Black Friday Special Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > HP > Aruba Certified Switching Professional (ACSP) V1 > HPE6-A73

HPE6-A73 Aruba Certified Switching Professional Exam Question and Answers

Question # 4

An administrator wants to use an existing Aruba gateway's firewall policies to filter both wireless and wired traffic. Which AOS-CX switch feature should a customer implement to ensure the gateway applies the same or similar firewall policies to users' wired and wireless traffic?

A.

GRE tunneling

B.

User-based tunneling

C.

Port-based tunneling

D.

IPSec tunneling

Full Access
Question # 5

A network has two AOS-CX switches connected to two different service providers. The administrator is

concerned about bandwidth consumption on the service provider links and learned that the service providers were using the company as a transit AS.

Which feature should the administrator implement to prevent this situation?

A.

Configure route maps and apply them to BGP

B.

Configure the two switches as route reflectors

C.

Configure a classifier policy to disable MED

D.

Configure bi-directional forwarding detection on both switches

Full Access
Question # 6

What is correct regarding rate limiting and egress queue shaping on AOS-CX switches?

A.

Only a traffic rate and burst size can be defined for a queue

B.

Limits can be defined only for broadcast and multicast traffic

C.

Rate limiting and egress queue shaping can be used to restrict inbound traffic

D.

Rate limiting and egress queue shaping can be applied globally

Full Access
Question # 7

Examine the output from an AOS-CX switch implementing a dynamic segmentation solution involving

downloadable user roles:

Switch# show port-access role clearpass

Role information:

Name : icxarubadur_employee-3044-2

Type : clearpass

Status: failed, parsing_failed

Reauthentication Period :

Authentication Mode :

Session Timeout :

The downloadable user roles are not being downloaded to the AOS-CX switch. Based on the above output,

what is the problem?

A.

The certificate that ClearPass uses in invalid

B.

The AOS-CX switch does not have the ClearPass certificate involved

C.

DNS fails to resolve the ClearPass server’s FQDN

D.

There is a date/time issue between the ClearPass server and the switch

Full Access
Question # 8

Which concept is implemented using Aruba’s dynamic segmentation?

A.

Root of trust

B.

Device fingerprinting

C.

Zero Touch Provisioning

D.

Colorless port

Full Access
Question # 9

A company has implemented 802.1X authentication on AOS-CX access switches, where two ClearPass

servers are used to implement AAA. Each switch has the two servers defined. A network engineer notices the following command configured on the AOS-CX switches:

radius-server tracking user-name monitor password plaintext aruba123

What is the purpose of this configuration?

A.

Implement replay protection for AAA messages

B.

Define the account to implement downloadable user roles

C.

Speed up the AAA authentication process

D.

Define the account to implement change of authorization

Full Access
Question # 10

A network administrator is implementing a configuration plan in NetEdit. The administrator used NetEdit to push the configuration plan to the switch. Which option in the NetEdit planning section should the administrator select to save the configuration running on the switch to the startup-config?

A.

EDIT

B.

VALIDATE

C.

COMMIT

D.

DEPLOY

Full Access
Question # 11

A company uses NetEdit to manage a network of 700 AOS-CX switches and approximately 1,000 other SNMP-capable devices.

Which management solution should the company use to monitor all the devices, as well as see a topology picture of how all the devices are connected together?

A.

NetEdit

B.

Aruba AirWave

C.

Aruba Activate

D.

Network Analysis Engine (NAE)

Full Access
Question # 12

An administrator has configured the following on an AOS-CX switch:

What is the correct ACL rule configuration that would allow traffic from anywhere to reach the web ports on the

two specified servers?

