[Oct-2021] HPE6-A79 Pre-Exam Practice Tests | Exam Questions and Answers for HP ACMX Study Guide
Aruba Certified Mobility Expert Written Exam Certification Sample Questions
NEW QUESTION 21
A joint venture between two companies results in a fully functional WLAN Aruba solution. The network administrator uses the following script to integrate the WLAN solution with two radius servers, radius1 and radius2.
While all users authenticate with [email protected] type of credentials, radius1 has user accounts with the domain name portion.
Which additional configuration is required to authenticate corp1.com users with radius1 and corp2 users with radius2?
- A. Option A
- B. Option D
- C. Option B
- D. Option C
Answer: A
NEW QUESTION 22
A network administrator assists with the migration of a WLAN from a third-party vendor to Aruba in different locations throughout the country. In order to manage the solution from a central point, the network administrator decides to deploy redundant Mobility Masters (MMs) in a datacenter that are reachable through the Internet.
Since not all locations own public IP addresses, the security team is not able to configure strict firewall polices at the datacenter without disrupting some MM to Mobility Controller (MC) communications. They are also concerned about exposing the MMs to unauthorized inbound connection attempts.
What should the network administrator do to ensure the solution is functional and secure?
- A. Block all inbound connections, and instruct the MM to initiate the connection to the MCs.
- B. Install a PEFV license, and configure firewall policies that protect the MM.
- C. Block all ports to the MMs except UDP 500 and 4500.
- D. Deploy an MC at the datacenter as a VPN concentrator.
Answer: C
NEW QUESTION 23
A network administrator has updated the ArubaOS code of a standalone Mobility Controller (MC) that is used for User-Based Tunneling (UBT) to a newer early release. Ever since the MC seems to reject PAPI sessions from the switch with the 10.1.10.10 IP address. Also the controller's prompt is now followed by a star mark: "(MC_VA) [mynode] *#" When opening a support ticket, an Aruba TAC engineer asks the administrator to gather the crash logs and if possible replicate UBT connection attempts from the switch while running packet captures of PAPI traffic on the controller and obtain the PCAP files. The administrator has a PC with Wireshark and TFTP server using the 10.0.20.20 IP address.
What commands must the administrator issue to accomplish these requests? (Choose two.)
- A. Option D
- B. Option B
- C. Option A
- D. Option C
- E. Option E
Answer: B,E
NEW QUESTION 24
Refer to the exhibit.
A network administrator adds a Mobility Controller (MC) in the /mm level and notices that the device does not show up in the managed networks hierarchy. The network administrator accesses the CLI. executes the show switches command, and obtains the output shown in the exhibit.
What is the reason that the MC does not appear as a managed device in the hierarchy?
- A. The network administrator has not moved the device into a group yet.
- B. The digital certificate of the MC is not trusted by the MM.
- C. The IP address of the MC does not match the one that was defined in the MM.
- D. The network administrator added the device using the wrong Pre-Shared Key (PSK).
Answer: C
NEW QUESTION 25
A network administrator is in charge of a Mobility Master (MM) - Mobility Controller (MC) based network security. Recently the Air Monitors detected a Rogue AP in the network and the administrator wants to enable "Tarpit" based wireless containment.
What profile must the administrator enable "tarpit" wireless containment on?
- A. IDS General profile
- B. IDS Unauthorized device profile
- C. IDS DOS profile
- D. IDS profile
Answer: B
NEW QUESTION 26
A company with 50 small coffee shops in a single country requires a single mobility solution that solves connectivity needs at both the main office and branch locations. Coffee shops must be provisioned with local WiFi internet access for customers.
The shops must also have a private WLAN that offers communication to resources at the main office to upload sales, request supplies through a computer system, and make phone calls if needed. In order to simplify network operations, network devices at the coffee shops should be cloud managed.
Which technologies best meet the company needs at the lowest cost?
- A. SD-Branch
- B. BOC with CAPs
- C. IAPVPN
- D. Activate with RAPs
Answer: A
NEW QUESTION 27
An organization owns a fully functional multi-controller Aruba network with a Virtual Mobility Master (VMM) in VLAN20. They have asked a network consultant to deploy a redundant MM on a different server. The solution must offer the lowest convergence time and require no human interaction in case of failure.
