Filters
Question type

Study Flashcards

A company is implementing a new wireless design and needs it to support high availability, even during times of switch system upgrades. The solution will involve Aruba Mobility Controller (MC) and Aruba AP connections requiring POE. Which campus AOS-CX switch solution and virtual switching should the company implement at the campus access layer?


A) AOS-CX 6400 and VSX
B) AOS-CX 6300 and VSF
C) AOS-CX 8325 and VSF
D) AOS-CX 8400 and VSX

E) All of the above
F) A) and C)

Correct Answer

verifed

verified

An administrator is supporting a network with the access layer consisting of AOS-CX 6300 and 6400 switches. The administrator needs to quickly deploy Aruba IAPs and security cameras in the network, ensuring that the correct QoS and VLAN settings are dynamically applied to the switch ports. Currently, switches are not configured to do device authentication, and no authentication server exists in the network. Which AOS-CX feature should the administrator use to dynamically assign the policy settings to the correct switch ports?


A) Device profiles
B) Change of authorization
C) Dynamic segmentation
D) Voice VLANs

E) All of the above
F) None of the above

Correct Answer

verifed

verified

An administrator wants to implement dynamic segmentation policies. The network consists of AOS-CX and Aruba gateways. Which type of forwarding should the administrator implement for users that already connect via wireless, but will also be connecting on Ethernet switch ports?


A) User-based tunneling (UBT)
B) Port-based tunneling (PBT)
C) Switch-to-switch tunneling (SST)
D) Local switching

E) A) and B)
F) B) and C)

Correct Answer

verifed

verified

Examine the following AOS-CX switch configuration: Examine the following AOS-CX switch configuration:   Which statement correctly describes what is allowed for traffic entering interface 1/1/3? A)  IP traffic from 10.1.11.0/24 is allowed to access 10.1.110.0/24 B)  IP traffic from 10.0.11.0/24 is allowed to access 10.1.12.0/24 C)  Traffic from 10.0.12.0/24 will generate a log record when accessing 10.0.11.0/24 D)  IP traffic from 10.1.12.0/24 is allowed to access 172.0.1.0/23 Which statement correctly describes what is allowed for traffic entering interface 1/1/3?


A) IP traffic from 10.1.11.0/24 is allowed to access 10.1.110.0/24
B) IP traffic from 10.0.11.0/24 is allowed to access 10.1.12.0/24
C) Traffic from 10.0.12.0/24 will generate a log record when accessing 10.0.11.0/24
D) IP traffic from 10.1.12.0/24 is allowed to access 172.0.1.0/23

E) None of the above
F) A) and B)

Correct Answer

verifed

verified

The AOS-CX mobile app allows a network engineer or technician to perform which tasks? (Choose two.)


A) Use NetEdit to manage switch configuration.
B) Create a stack of AOS-CX switches.
C) Transfer files between the switch and your mobile device.
D) Securely access the switch using SSH.
E) Schedule an operating system upgrade.

F) A) and C)
G) A) and D)

Correct Answer

verifed

verified

An administrator is implementing a multicast solution in a multi-VLAN network. Which statement is true about the configuration of the switches in the network?


A) IGMP snooping must be enabled on all interfaces on a switch to intelligently forward traffic
B) IGMP requires join and leave messages to graft and prune multicast streams between switches
C) IGMP must be enabled on all routed interfaces where multicast traffic will traverse
D) IGMP must be enabled on all interfaces where multicast sources and receivers are connected

E) All of the above
F) B) and D)

Correct Answer

verifed

verified

B

An administrator will be replacing a campus switching infrastructure with AOS-CX switches that support VSX capabilities. The campus involves a core, as well as multiple access layers. Which feature should the administrator implement to allow both VSX-capable core switches to process traffic sent to the default gateway in the campus VLANs?