A.

access-list ip server 10 permit tcp any web-servers group web-ports

B.

access-list ip server 10 permit tcp any object-group web-servers object-group web-ports

C.

access-list ip server 10 permit tcp any group web-servers group web-ports

D.

access-list ip server 10 permit tcp any web-servers web-ports

Full Access
Question # 13

Examine the attached diagram

Two AOS-CX switches are configured for VSX at the access layer, where servers attached to them. An SVI interface is configured for VLAN 10 and serves as the default gateway for VLAN 10. The ISL link between the switches fails, but the keepalive interface functions. Active gateway has been configured on the switches.

What is correct about access from the servers to the Core?

A.

Server 2 can successfully access the core layer via the keepalive link.

B.

Server 1 and Server 2 can communicate with each other via the core layer.

C.

Server 2 cannot access the core layer.

D.

Server 1 can access the core layer via both uplinks.

Full Access
Question # 14

Examine the network exhibit.

A network administrator is implementing OSPF on a VSX pair of aggregation switches: Agg1 and Agg2. VLANs 10 and 20 are connected to layer-2 access switches. Agg-1 and Agg-2 are configured as the default gateway for VLANs 10 and 20, with active gateway enabled.

What is the best practice for configuring OSPF on the aggregation switches and their connection to the Core switch?

A.

Define a layer-2 VSX LAG associated with a layer-3 VLAN interface. Enable active gateway for the Layer-3 VLAN.

B.

Define separate layer-3 VLAN interfaces between the aggregation and core switches. Enable active forwarding for the Layer-3 VLAN.

C.

Define separate layer-3 VLAN interfaces between the aggregation and core switches. Enable active gateway for the Layer-3 VLAN.

D.

Define a layer-2 VSX LAG associated with a layer-3 VLAN interface. Enable active forwarding for the Layer-3 VLAN.

Full Access
Question # 15

What must a network administrator implement in order to run an NAE script on an AOS-CX switch?

A.

Deployment

B.

Schedule

C.

Plan

D.

Agent

Full Access
Question # 16

How is voice traffic prioritized correctly on AOS-CX switches?

A.

By defining device profiles with QOS settings

B.

By placing it in the strict priority queue

C.

By implementing voice VLANs

D.

By implementing weighted fair queueing (WFQ)

Full Access
Question # 17

A network engineer for a company with 896 users across a multi-building campus wants to gather statistics on an important switch uplink and create actions based on issues that occur on the uplink. How often does an NAE agent gather information from the current state database in regard to the uplink interfaces?

A.

Once every 60 seconds

B.

Once every 1 second

C.

Once every 30 seconds

D.

Once every 5 seconds

Full Access
Question # 18

A network administrator is implementing BGP for a larger network. The network has over 20 exit points across 15 different BGP routers. The administrator does not want to implement a fully-meshed iBGP peering between all BGP routers.

Which feature should the administrator implement to reduce the number of peers the administrator needs to define?

A.

Next-hop-self

B.

BFD

C.

Peer-Groups

D.

Route reflectors

Full Access
Question # 19

An administrator is managing a network comprised of AOS-CX switches deployed at the aggregation layer. The switches are paired in a VSX stack and run the OSPF routing protocol. The administrator is concerned about how long it takes for OSPF to converge when one of the VSX switches has to reboot.

What should the administrator to do speed up the OSPF convergence of the switch that is rebooting?

A.

Change the VSXISL link from an OSPF broadcast link point-to-point.

B.

Implement graceful restart on the VSX switches and their neighboring OSPF switches.

C.

Decrease the VSX initial synchronization timer on the two VSX switches.

D.

Define non-backbone areas on the VSX switches as totally stubby areas.

Full Access
Question # 20

What is the correct way of associating a VRF instance to either a VLAN or an interface?

A.

Switch(config)# interface

Switch(config-if)# vlan access vrf attach

B.

Switch(config)# vlan vrf attach < vrf-name >

C.

Switch(config)# vlan

Switch(config-vlan-# vrf attach < vrf-name >

D.

Switch(config)# vlan vrf < vrf-name >

Full Access
Question # 21

A customer has twenty AOS-CX switches that will be managed by NetEdit and would like support for NetEdit these switches will exist in the network for at least five years.

