Filters
Question type

Study Flashcards

A network engineer is using NetEdit to manage AOS-CX switches. The engineer notices that a lot of third-party VoIP phones are showing up in the NetEdit topology. The engineer deletes these, but they are automatically rediscovered by NetEdit and added back in. What should the administrator do to solve this problem?


A) Change the VoIP phone SNMP community string to something unknown by NetEdit
B) Disable LLDP globally on the AOS-CX switches where phones are connected
C) Disable SSH access on all the VoIP phones
D) Disable the RESTful API on all the VoIP phones

E) A) and D)
F) A) and C)

Correct Answer

verifed

verified

Examine the network exhibit: Examine the network exhibit:   The ACL configuration defined on Core-1 is as follows:   If telnet was being used, which device connection would be permitted and functional in both directions? (Choose two.)  A)  Client 3 to Client 2 B)  Client 1 to Client 2 C)  Server 2 to Client 2 D)  Server 1 to Client 1 E)  Client 1 to Client 3 The ACL configuration defined on Core-1 is as follows: Examine the network exhibit:   The ACL configuration defined on Core-1 is as follows:   If telnet was being used, which device connection would be permitted and functional in both directions? (Choose two.)  A)  Client 3 to Client 2 B)  Client 1 to Client 2 C)  Server 2 to Client 2 D)  Server 1 to Client 1 E)  Client 1 to Client 3 If telnet was being used, which device connection would be permitted and functional in both directions? (Choose two.)


A) Client 3 to Client 2
B) Client 1 to Client 2
C) Server 2 to Client 2
D) Server 1 to Client 1
E) Client 1 to Client 3

F) None of the above
G) B) and D)

Correct Answer

verifed

verified

A network administrator is installing NetEdit. In order for NetEdit to manage the AOS-CX switches in the network, what must be defined on the AOS-CX switches? (Choose two.)


A) Enabling telnet
B) Defining an admin user password
C) Defining the https user-group
D) Enabling the RESTful API for read and write access
E) Enabling SFTP

F) None of the above
G) D) and E)

Correct Answer

verifed

verified

A network engineer is examining NAE graphs from the Dashboard but notices that the time shown in the graph does not represent the current time. The engineer verifies that the AOS-CX switch is configured for NTP and is successfully synchronized. What should be done to fix this issue?


A) Ensure the engineer's web browser is configured for the same timezone as the AOS-CX switch
B) Ensure the engineer's PC is synchronized to the same NTP server as the AOS-CX switch
C) Ensure NetEdit and the AOS-CX switch are synchronized to the same NTP server
D) Enable trust settings for the AOS-CX switch's SSL certificate

E) B) and D)
F) A) and B)

Correct Answer

verifed

verified

A network administrator wants to replace older access layer switches with AOS-CX 6300 switches. Which virtual switching technology can the administrator implement with this solution?


A) Both VSF and VSX
B) Only Backplane stacking
C) Only VSF
D) Only VSX

E) C) and D)
F) A) and D)

Correct Answer

verifed

verified

An administrator of a large campus network needs a solution that will provide root cause analytics to quickly identify problems so that they can quickly be fixed. Which AOS-CX switch feature should the administrator utilize to help with root cause analytics?


A) NAE
B) VoQ
C) NetEdit
D) VSX

E) None of the above
F) B) and D)

Correct Answer

verifed

verified

A company requires access by all users, guests, and employees to be authenticated. Employees will be authenticated using 802.1X, whereas guests will be authenticated using captive portal. Which type of authentication must be configured on an AOS-CX switch ports where both guests and employees connect?


A) Both 802.1X and captive portal
B) 802.1X only
C) Both 802.1X and MAC-Auth
D) 802.1X, captive portal, and MAC-Auth

E) B) and C)
F) C) and D)

Correct Answer

verifed

verified

A network engineer is having a problem adding a custom-written script to an AOS-CX switch's NAE GUI. The script was written in Python and was successfully added on other AOS-CX switches. The engineer examines the following items from the CLI of the switch: A network engineer is having a problem adding a custom-written script to an AOS-CX switch's NAE GUI. The script was written in Python and was successfully added on other AOS-CX switches. The engineer examines the following items from the CLI of the switch:   What should the engineer perform to fix this issue? A)  Install the script's signature before installing the new script B)  Ensure the engineer's desktop and the AOS-CX switch are synchronized to the same NTP server C)  Enable trust settings for the AOS-CX switch's SSL certificate D)  Remove a script that is no longer used before installing the new script What should the engineer perform to fix this issue?


