HPE6-A88 Sample Questions & Answers
Four domains tie for top billing: network access control basics, the right service configuration, dynamic user segmentation, and server administration, alongside smaller equal shares for ClearPass's architecture, AAA, guest access, and onboarding with posture checks.
Launch the full HPE6-A88 simulator →Showing 10 of 20 free samples.
- Question 1Beginner
Define HPE Aruba Networking ClearPass Server Management · External Authentication Sources
During a ClearPass deployment, an administrator needs to integrate with an external SQL database to authorize users based on a 'status' column in a customer table. Which component in ClearPass is used to define the connection settings and queries for this external database?
Show answer & explanation
Correct answer: B
Authentication Sources are used to connect ClearPass to external identity stores like Active Directory, LDAP, and generic SQL databases. Within the Authentication Source configuration for a SQL DB, an administrator defines the server connection details, database name, and the specific SQL queries to be used for authentication and fetching attributes.
- Question 2Intermediate
Define Guest Access Management and Captive Portal · Guest Access Workflows
A retail company wants to provide sponsored guest Wi-Fi access in its stores. A store manager must approve each guest's request before access is granted. Which ClearPass Guest workflow should be configured to meet this requirement?
Show answer & explanation
Correct answer: B
The 'Self-Registration with sponsor confirmation' workflow is specifically designed for this scenario. A guest fills out the registration form, and an approval request is sent to a designated sponsor (the store manager). The guest account remains disabled until the sponsor approves the request via email or by logging into ClearPass.
- Question 3Beginner
Identify HPE Aruba Networking ClearPass Modules and System Components · ClearPass Cluster Roles
True or False: In a ClearPass cluster, the Publisher is the only node that can have read/write access to the configuration database. All Subscribers have a read-only copy.
Show answer & explanation
Correct answer: A
This statement is true. The fundamental architecture of a ClearPass cluster is a single-master model where the Publisher holds the master configuration database. All administrative changes must be made on the Publisher, which then replicates those changes to all Subscriber nodes.
- Question 4Advanced
Identify Dynamic User Roles and Segmentation · Dynamic Segmentation Integration
An organization is using Aruba Dynamic Segmentation. A user authenticates via 802.1X, and ClearPass assigns them the 'Finance' role. Which RADIUS attribute does ClearPass send to the Aruba switch or gateway to instruct it to apply the corresponding 'Finance' user role policy?
Show answer & explanation
Correct answer: C
The 'Aruba-User-Role' is a specific Aruba Vendor-Specific Attribute (VSA) used for this purpose. When ClearPass sends a RADIUS Access-Accept message, it includes this attribute with the value set to the name of the role (e.g., 'Finance'). The Aruba switch or gateway receives this and applies its locally configured policy for that user role to the client's session.
- Question 5Intermediate
Define HPE Aruba Networking ClearPass Server Management · System Updates and Maintenance
A system administrator needs to update the Posture Signature and Windows Hotfixes data files on a ClearPass server that is in an air-gapped network with no internet connectivity. What is the correct procedure to perform this update?
Show answer & explanation
Correct answer: C
For air-gapped systems, the correct procedure is to download the necessary update files from the Aruba support portal onto a machine with internet access. The files are then transferred to the ClearPass server and imported manually through the UI at Administration > Agents and Software Updates > Software Updates. This allows offline servers to stay current with posture and other subscription data.
- Question 6Advanced
Define HPE Aruba Networking ClearPass Server Management · API Integration
A developer needs to create an external application that can programmatically disable a user's network access via ClearPass in an emergency. Which ClearPass component should the developer interact with to achieve this?
Show answer & explanation
Correct answer: C
The ClearPass REST API is the correct tool for programmatic interaction. The developer would create an API client in ClearPass, obtain an access token, and then use HTTP requests (e.g., a PATCH request to the Endpoint or GuestUser entity) to change an attribute that an enforcement policy can act upon to deny access. For active sessions, a RADIUS Change of Authorization (CoA) could also be triggered via the API.
- Question 7Beginner
Identify Service Configuration and Selection · Enforcement Policies and Profiles
What is the primary function of an Enforcement Policy in ClearPass?
Show answer & explanation
Correct answer: C
An Enforcement Policy acts as a decision-making engine. It contains a set of rules that evaluate attributes from the authentication session (such as user role, device type, posture status). Based on which rule is matched, it selects the appropriate Enforcement Profile, which contains the specific access control actions (like assigning a VLAN or user role) to be sent back to the NAD.
- Question 8Intermediate
Define Onboard Provisioning and Posture Attribute Enforcement · Troubleshooting Onboard
A company is using ClearPass Onboard to provision certificates for BYOD devices. After a successful onboarding process, a user's Android device is unable to connect to the secure 802.1X SSID. A packet capture shows the device is not presenting a client certificate. What is a common cause for this issue with Android devices?
Show answer & explanation
Correct answer: B
Unlike iOS or Windows, Android requires a separate step to install the network profile after the certificate is provisioned. If the user only installs the certificate but fails to install the associated network (Wi-Fi) profile, the device will not know to use that certificate for the specific SSID. This is a common point of failure in the Android onboarding workflow.
- Question 9Intermediate
Identify Service Configuration and Selection · Troubleshooting Enforcement Policies
A user successfully authenticates to the network but is placed in a quarantine VLAN. The Access Tracker shows that the user was assigned the 'HEALTHY' posture token, but the Enforcement Policy applied the '[Quarantine Profile]'. Review the following Enforcement Policy rules. What is the most likely cause of the issue?
- Rule 1: IF (Tips:Role EQUALS [User Authenticated]) AND (Tips:Posture EQUALS HEALTHY) -> THEN -> [Allow Access Profile]
- Rule 2: IF (Tips:Role EQUALS [User Authenticated]) -> THEN -> [Quarantine Profile]
- Default Profile: [Deny Access Profile]
Show answer & explanation
Correct answer: C
Enforcement policies are evaluated from top to bottom. If the evaluation mode is NOT set to 'First match', ClearPass will evaluate all rules and apply the profiles from all matching rules. Since the user is authenticated, they match both Rule 1 and Rule 2. When multiple profiles are returned, the NAD's behavior can be unpredictable, but often the last or a combination of attributes is applied, leading to incorrect access. The fix is to reorder the rules (most specific first) or set the evaluation mode to 'First Match'.
- Question 10IntermediateSelect 3
Identify Dynamic User Roles and Segmentation · Device Profiling Methods
Which of the following are valid endpoint profiling collectors in ClearPass? (Select THREE)
Show answer & explanation
Correct answers: B, C, D
Ready for the real thing?
The full HPE6-A88 simulator has every exam-style question, timed mode, and instant scoring.