Summer Goodies - 55% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: av5rz84q

Exact2Pass Menu

Question # 4

Refer to the exhibit.

A customer has configured Onboard in a cluster with two nodes. All devices were onboarded in the network through node1 but those clients fail to authenticate through node2 with the error shown What steps would you suggest to make provisioning and authentication work across the entire cluster? (Select three)

A.

Configure the Network Settings in Onboard to trust the Policy Manager EAP certificate.

B.

Have all of the BYOO clients disconnect and reconnect to the network.

C.

Configure the Onboard Root CA to trust the Policy Manager EAP certificate root.

D.

Make sure that the EAP certificates on both nodes are issued by one common root Certificate Authority (CA).

Full Access
Question # 5

Your customer has recently implemented a seIf-registration portal in ClearPass Guest to be used on a Guest SSID broadcast from an Aruba controller Your customer has started complaining that the users are not able to reliably access the Internet after clicking the login button on the receipt page They tell you that the users will click the login button multiple times and after about a minute they gam access.

What could be causing this issue?

A.

The enforcement profile on ClearPass is set up with an IETF:session delay.

B.

The self-registration page is configured with a 1 minute login delay.

C.

The guest users are assigned a firewall user role that has a rate limit.

D.

The guest users are assigned multiple DNS servers delaying DNS response.

Full Access
Question # 6

Refer to the exhibit.

You have configured an Onboard portal for single SSID provision. During testing you notice that the QuickConnect Application did not display the "Connect" button, only the finish button. To get connected the test user had to manually connect to the secure-HS-5007 SSID but was prompted for a username and password. Using the screenshots as a reference, how would you fix this issue?

A.

Check the network settings for the correct SSID name spelling.

B.

Install a public signed HTTPS web server certificate on the ClearPass server

C.

Change the network settings to use EAP-TLS for the authentication protocol.

D.

Configure the SSID to support both EAP-PEAP and EAP-TLS authentication method

Full Access
Question # 7

Refer to the exhibit.

A customer is doing a new ClearPass installation and is setting up clustering between two ClearPass servers running a 6.8.6 version. The ClearPass server failed to add the subscriber node. The customer was able to login to the console of the ClearPass server with the same CLI password used during the cluster setup. The customer has sent you the screenshots seeking your support Why did an attempt to add a subscriber node failed showing that error?

A.

The data and time in the subscriber was not synchronized with the NTP server

B.

The subscriber server is running with a default self -signed HTTPS certificate

C.

The default database certificate used in the publisher server is not a valid certificate

D.

The subscriber server is running with a public signed and trusted HTTPS certificate

Full Access
Question # 8

A customer is planning to implement machine and user authentication on infrastructure with one Aruba Controller and a single ClearPass Server. What should the customer consider while designing this solution? (Select three.)

A.

The customer does not need to worry about Multi-Master Catht Survivability because the Controller will also cache the machine state.

B.

The Windows User must log off. restart or disconnect their machine to initiate a machine authentication before the cache expires.

C.

The machine authentication status rs written in the Multi-master cache on the ClearPass Server for 24 hrs

D.

The Customer should enable Multi-Master Cache Survivability as the Aruba Controller will not cache the machine state.

E.

Machine Authentication only uses EAP TLS. as such a PKI infrastructure should be in place for machine authentication.

F.

Onboard must be used to install the Certificates on the personal devices to do the user and machine authentication

Full Access