HPE7-A06 Sample Questions & Answers
Layer 2 switching technologies carry the biggest weight, alongside advanced network-stack analysis, configuration development, resiliency mechanisms, routing topologies, RF functions, security design, AAA configurations, troubleshooting, and performance remediation.
Launch the full HPE7-A06 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Switching · STP Security
During a network audit, a security analyst discovers that switches in the access layer are vulnerable to STP manipulation attacks, such as a rogue device claiming to be the root bridge. To mitigate this, the administrator decides to implement STP protection features on edge ports connected to end-user devices. Which ArubaOS-Switch feature should be configured on these ports to prevent them from becoming STP root or designated ports?
Show answer & explanation
Correct answer: D
Root Guard is the specific feature designed for this purpose. When enabled on a port, it prevents that port from becoming an STP root port. If the port receives a superior BPDU (Bridge Protocol Data Unit), Root Guard will place the port into a 'root-inconsistent' state, effectively ignoring the rogue BPDU and protecting the integrity of the STP topology. BPDU Guard would disable the port entirely, which might be too aggressive, and Loop Guard is for preventing loops when BPDUs are no longer received.
- Question 2Intermediate
Performance Optimization · Broadcast Storm Control
An e-commerce company is experiencing intermittent packet loss and high latency for its critical application servers connected to a VSF stack of Aruba 5406R switches. A network analysis reveals that a high volume of broadcast and unknown unicast traffic from a misconfigured server is flooding a large VLAN, consuming significant switch CPU and link bandwidth. What is the most effective feature to limit the impact of this traffic on the VSF stack?
Show answer & explanation
Correct answer: C
Broadcast-traffic rate limiting (often called storm control) is specifically designed to mitigate this issue. By setting a threshold (e.g., in packets-per-second or percentage of bandwidth) for broadcast traffic on switch ports, the feature can drop excessive broadcast packets, preventing them from overwhelming the switch's CPU and fabric. This directly addresses the root cause of the performance degradation. QoS would help prioritize good traffic but wouldn't stop the flood, and IGMP snooping only affects multicast traffic.
- Question 3Intermediate
Network Resiliency and virtualization · Multi-Chassis Link Aggregation
A consultant is designing a resilient network for a manufacturing plant using ArubaOS-CX switches. The design uses two core switches and multiple access layer switch stacks. To provide redundant uplinks from an access stack to the two core switches, the consultant configures a multi-chassis link aggregation group (MC-LAG). Which underlying technology on the core switches is required to support this MC-LAG configuration?
Show answer & explanation
Correct answer: C
Virtual Switching Extension (VSX) is the ArubaOS-CX technology that enables two separate switches to appear as a single logical switch to downstream devices. This is the foundation for creating a multi-chassis LAG (MC-LAG). The downstream access stack forms a standard LACP LAG, with its physical members connected to each of the VSX-paired core switches. VSX ensures the two core switches coordinate to handle the LAG traffic as a single entity.
- Question 4Advanced
Security · EAP-TLS Troubleshooting
An administrator is configuring 802.1X with EAP-TLS on an ArubaOS-CX switch for wired authentication against a ClearPass server. Corporate clients are issued certificates from an internal Certificate Authority (CA). When a client connects, the authentication fails. The ClearPass access tracker shows the error 'TLS session error'. The switch configuration is correct, and the client has a valid certificate. What is a common cause for this specific error in an EAP-TLS deployment?
Show answer & explanation
Correct answer: B
In EAP-TLS, mutual authentication occurs. The client must trust the server's certificate, and the server must trust the client's. A 'TLS session error' often indicates a failure in establishing this trust. If the RADIUS server certificate presented by ClearPass is not signed by a CA that the client trusts, the client will terminate the TLS handshake, resulting in this error. The client's supplicant must be configured to trust the CA that issued the ClearPass RADIUS certificate.
- Question 5Advanced
Switching · EVPN-VXLAN Control Plane
A large enterprise is designing a campus network using an EVPN-VXLAN fabric with ArubaOS-CX switches. The goal is to provide Layer 2 and Layer 3 segmentation for multiple tenants. Which statement accurately describes the role of the BGP EVPN control plane in this architecture?
Show answer & explanation
Correct answer: C
The primary function of the BGP EVPN control plane is to replace the traditional flood-and-learn mechanism of Ethernet. VTEPs (VXLAN Tunnel Endpoints) use BGP to advertise learned MAC addresses (and optionally IP addresses for ARP suppression) to other VTEPs. This allows for a more scalable and efficient fabric, as unicast traffic can be routed directly to the destination VTEP without prior flooding. Encapsulation is the role of the VXLAN data plane, not the EVPN control plane.