A) VRF
B) VRRP
C) IP helper
D) Active gateway

E) A) and D)
F) B) and C)

Correct Answer

verifed

verified

B

An administrator is replacing the current access switches with AOS-CX switches. The access layer switches must authenticate user and networking devices connecting to them. Some devices support no form of authentication, and some support 802.1X. Some ports have a VoIP phone and a PC connected to the same port, where the PC is connected to the data port of the phone and the phone's LAN port is connected to the switch. Which statement is correct about this situation?


A) 802.1X must be configured to work in fallback mode
B) Device fingerprinting is required for authentication
C) The client-limit setting for port access needs to be changed
D) Device mode should be implemented

E) A) and B)
F) A) and C)

Correct Answer

verifed

verified

What is correct regarding the configuration of ACLs on AOS-CX switches?


A) Statements with the log keyword are always processed by the switch CPU.
B) Standard ACLs are used to match on routes when performing route distribution.
C) Wildcard masks are used to match on a range of IP addresses.
D) Numbers 100 through 199 and 2000 through 2999 are used when creating extended ACLs.

E) A) and D)
F) C) and D)

Correct Answer

verifed

verified

Examine the network topology. Examine the network topology.   Company XYZ has two connections to a service provider (ISP1) . Here is the configuration of Router1:   Here is the configuration of Router2:   Based on configuration of Router1 and Router2, which BGP metric is being manipulated? A)  Weight B)  Multiple exit discriminator C)  Local preference D)  AS path length Company XYZ has two connections to a service provider (ISP1) . Here is the configuration of Router1: Examine the network topology.   Company XYZ has two connections to a service provider (ISP1) . Here is the configuration of Router1:   Here is the configuration of Router2:   Based on configuration of Router1 and Router2, which BGP metric is being manipulated? A)  Weight B)  Multiple exit discriminator C)  Local preference D)  AS path length Here is the configuration of Router2: Examine the network topology.   Company XYZ has two connections to a service provider (ISP1) . Here is the configuration of Router1:   Here is the configuration of Router2:   Based on configuration of Router1 and Router2, which BGP metric is being manipulated? A)  Weight B)  Multiple exit discriminator C)  Local preference D)  AS path length Based on configuration of Router1 and Router2, which BGP metric is being manipulated?


A) Weight
B) Multiple exit discriminator
C) Local preference
D) AS path length

E) None of the above
F) C) and D)

Correct Answer

verifed

verified

What is a concept associated with PIM sparse mode (SM) ?


A) Reverts to forwarding when the pruning state times out.
B) Requires periodic joins to maintain the shortest path tree (SPT) .
C) Recommended for use when high bandwidth connections exist.
D) Implements a push content to forward traffic from the multicast source.

E) A) and B)
F) A) and D)

Correct Answer

verifed

verified

An administrator is managing a network comprised of AOS-CX switches deployed at the aggregation layer. The switches are paired in a VSX stack and run the OSPF routing protocol. The administrator is concerned about how long it takes for OSPF to converge when one of the VSX switches has to reboot. What should the administrator to do speed up the OSPF convergence of the switch that is rebooting?


A) Change the VSX ISL link from an OSPF broadcast link point-to-point.
B) Implement graceful restart on the VSX switches and their neighboring OSPF switches.
C) Decrease the VSX initial synchronization timer on the two VSX switches.
D) Define non-backbone areas on the VSX switches as totally stubby areas.

E) C) and D)
F) A) and B)

Correct Answer

verifed

verified

An administrator is managing a pair of core AOS-CX switches configured for VSX. Connected to this core are pairs of aggregation layer AOS-CX switches configured for VSX. OSPF is running between the aggregation and core layers. To speed up OSPF convergence, the administrator has configured BFD between the core and aggregation switches. What is a best practice the administrator should implement to reduce CPU processing on the switches if a BFD neighbor fails?