Which type of licensing should be used by this customer?

A.

20 Aruba NetEdit permanent licenses

B.

20 Aruba NetEdit single node subscription licenses

C.

25 Aruba NetEdit permanent licenses

D.

1 Aruba NetEdit SMB License

Full Access
Question # 22

Which protocols are used by NetEdit to interact with third-party devices? (Choose two.)

A.

telnet

B.

SNMP

C.

SSH

D.

Restful API

E.

CDP

Full Access
Question # 23

An administrator wants to leverage the Network Analysis Engine (NAE) feature on AOS-CX switches to perform rootcause analysis and to assist in quicklyidentifying problems. Which two AOS-CX databases does the administrator have access to when implementing scripts? (Select two.)

A.

Time-series

B.

API

C.

VSX

D.

Configuration

E.

Audit

Full Access
Question # 24

When comparing PIM-DM and PIM-SM, which multicast components are only found with PIM-SM in multicast routing? (Choose two.)

A.

IGMP querier

B.

Rendezvous point

C.

Bootstrap router

D.

Shortest path tree

E.

Designated router

Full Access
Question # 25

A network engineer is setting up BGP on AOS-CX switches. The engineer is establishing two different eBGP peering’s to two different service providers. The engineer has dozens of contiguous C-class public networks that need to be advertised to the two service providers. The engineer manually defines the networks to be advertised individually with the "network" command.

How can an administrator advertise only a summarized route to the two service providers?

A.

Create a summarized static route and redistribute this into OSPR

B.

Summarize the networks with the "aggregate-address" BGP command

C.

Enable auto-summarization in the IPv4 address family of the BGP configuration

D.

Create a summarized route in OSPF

Full Access
Question # 26

An administrator is supporting a network with the access layer consisting of AOS-CX 6300 and 6400 switches. The administrator needs to quickly deploy Aruba IAPs and security cameras in the network, ensuring that the correct QoS and VLAN settings are dynamically applied to the switch ports. Currently, switches are not configured to do device authentication, and no authentication server exists in the network.

Which AOS-CX feature should the administrator use to dynamically assign the policy settings to the correct switch ports?

A.

Device profiles

B.

Change of authorization

C.

Dynamic segmentation

D.

Voice VLANs

Full Access
Question # 27

Examine the network exhibit.

A company has a guest implementation for wireless and wired access. Wireless access is implemented

through a third-party vendor. The company is concerned about wired guest traffic traversing the same network as the employee traffic. The network administrator has established a GRE tunnel between AOS-CX switches where guests are connected to a routing switch in the DMZ.

Which feature should the administrator implement to ensure that the guest traffic is tunneled to the DMZ while the employee traffic is forwarded using OSPF?

A.

OSPF route maps using the “set metric” command

B.

Policy-based routing (PBR)

C.

User-based tunneling (UBT)

D.

Classifier policies

Full Access
Question # 28

An administrator is managing a VSX pair of AOS-CX switches An administrator configures the following on the primary AOS-CX switch:

A.

The primary switch will erase VLAN 200 from the VSX pair

B.

The VLAN is only created on the secondary switch.

C.

The operation is not allowed by the switch and a CLI error is displayed

D.

The VLAN is created on both the primary and secondary switches

Full Access
Question # 29

The AOS-CX mobile app allows a network engineer or technician to perform which tasks? (Choose two.)

A.

Use NetEdit to manage switch configuration.

B.

Create a stack of AOS-CX switches.

C.

Transfer files between the switch and your mobile device.

D.

Securely access the switch using SSH.

E.

Schedule an operating system upgrade.

Full Access
Question # 30

What is a best practice concerning voice traffic and dynamic segmentation on AOS-CX switches?

A.

Controller authentication and user-based tunneling of the voice traffic

B.

Switch authentication and user-based tunneling of the voice traffic

C.