- Question 6Intermediate
Routing · OSPF Adjacency Troubleshooting
A network administrator needs to establish an OSPF adjacency between an ArubaOS-CX switch and a router from another vendor across a point-to-point link. After configuring the interfaces and OSPF process, the adjacency is stuck in the ExStart/Exchange state. A packet capture reveals that the Aruba switch is rejecting the DBD packets from the other router. What is the most likely cause of this issue?
Show answer & explanation
Correct answer: B
An OSPF adjacency getting stuck in the ExStart/Exchange state is a classic symptom of an MTU mismatch. During the DBD exchange, routers send packets with the interface MTU value. If one router sends a DBD packet larger than the other router's interface MTU, the receiving router will drop the packet, and the state will not progress. The ArubaOS-CX switch is likely rejecting the packet because its MTU is smaller than the MTU of the packet being received. Aligning the MTU on both interfaces will resolve the issue.
- Question 7Intermediate
WLAN · Wireless QoS (WMM)
A network engineer is deploying a campus WLAN and needs to ensure that voice traffic from wireless IP phones is prioritized over data traffic from laptops. Both types of traffic will use the same SSID. What is the standard mechanism used to classify and mark traffic from the wireless client to the access point and onto the wired network for QoS treatment?
Show answer & explanation
Correct answer: C
Wi-Fi Multimedia (WMM), based on the IEEE 802.11e standard, is the mechanism for providing QoS over Wi-Fi. It defines four Access Categories (ACs): AC_VO (Voice), AC_VI (Video), AC_BE (Best Effort), and AC_BK (Background). Wireless clients that support WMM classify their traffic into these categories. The access point then uses these categories to prioritize access to the wireless medium and maps them to appropriate wired QoS markings (like CoS or DSCP) for end-to-end prioritization.
- Question 8Beginner
Network Stack · TCP Connection Termination
A systems administrator is analyzing a TCP flow between a client and a server using a packet capture tool. The administrator observes the client sending a packet with the FIN and ACK flags set, followed by the server responding with a packet with only the ACK flag set, and then another server packet with the FIN and ACK flags set. Finally, the client sends a packet with only the ACK flag set. Which process does this sequence of packets represent?
sequenceDiagram participant Client participant Server Client->>Server: FIN, ACK (Client closes) Server-->>Client: ACK (Server acknowledges) Server->>Server: Process remaining data Server->>Client: FIN, ACK (Server closes) Client-->>Server: ACK (Client acknowledges)Show answer & explanation
Correct answer: C
This sequence describes the standard, graceful TCP connection termination, often called a four-way handshake. 1) The client sends a FIN to signal it has no more data. 2) The server ACKs the client's FIN. 3) The server, after finishing its data transmission, sends its own FIN. 4) The client ACKs the server's FIN. This ensures that both sides of the connection have successfully finished sending data before the connection is fully closed.
- Question 9IntermediateSelect 3
Connectivity · Zero Touch Provisioning (ZTP)
An organization wants to simplify the deployment of new ArubaOS-CX switches in its branch offices. The goal is for the switches to automatically download their configuration and firmware from Aruba Central upon being powered on, without any manual intervention at the branch site. Which technologies and services are required to enable this Zero Touch Provisioning (ZTP) process? (Select THREE)
Show answer & explanation
Correct answers: B, C, D
The switch first needs an IP address, which it gets from DHCP. The DHCP server also provides critical information via vendor-specific options (Option 43) or a generic option (Option 60) that directs the switch to the Aruba Central management platform.
Before the switch can be managed, its serial number and MAC address must be added to the company's Aruba Central account. This allows Central to recognize the device when it calls home and assign it to the correct group, which contains the configuration template and firmware policy.
Once the switch receives the Aruba Central information from DHCP, it must be able to resolve the FQDN of the Central server via DNS and have a route to the public internet to establish a connection. Without DNS and internet access, it cannot contact Central to download its configuration.
- Question 10Intermediate
Switching · STP Edge Port Configuration
True or False: The
spanning-tree admin-edge-portcommand on an ArubaOS-Switch is functionally identical to thespanning-tree port-type admin-edgecommand on an ArubaOS-CX switch, as both immediately transition the port to the forwarding state while retaining BPDU protection.Show answer & explanation
Correct answer: A
This statement is true. Both commands serve the same purpose, which is analogous to Cisco's PortFast feature. They designate a port as an edge port that connects to an end device, not another switch. This allows the port to bypass the listening and learning STP states and transition directly to forwarding, speeding up device connectivity. Both implementations also maintain STP protection; if a BPDU is received on the port, it will revert to a normal STP port and go through the standard state transitions to prevent a loop.
Ready for the real thing?
The full HPE7-A06 simulator has every exam-style question, timed mode, and instant scoring.