A) Disable ICMP redirects
B) Implement graceful restart
C) Increase the BFD echo timers
D) Increase the VSX keepalive timer

E) None of the above
F) B) and C)

Correct Answer

verifed

verified

Examine the network topology. Examine the network topology.   The network is configured for OSPF with the following attributes: Core1 and Core2 and ABRs Area 1 has 20 networks in the 10.1.0.0/16 range Area 0 has 10 networks in the 10.0.0.0/16 range Area 2 has 50 networks in the 10.2.0.0/16 range The ASBR is importing a static route into Area 1 Core2 has a summary for Area 2: area 0.0.0.2 range 10.2.0.0/16 type inter-area Here is the OSPF configuration performed on Core1:   Based on the above information, what is correct? A)  ISP 1 is not reachable from any area. B)  Core1 has received one type 5 LSA from the ASBR. C)  Area 0 has 81 routes D)  Area 1 has 23 routes The network is configured for OSPF with the following attributes: Core1 and Core2 and ABRs Area 1 has 20 networks in the 10.1.0.0/16 range Area 0 has 10 networks in the 10.0.0.0/16 range Area 2 has 50 networks in the 10.2.0.0/16 range The ASBR is importing a static route into Area 1 Core2 has a summary for Area 2: area 0.0.0.2 range 10.2.0.0/16 type inter-area Here is the OSPF configuration performed on Core1: Examine the network topology.   The network is configured for OSPF with the following attributes: Core1 and Core2 and ABRs Area 1 has 20 networks in the 10.1.0.0/16 range Area 0 has 10 networks in the 10.0.0.0/16 range Area 2 has 50 networks in the 10.2.0.0/16 range The ASBR is importing a static route into Area 1 Core2 has a summary for Area 2: area 0.0.0.2 range 10.2.0.0/16 type inter-area Here is the OSPF configuration performed on Core1:   Based on the above information, what is correct? A)  ISP 1 is not reachable from any area. B)  Core1 has received one type 5 LSA from the ASBR. C)  Area 0 has 81 routes D)  Area 1 has 23 routes Based on the above information, what is correct?


A) ISP 1 is not reachable from any area.
B) Core1 has received one type 5 LSA from the ASBR.
C) Area 0 has 81 routes
D) Area 1 has 23 routes

E) A) and C)
F) All of the above

Correct Answer

verifed

verified

A company has a third-party AAA server solution. The campus access layer was just upgraded to AOS-CX switches that perform access control with MAC-Auth and 802.1X. The company has an Aruba Mobility Controller (MC) solution for wireless, and they want to leverage the firewall policies on the controllers for the wired traffic. What is correct about how the company should implement a security solution where the wired traffic is processed by the MCs?


A) Implement downloadable user roles with a gateway role defined on the AOS-CX switches
B) Implement local user roles with a gateway role defined on the AOS-CX switches
C) Implement standards-based RADIUS VSAs to pass policy information directly to the AOS-CX switches and MCs
D) Implement downloadable user roles with a device role defined on the AOS-CX switches and MCs

E) A) and B)
F) C) and D)

Correct Answer

verifed

verified

D

Examine the network exhibit. Examine the network exhibit.   A company has a guest implementation for wireless and wired access. Wireless access is implemented through a third-party vendor. The company is concerned about wired guest traffic traversing the same network as the employee traffic. The network administrator has established a GRE tunnel between AOS-CX switches where guests are connected to a routing switch in the DMZ. Which feature should the administrator implement to ensure that the guest traffic is tunneled to the DMZ while the employee traffic is forwarded using OSPF? A)  OSPF route maps using the  set metric  command B)  Policy-based routing (PBR)  C)  User-based tunneling (UBT)  D)  Classifier policies A company has a guest implementation for wireless and wired access. Wireless access is implemented through a third-party vendor. The company is concerned about wired guest traffic traversing the same network as the employee traffic. The network administrator has established a GRE tunnel between AOS-CX switches where guests are connected to a routing switch in the DMZ. Which feature should the administrator implement to ensure that the guest traffic is tunneled to the DMZ while the employee traffic is forwarded using OSPF?


