adding a "Log Settings" definition in the ArubaOS Diagnostics > System > Log Settings page?
- A. Configuring the log facility and log format that the MC will use for forwarding logs to all Syslog servers
- B. Configuring a filter that you can apply to a defined Syslog server in order to filter events by subcategory
- C. Configuring the Syslog server settings for the server to which the MC forwards logs for a particular category and level
- D. Configuring the MC to generate logs for a particular event category and level, but only for a specific user or AP.
Answer: C
NEW QUESTION # 35
Refer to the exhibit.
You need to ensure that only management stations in subnet 192.168.1.0/24 can access the ArubaOS-Switches' CLI. Web Ul. and REST interfaces The company also wants to let managers use these stations to access other parts of the network What should you do?
- A. Specify 192.168.1.0.255.255.255.0 as authorized IP manager address
- B. Specify vlan 100 as the management vlan for the switches.
- C. Configure the switch to listen for these protocols on OOBM only.
- D. Establish a Control Plane Policing class that selects traffic from 192.168 1.0/24.
Answer: D
NEW QUESTION # 36
Which is a correct description of a stage in the Lockheed Martin kill chain?
- A. In the reconnaissance stage, the hacker assesses the impact of the attack and how much information was exfilltrated.
- B. In the exploitation and installation phases, malware creates a backdoor into the infected system for the hacker.
- C. In the delivery stage, malware collects valuable data and delivers or exfilltrated it to the hacker.
- D. In the weaponization stage, which occurs after malware has been delivered to a system, the malware executes Its function.
Answer: A
NEW QUESTION # 37
A company is deploying ArubaOS-CX switches to support 135 employees, which will tunnel client traffic to an Aruba Mobility Controller (MC) for the MC to apply firewall policies and deep packet inspection (DPI).
This MC will be dedicated to receiving traffic from the ArubaOS-CX switches.
What are the licensing requirements for the MC?
- A. one AP license per-switch. and one PEF license per-switch
- B. one AP license per-switch
- C. one PEF license per-switch. and one WCC license per-switch
- D. one PEF license per-switch
Answer: A
NEW QUESTION # 38
How does the ArubaOS firewall determine which rules to apply to a specific client's traffic?
- A. The firewall applies thee rules in policies associated with the client's user role.
- B. The firewall applies every rule that includes the client's IP address as the source or destination.
- C. The firewall applies the rules in policies associated with the client's wlan
- D. The firewall applies every rule that includes the dent's IP address as the source.
Answer: D
NEW QUESTION # 39
A company has an Aruba solution with a Mobility Master (MM) Mobility Controllers (MCs) and campus Aps.
What is one benefit of adding Aruba Airwave from the perspective of forensics?
- A. Airwave retains information about the network for much longer periods than ArubaOS solution
- B. Airwave is required to activate Wireless Intrusion Prevention (WIP) services on the ArubaOS solution
- C. Airwave can provide more advanced authentication and access control services for the AmbaOS solution
- D. AirWave enables low level debugging on the devices across the ArubaOS solution
Answer: B
NEW QUESTION # 40
You configure an ArubaOS-Switch to enforce 802.1X authentication with ClearPass Policy Manager (CPPM) denned as the RADIUS server Clients cannot authenticate You check Aruba ClearPass Access Tracker and cannot find a record of the authentication attempt.
What are two possible problems that have this symptom? (Select two)
- A. Clients are configured to use a mismatched EAP method from the one In the CPPM service.
- B. CPPM does not have a network device defined for the switch's IP address.
- C. The RADIUS shared secret does not match between the switch and CPPM.
- D. users are logging in with the wrong usernames and passwords or invalid certificates.
- E. Clients are not configured to trust the root CA certificate for CPPM's RADIUS/EAP certificate.
Answer: D,E
NEW QUESTION # 41
What is a benefit of Opportunistic Wireless Encryption (OWE)?
- A. It offers more control over who can connect to the wireless network when compared with WPA2-Personal
- B. It provides protection for wireless clients against both honeypot APs and man-in-the-middle (MUM) attacks
- C. It allows both WPA2-capabie and WPA3-capable clients to authenticate to the same WPA-Personal WLAN
- D. It allows anyone lo connect, but provides better protection against eavesdropping than a traditional open network
Answer: D
NEW QUESTION # 42
What is symmetric encryption?
- A. It uses a Key that is double the size of the message which it encrypts.
- B. It simultaneously creates ciphertext and a same-size MAC.
- C. It any form of encryption mat ensures that thee ciphertext Is the same length as the plaintext.
- D. It uses the same key to encrypt plaintext as to decrypt ciphertext.
Answer: D
NEW QUESTION # 43
A company has an ArubaOS controller-based solution with a WPA3-Enterprise WLAN. which authenticates wireless clients to Aruba ClearPass Policy Manager (CPPM). The company has decided to use digital certificates for authentication A user's Windows domain computer has had certificates installed on it However, the Networks and Connections window shows that authentication has tailed for the user. The Mobility Controllers (MC's) RADIUS events show that it is receiving Access-Rejects for the authentication attempt.
What is one place that you can you look for deeper insight into why this authentication attempt is failing?
- A. the reports generated by Aruba ClearPass Insight
- B. the packets captured on the MC control plane destined to UDP 1812
- C. the Alerts tab in the authentication record in CPPM Access Tracker
- D. the RADIUS events within the CPPM Event Viewer
Answer: C
NEW QUESTION # 44
......
Pass Your HPE6-A78 Dumps as PDF Updated on 2023 With 62 Questions: https://www.examprepaway.com/HP/braindumps.HPE6-A78.ete.file.html
Verified HPE6-A78 Dumps Q&As - HPE6-A78 Test Engine with Correct Answers: https://drive.google.com/open?id=1ijAZJRYm49bOEcQFT4O5pyiqwnoOCBTE