Controller authentication and port-based tunneling of the voice traffic

D.

Switch authentication and local forwarding of the voice traffic

Full Access
Question # 31

What would prevent two OSPF routers from forming an adjacency? (Select two.)

A.

Different priorities

B.

Different area types

C.

Different MTU sizes

D.

Different IP addresses

E.

Different router IDs

Full Access
Question # 32

Examine the attached diagram.

The two PCs are located in VLAN 11 (10.1.11.0/24). Which example defines how to implement active gateway

on the VSX core for VLAN 11?

A.

interface vlan 11

active-gateway ip 10.1.11.1

active-gateway mac 02:02:00:00:01:00

B.

interface lag 254

active-gateway vlan 11 ip 10.1.11.1

active-gateway vlan 11 mac 02:02:00:00:01:00

C.

interface lag 254

active-gateway ip 10.1.11.1

active-gateway mac 02:02:00:00:01:00

D.

vsx

vrrp group 1

Full Access
Question # 33

A network administrator is tasked to set up BGP in the company's network. The administrator is defining an eBGP peering between an AOS-CX switch and a directly-connected service provider. The administrator has configured the following on the AOS-CX switch:

However, when using the "show bgp all summary" command, the state does not display "Established" for the eBGP peer. What must the administrator configure to fix this issue?

A.

router bgp 64500 neighbor 192.168.1.1 ebgp-multihop

B.

router bgp 64500 enable

C.

router bgp 64500 address-family ipv4 unicast neighbor 192.168.1.1 activate

D.

router bgp 64500 neighbor 192.168.1.1 update-source loopback0

Full Access
Question # 34

How is NetEdit installed at a customer location?

A.

Via an Aruba NetEdit hardware appliance

B.

Via a DVD using a virtualized platform like Microsoft’s Hyper-V

C.

Via the Aruba Central cloud solution

D.

Via an OVA file and a virtualized platform like VMware’s ESXi

Full Access
Question # 35

A network administrator is attempting to troubleshoot a connectivity issue between a group of users and a

particular server. The administrator needs to examine the packets over a period of time from their desktop;

however, the administrator is not directly connected to the AOS-CX switch involved with the traffic flow.

What is correct regarding the ERSPAN session that needs to be established on an AOS-CX switch? (Choose two.)

A.

On the source AOS-CX switch, the destination specified is the switch to which the administrator’s desktop is connected

B.

On the source AOS-CX switch, the destination specified is the administrator’s desktop

C.

The encapsulation protocol used is GRE

D.

The encapsulation protocol used is VXLAN

E.

The encapsulation protocol is UDP

Full Access
Question # 36

A company is implementing AOS-CX switches at the access layer. The company wants to implement access control for employees and guests.

Which security features will require a ClearPass server to be installed and used by the company?

A.

Downloadable user roles

B.

Dynamic segmentation

C.

User-based tunneling (UBT)

D.

Change of authorization (CoA)

Full Access
Question # 37

An administrator implements interim accounting for guest users so that ClearPass can track the amount of bandwidth that guests upload and download. Guests that abuse bandwidth consumption should be disconnected from the network. The administrator configures the following on the AOS-CX access switches:

After performing this configuration, the administrator notices that guest users that have exceeded the guest bandwidth limit are not being disconnected. Upon further investigation, Access Tracker in ClearPass indicates a disconnect CoA message is being sent to the AOS-CX switch.

What is causing this issue?

A.

RADIUS change of authorization is not enabled on the AOS-CX switch.

B.

Bandwidth consumption of the guests is not being reported by the AOS-CX switch.

C.

NTP is not configured on the AOS-CX switch.

D.

There is a time discrepancy between the AOS-CX switch and ClearPass.

Full Access
Question # 38

When implementing user-based tunneling on an AOS-CX switch, which component defines the primary and backup Aruba gateways?

A.

Transit VLAN

B.

Gateway role

C.

Server group

D.

Zone

Full Access