A) OSPF route maps using the "set metric" command
B) Policy-based routing (PBR)
C) User-based tunneling (UBT)
D) Classifier policies

E) B) and C)
F) A) and B)

Correct Answer

verifed

verified

An administrator implements interim accounting for guest users so that ClearPass can track the amount of bandwidth that guests upload and download. Guests that abuse bandwidth consumption should be disconnected from the network. The administrator configures the following on the AOS-CX access switches: An administrator implements interim accounting for guest users so that ClearPass can track the amount of bandwidth that guests upload and download. Guests that abuse bandwidth consumption should be disconnected from the network. The administrator configures the following on the AOS-CX access switches:   After performing this configuration, the administrator notices that guest users that have exceeded the guest bandwidth limit are not being disconnected. Upon further investigation, Access Tracker in ClearPass indicates a disconnect CoA message is being sent to the AOS-CX switch. What is causing this issue? A)  RADIUS change of authorization is not enabled on the AOS-CX switch. B)  Bandwidth consumption of the guests is not being reported by the AOS-CX switch. C)  NTP is not configured on the AOS-CX switch. D)  There is a time discrepancy between the AOS-CX switch and ClearPass. After performing this configuration, the administrator notices that guest users that have exceeded the guest bandwidth limit are not being disconnected. Upon further investigation, Access Tracker in ClearPass indicates a disconnect CoA message is being sent to the AOS-CX switch. What is causing this issue?


A) RADIUS change of authorization is not enabled on the AOS-CX switch.
B) Bandwidth consumption of the guests is not being reported by the AOS-CX switch.
C) NTP is not configured on the AOS-CX switch.
D) There is a time discrepancy between the AOS-CX switch and ClearPass.

E) B) and D)
F) None of the above

Correct Answer

verifed

verified

Examine the commands entered on an AOS-CX switch: Examine the commands entered on an AOS-CX switch:   What is true regarding this configuration for traffic received on interface 100? A)  The default next-hop address supersedes the two preceding next-hop addresses B)  The traffic is always dropped is the next-hop addresses are unreachable C)  The traffic will be routed with the IP routing table entries if the next-hop addresses are unreachable D)  The next-hop address of 1.1.1.1 is overwritten by the next-hop address of 2.2.2.2 What is true regarding this configuration for traffic received on interface 100?


A) The default next-hop address supersedes the two preceding next-hop addresses
B) The traffic is always dropped is the next-hop addresses are unreachable
C) The traffic will be routed with the IP routing table entries if the next-hop addresses are unreachable
D) The next-hop address of 1.1.1.1 is overwritten by the next-hop address of 2.2.2.2

E) A) and C)
F) All of the above

Correct Answer

verifed

verified

An administrator in a company of 349 users has a pair of AOS-CX switches with connections to external networks. Both switches are configured for OSPF. The administrator wants to import external routes on both switches, but assigns different seed metrics to the routes, as well as imports them as external type-1 routes. What is the best way for the administrator to accomplish this?


A) Create a route map with the correct route type and metrics
B) Define the route type and metrics in the OSPF process
C) Create a classifier policy with the correct route type and metrics
D) Define a class and policy map with the correct route type and metrics

E) A) and B)
F) All of the above

Correct Answer

verifed

verified

A company has recently upgraded their campus switching infrastructure with AOS-CX switches. They have implemented 802.1X authentication on access ports where laptop and IOT devices typically connect. An administrator has noticed that for POE devices, the AOS-CX switch ports are delivering the maximum wattage to the port instead of what the device actually needs. Concerned about this waste of electricity, what should the administrator implement to solve this problem?


A) Implement a classifier policy with the correct power definitions
B) Create device profiles with the correct power definitions
C) Enable AAA authentication to exempt LLDP and/or CDP information
D) Globally enable the QoS trust setting for LLDP and/or CDP

E) A) and B)
F) B) and C)

Correct Answer

verifed

verified

Showing 1 - 20 of 98

Related Exams

Show Answer