The servers host other virtual machines and are connected to different switches that implement ACLs to protect them. The organization grants the network consultant access to the servers only, and appoints a network administrator to assist with the deployment.
What must the network administrator do so the network consultant can successfully deploy the solution? (Choose two.)
- A. Allocate VLAN20 to the second server, and extend it throughout the switches, then reserve one IP address for the second MM and another IP address for its gateway.
- B. Allocate VLAN20 to the second server, and extend it throughout the switches, then reserve one IP address for the second MM and another for the VIP.
- C. Allocate VLAN20 to the second server, and permit routing between them, then reserve one IP address for the second MM and another IP address for its gateway.
- D. Configure an ACL entry that permits UDP 500, TCP 4500, and multicast IP 224.0.0.5.
- E. Configure an ACL entry that permits IP protocol 50, UDP port 500, and multicast IP 224.0.0.18.
Answer: A,D
NEW QUESTION 28
Refer to the exhibit:
A company acquires ten barcode scanners to run inventory tasks. These WiFi devices support WPA2-PSK security only. The network administrator deploys a WLAN named scanners using the configuration shown in the exhibit.
What must the network administrator do next to ensure that the scanner devices successfully connect to their SSID?
- A. Enable L2 Authentication Fail Through.
- B. Add scanner MAC addresses in user derivation rules.
- C. Set internal as the MAC authentication server group.
- D. Add scanner MAC addresses in the internal database.
Answer: D
NEW QUESTION 29
Refer to the exhibit.
A network administrator wants to configure an 802.1x supplicant for a wireless network that includes the following:
* AES encryption
* EAP-MSCHAP v2-based user and machine authentication
* Validation of server certificate in Microsoft Windows 10
The network administrator creates a WLAN profile and selects the change connection settings option. Then the network administrator changes the security type to Microsoft: Protected EAP (PEAP), and enables user and machine authentication under Additional Settings.
What must the network administrator do next to accomplish the task?
- A. Enable server certificate validation under Settings.
- B. Change default RC4 encryption for AES.
- C. Enable user authentication under Settings
- D. Change the security type to Microsoft: Smart Card or other certificate.
Answer: D
NEW QUESTION 30
Refer to the exhibit.
A network engineer deploys two different DHCP pools in an Instant AP (IAP) cluster for WLANs that will have connectivity to a remote site using Aruba IPSec.
Based on the output shown in the exhibit, which IAP-VPN DHCP modes are being used?
- A. local L3 and centralized L2
- B. distributed L3 and centralized L2
- C. local L3 and distributed L2
- D. centralized L3 and distributed L2
Answer: D
NEW QUESTION 31
Refer to the exhibit.
The network administrator must ensure that the configuration will force users to authenticate periodically every eight hours. Which configuration is required to effect this change?
- A. Set the reauth-period to 28800 enable reauthentication in both dotlx and AAA profile.
- B. Set the reauth-period to 28800 enable reauthentication in the AAA profile.
- C. Set the reauth-period to 28800 enable reauthentication in the dotlx profile.
- D. Set the reauth-period to 28800 in the dotlx profile and enable reauthentication in the AAA profile.
Answer: C
NEW QUESTION 32
Refer to the exhibits.


A network administrator has fully deployed a WPA3 based WLAN with 802.1X authentication. Later he defined corp-employee as the default user-role for the 802.1X authentication method in the aaa profile. When testing the setup he realizes the client gets the "guest" role.
What is the reason "corp-employee" user role was not assigned?
- A. The Mobility Master lacks MM-VA licenses; therefore, it shares partial configuration only.
- B. The administrator forgot to enable PEFNG feature set on the Mobility Master.
- C. The administrator forgot to map a dotlx profile to the corp-employee aaa profile.
- D. MC 1 has not received the configuration from the mobility master yet.
Answer: D
NEW QUESTION 33
Refer to the exhibit.
