Question 1:

What are the types of server derivation rules that can be applied to clients? (Select two)


B. Role




Correct Answer: BC

http://www.arubanetworks.com/techdocs/ArubaOS_63_Web_Help/Content/ArubaFrameSty les/Firewall_Roles/User_Role_Assignments.htm

Question 2:

An administrator provisions a Remote AP (RAP) and plans to install it at a branch office. The administrator tries to determine which discovery method should be used for the RAP to discover and connect to the corporate office controller across the internet.

Which method would cause the RAP to fail to discover and connect to the corporate office controller?



C. LMS IP address in the AP Group

D. Aruba Discovery Protocol (ADP)

Correct Answer: C

Question 3:

An administrator implements a WLAN virtual AP (VAP) to authenticate employee access on Aruba Mobility Controller in a master-local topology. However, when testing wireless access from a Windows client the administrator sees the pop-up window show in the exhibit:

What should the administrator do to solve this problem?

A. Add a client certificate from the same CA used to obtain the controller\’s certificate on the Windows client.

B. Add the root certificate for the corresponding controller identity certificate on the windows client.

C. Configure the client\’s certificate as a trusted certificate on the Windows client.

D. Define the controller\’s certificate as a trusted certificate on the windows client.

Correct Answer: A

Question 4:

An administrator works in an Aruba-based network which has a master controller and three local controllers, Centralized licensing is not in use. The administrator notices that no Aps terminate on the master controller and concludes that the roles and firewall policies need to be to created and applied.

Which statement is true about the administrator\’s conclusion?

A. A PEFNG license does not need to be installed on the controller since PEFNG is part of base OS.

B. A PEFNG license should be installed on the master and all three local controllers.

C. A PEFNG license should be installed on only the master controller, since that is where role and firewall policies are created.

D. A PEFNG license should be installed on only the local controllers, since that is where firewall policies are applied.

Correct Answer: B

Question 5:

An administrator sets up a master-local topology. The administrator disables control plane security (CPSec) on all of the controllers and then configures the master and local controllers. Which protocol will be used between these controllers to tunnel management traffic once the inter-controller configuration has been completed?



C. IPSec


Correct Answer: B

Question 6:

Which firewall rules allow a user to initiate ICMP and SSH sessions to other devices? (Select two)

A. user any svc-ssh permit

B. mswitch any svc-icmp permit

C. localip any svc-icmp permit

D. any any svc-icmp permit

E. user user svc-icmp permit

Correct Answer: AD

Question 7:

An administrator supports a wireless network that includes Aruba Mobility controllers and Aruba Aps. The network has on Virtual AP (VAP) profile configured for employees and one VAP profile configured for guests. The network has 200 employees now, but, because of rapid expansion and the move to a brand new campus network, the number of employees is expected to increase to over 500. The administrator wants to continue to use only two VAPs to keep the WLAN implementation simple.

Which feature should the administrator implement for the employee VAP that will allow it to scale to a large number of users?

A. Source NAT

B. VLAN Mobility

C. VLAN Pools

D. IP Mobility

Correct Answer: C

Explanation: http://www.arubanetworks.com/assets/vrd/RAPVRD_version_8.pdf

Question 8:

Examine this controller-configuration:

ip access-list session icmp-traffic any any svc-icmp permit

Which type of alias is used in this configuration?

A. Category

B. Network destination

C. Network service

D. ICMP server

Correct Answer: B

Question 9:

An administrator plans to deploy a Remote AP (RAP) for a new branch office. The AP Group will have one Virtual AP (VAP) profile for guests and one VAP profile for employees. All employee traffic will be sent to the corporate office. The guest traffic should be forwarded directly to the internet from the RAP.

Which RAP operating mode should the administrator configure for the guest VAP?

A. Bridge

B. Tunnel

C. Source NAT

D. Split-Tunnel

Correct Answer: D

Explanation: http://www.airheads.eu/aruba/attachments/aruba/Aruba- VRDs/44/1/Aruba RAP VRD.pdf

Question 10:

Which functions can adaptive Radio Management (ARM) perform on Aruba Aps? (Select two)

A. Use Fast connect to provide quick and seamless roaming

B. Steer clients to the most appropriate radio, based on client capabilities.

C. Discover the best power settings for an AP\’s radio

D. Prevent sticky clients from always connecting to the same AP

E. Determine the best channel for an AP\’s radio

Correct Answer: AC

Question 11:

A company uses Aruba Mobility Controllers and Aruba Aps. The Aps incur a power outage.

Which Aruba feature should be implemented to allow the surrounding Aps to provide wireless coverage for the area of the AP that lost power?

A. Airtime Fairness

B. Adaptive Radio Management

C. Band Balancing

D. High Availability

Correct Answer: B

Question 12:

An administrator installs a new Remote AP (RAP) at a branch office. This RAP will connect to the corporate office\’s Aruba Mobility Controller in the DMZ from across the internet. The administrator will need to make some rule changes on the firewall to allow for this connectivity.

Which protocol or protocols will the administrator have to permit on the firewall for the RAP to successfully connect to and send users wireless 802.1x data to the corporate office?

A. IPSec/NAT-T and PAPI, but not GRE

B. GRE, but not IPSec/NAT-T or PAPI

C. IPSEC/NAT-T, but not GRE or PAPI

D. PAPI and GRE, but not IPSec/NAT-T

Correct Answer: D

Question 13:

Which description of the adaptive Radio Management (ARM) spectrum Load Balancing feature is accurate? (Select two) A. It is enabled by default.

B. It only affects the association of new clients.

C. It is available only on 5GHz radios.

D. It is disabled by default.

E. It is available only on 2.4 GHz radios.

Correct Answer: BD

Explanation: http://www.arubanetworks.com/techdocs/ArubaOS_60/UserGuide/ARM.php

Question 14:

Which description of client match are accurate? (Choose Two)

A. performs spectrum load balancing

B. performs load balancing

C. moves higher traffic devices to adjacent Aps

D. sends QRT frames to neighbor Aps

E. performs enhanced AP reassignment

Correct Answer: BE

Question 15:

Refer to exhibit: What can an administrator conclude about the Aps shown in the exhibit?

A. No evidence has been gathered that shows the Aps attached to the wired corporate network.

B. The reason the Aps are classified as interfering is because they are not Aruba Aps.

C. The reason the Aps are classified as interfering is because they are running 2.4 ghz spectrum.

D. Evidence has been gathered that shows the Aps are connected to the Aruba network

Correct Answer: A

