HPE6-A84 Sample Questions & Answers
Analyzing logs and alerts at an expert level, remediating security risk, and tuning alerts carry the biggest weight, alongside the zero trust mindset, forensic techniques, ClearPass's architecture, enterprise firewall ACL design, and client-to-site access.
Launch the full HPE6-A84 simulator →Showing 8 of 17 free samples.
- Question 1Advanced
Security Architecture & Policy · Dynamic Segmentation
A large enterprise is deploying User-Based Tunneling (UBT) using AOS-CX switches at the edge and a cluster of Aruba Gateways at the core. The security architect mandates that all guest traffic must be tunneled to the DMZ gateways, while corporate traffic is tunneled to the Data Center gateways. Both traffic types originate from the same physical switch ports. Which architectural component allows the AOS-CX switch to direct traffic to different gateway clusters based on the user role derived from ClearPass?
Show answer & explanation
Correct answer: D
In advanced UBT deployments on AOS-CX, you can define multiple UBT zones. Each zone points to a different Primary Controller (Gateway Cluster). By mapping the user role to a specific UBT zone ID, the switch knows which tunnel destination to use for that specific user session.
- Question 2Intermediate
ClearPass Policy Manager · Enforcement Profiles
You are troubleshooting a Downloadable User Role (DUR) failure on an AOS-CX switch. The switch successfully authenticates the user via ClearPass, but the role fails to download, placing the port in a generic reject state. You verify that the switch has the correct ClearPass root CA certificate installed. A packet capture reveals the switch is attempting to contact ClearPass on port 443 but receiving a reset. Which configuration on the ClearPass Policy Manager is most likely missing?
Show answer & explanation
Correct answer: D
When AOS-CX switches download a DUR, they often use the IP address returned in the RADIUS response to initiate the HTTPS connection. If the ClearPass HTTPS server certificate does not contain this IP address in the SAN field, the TLS handshake may fail or be rejected depending on strict validation settings, or the connection might be reset if the service is unreachable due to certificate validation errors on the client side.
- Question 3Advanced
ClearPass Policy Manager · OnGuard
An organization requires a highly secure authentication flow for their finance department. The requirements are:
- Users must authenticate using EAP-TLS with a machine certificate.
- The machine must pass a health check (OnGuard) before full access is granted.
- If the health check is pending, the user sits in a quarantine role.
Which combination of ClearPass Service configurations best achieves this workflow using a single service where possible?
Show answer & explanation
Correct answer: C
OnGuard agents communicate via HTTP/HTTPS (WebAuth) to ClearPass, while the network access is RADIUS (802.1X). These are distinct flows. The WebAuth service updates the endpoint's posture status. The 802.1X service then checks this cached endpoint attribute (Posture Status) during re-authentication/CoA to determine the enforcement profile.
- Question 4Intermediate
ClearPass Policy Manager · Profiling
A network administrator needs to implement a 'Headless Device' onboarding process for printers and IoT devices that do not support 802.1X. The goal is to profile them accurately and allow them onto the network only if they match specific device fingerprints. Which set of ClearPass features should be combined to achieve this most securely?
Show answer & explanation
Correct answer: D
The standard flow for unknown IoT devices is: 1. Device connects via MAC Auth. 2. If unknown, allow temporarily with limited access (or use Allow-All-Mac-Auth). 3. ClearPass collects DHCP fingerprints/SPAN data. 4. Once profiled, ClearPass sends a Change of Authorization (CoA) to bounce the port. 5. Device reconnects, matches the new specific Profile/Attribute in the policy, and gets full access.
- Question 5Intermediate
Network Access Control · CoA
Refer to the diagram below regarding an authentication flow.
Which ClearPass Policy Manager service type is specifically designed to handle the 'Authorization' phase shown in the sequence where the NAD requests permission changes for an active session?
Show answer & explanation
Correct answer: C
The diagram depicts a sequence where the Policy Server updates the status of an active session. This mechanism is Change of Authorization (CoA), defined in RFC 3576 (or RFC 5176). ClearPass uses this to send unsolicited messages to the NAD to disconnect a user or change their authorization attributes (e.g., VLAN or ACL) without a full re-authentication.
- Question 6Beginner
Firewall Policies · Rule Ordering
You are configuring a Policy Enforcement Firewall (PEF) role on an Aruba Mobility Controller. You want to allow users to access the corporate intranet (10.0.0.0/8) but strictly block access to the finance subnet (10.10.10.0/24) and the HR subnet (10.10.20.0/24). The policy must process rules from top to bottom. Which rule order is correct?
Show answer & explanation
Correct answer: B
Firewall rules are processed sequentially. You must place the more specific 'Deny' rules for the Finance and HR subnets BEFORE the broader 'Permit' rule for the 10.0.0.0/8 network. If the Permit rule were first, traffic to Finance would match 10.0.0.0/8 and be allowed before reaching the deny rule.
- Question 7Intermediate
Threat Detection & Response · WIPS
An administrator observes that valid corporate clients are occasionally being contained by the Aruba WIPS (Wireless Intrusion Prevention System) when they roam near the building perimeter. The WIPS policy is set to contain 'Rogue' APs. Upon investigation, the 'Rogue' APs are actually neighbors' APs that corporate clients are accidentally associating with. What is the most effective way to prevent corporate clients from connecting to these neighbors without aggressively attacking the neighbor's infrastructure?
flowchart LR Client((Corp Client)) -->|Accidental Assoc| NeighborAP[Neighbor AP] WIPS[Aruba WIPS] -->|Deauth?| Client style WIPS fill:#f9f,stroke:#333Show answer & explanation
Correct answer: A
Aruba WIPS has a feature often called 'Client Containment' or 'Protect SSO' which specifically targets the valid corporate client's MAC address to disconnect it from an external AP (Rogue or Interfering). This avoids sending de-auth frames to the Neighbor AP itself (which could be illegal or disruptive to neighbors), focusing only on enforcing the policy that 'My clients must not connect to external APs'.
- Question 8Intermediate
ClearPass Policy Manager · Clustering
When implementing a ClearPass Cluster for a global organization with three regions (Americas, EMEA, APAC), what is the recommended latency threshold between the Publisher and any Subscriber to ensure reliable database replication and cluster health?
Show answer & explanation
Correct answer: C
Aruba recommends a maximum Round Trip Time (RTT) latency of 200ms between the Publisher and Subscribers in a ClearPass cluster. Higher latency can lead to database replication issues, split-brain scenarios, or slow administrative interface performance.
Ready for the real thing?
The full HPE6-A84 simulator has every exam-style question, timed mode, and instant scoring.