An organization provides WiFi access through a corporate SSID with an Aruba Mobility Master (MM) - Mobility Controller (MC) network that includes PEF functions. The organization wants to have a single firewall policy configured and applied to the employee role.
This policy must allow users to reach Web, FTP, and DNS services, as shown in the exhibit. Other services should be exclusive to other roles. The client NICs should receive IP settings dynamically.
Which policy design meets the organization's requirements while minimizing the number of policy rules?

- A. Option D
- B. Option C
- C. Option A
- D. Option B
Answer: B
NEW QUESTION 34
Refer to the exhibit.
A network administrator has created AAA profile for the corporate VAP. In addition to the regular Radius based authentication, the administrator needs to be able to disconnect the users from either of the two servers that are part of the "Radius" server group.
What must the administrator do next in order to achieve this goal?
- A. Create two new RFC 3576 servers and assign them as the RFC 3576 servers in the AAA profile.
- B. Use the "Radius' server group as the RFC 3576 server in the AAA profile.
- C. Use the "Radius' server group as both the Accounting Server Group and the RFC 3576 server in the AAA profile.
- D. Use the "Radius" server group as the RADIUS Accounting Server Group in the AAA profile.
Answer: C
NEW QUESTION 35
Refer to the exhibit.
A network administrator has recently enabled WMM on the VAP's SSID profile and enabled UCC Skype4B ALG at the Mobility Master level. During testing, some voice and video conference calls were made, and it was concluded that the call quality has dramatically improved. However, end to end information isn't displayed in the call's details. Also, Skype4B app-sharing's performance is poor at times.
What must the administrator do next in order to enable end to end call visibility and QoS correction to app-sharing service?
- A. Increase the app-sharing DSCP value in the Skype4B ALG profile.
- B. Enable the App-sharing ALG profile at both MM and MD hierarchy levels.
- C. Deploy the SDN API Software in the Skype4B Solution and point to the MM.
- D. Enable UCC monitoring on the "default-controller' mgmt.-server profile.
Answer: B
NEW QUESTION 36
A software development company has 764 employees who work from home. The company also has small offices located in different cities throughout the world. During working hours, they use RAPs to connect to a datacenter to upload software code as well as interact with databases.
In the past two month, cabling issues have occurred connection to the 7240XM Mobility Controller (MC) that runs ArubaOS 8 and terminates the RAPs. These RAPs disconnect, affecting the users connected to the RAPs. This also causes problems with code uploads and database synchronizations. Therefore, the company decides to add a second 7240XM controller for redundancy.
How should the network administrator deploy both controllers in order to provide the redundancy while preventing failover events from disconnecting users?
- A. Connect both controllers with common VLANs. and create an HA fast failover group with public addresses in the internet VLAN.
- B. Connect both controllers with common VLANs. and configure LMS/BLMS values equal to public addresses in the internet VLAN.
- C. Connect both controllers with different VLANs. and create an L2-connected cluster using public addresses in the internet VLAN.
- D. Connect both controllers with common VLANs. and create an L2-connected cluster using public addresses in the internet VLAN.
Answer: A
NEW QUESTION 37
Refer to the exhibit.
A network administrator has a Mobility Master (MM) Mobility Controller (MC) architecture along with the MC in the DMZ for terminating RAPs. The network firewall has been provisioned to allow access to the MC in the DMZ for both UDP 500 and 4500. Then he proceeds to provision an AP as shown in the exhibit.
Which additional configuration steps must the administrator to assure RAPs successfully contact the MC? (Choose two.)
- A. Create the RAP1 account in the InternalDB of the MM.
- B. Create an IP local pool and PSK at the device node level.
- C. Create the RAP1 account in the InternalDB of the MC.
- D. Create an IP local pool and PSK at the /mm/mynode level.
- E. Add the RAP1 entry in the CPsec whitelist at the MM level.
Answer: D,E
NEW QUESTION 38
......
HP Exam Practice Test To Gain Brilliante Result: https://www.topexamcollection.com/HPE6-A79-vce-collection.html
Tested Material Used To HPE6-A79: https://drive.google.com/open?id=1YaqCi0cOtCLopFEV5xn_qoGAPKDp0-2K