A) Install the script's signature before installing the new script
B) Ensure the engineer's desktop and the AOS-CX switch are synchronized to the same NTP server
C) Enable trust settings for the AOS-CX switch's SSL certificate
D) Remove a script that is no longer used before installing the new script

E) C) and D)
F) All of the above

Correct Answer

verifed

verified

How does PIM build the IP multicast routing table to route traffic between a multicast source and one or more receivers?


A) It uses the unicast routing table and reverse path forwarding (RPF)
B) It uses IGMP and calculates a shortest path tree (SPT)
C) It uses the shortest path first (SPF) algorithm derived from link state protocols
D) It uses the Bellman-Ford algorithm derived from distance vector protocols

E) A) and D)
F) C) and D)

Correct Answer

verifed

verified

An administrator wants to track what configuration changes were made on a switch. What should the administrator implement to see the configuration changes on an AOS-CX switch?


A) AAA authorization
B) Network Analysis Engine (NAE)
C) AAA authentication
D) VSX synchronization logging

E) A) and C)
F) C) and D)

Correct Answer

verifed

verified

An administrator is concerned about the security of the control plane connection between an AOS-CX switch and an Aruba Mobility Controller (MC) when implementing user-based tunneling. How should the administrator protect this traffic?


A) IPSec with a digital certificate
B) GRE with a pre-shared key
C) PAPI with an MD5 pre-shared key
D) IPSec with a pre-shared key

E) B) and D)
F) B) and C)

Correct Answer

verifed

verified

Examine the output from an AOS-CX switch implementing a dynamic segmentation solution involving downloadable user roles: Switch# show port-access role clearpass Role information: Name : icx aruba dur_employee-3044-2 Type : clearpass Status: failed, parsing_failed     Reauthentication Period        :     Authentication Mode            :     Session Timeout                : The downloadable user roles are not being downloaded to the AOS-CX switch. Based on the above output, what is the problem?


A) The certificate that ClearPass uses in invalid
B) The AOS-CX switch does not have the ClearPass certificate involved
C) DNS fails to resolve the ClearPass server's FQDN
D) There is a date/time issue between the ClearPass server and the switch

E) All of the above
F) A) and B)

Correct Answer

verifed

verified

The company has just upgraded their access layer switches with AOS-CX switches and implemented an AAA solution with ClearPass. The company has become concerned about what actually connects to the user ports on the access layer switch, Therefore, the company is implementing 802.1X authentication on the AOS-CX switches. An administrator has globally enabled 802.1X, and has enabled it on all the access ports connected to user devices, including VoIP phones, security cameras, and wireless Aruba IAPs. Wireless users are complaining that they successfully authenticate to the IAPs; however, they do not have access to network resources. Previously, this worked before 802.1X was implemented on the AOS-CX switches. What should the company do to solve this problem?


A) Implement device-based mode on the IAP-connected AOS-CX switch ports.
B) Implement local user roles and local forwarding on the AOS-CX switches.
C) Implement downloadable user roles and user-based tunneling (UBT) on the AOS-CX switches.
D) Implement AAA RADIUS change of authorization on the AOS-CX switches.

E) A) and B)
F) All of the above

Correct Answer

verifed

verified

Examine the network topology. Examine the network topology.   The network is configured for OSPF with the following attributes: Core1 and Core2 and ABRs Area 1 has 20 networks in the 10.1.0.0/16 range Area 0 has 10 networks in the 10.0.0.0/16 range Area 2 has 50 networks in the 10.2.0.0/16 range The ASBR is importing a static route into Area 1 Core2 has a summary for Area 2: area 0.0.0.2 range 10.2.0.0/16 type inter-area Here is the OSPF configuration performed on Core1:   Based on the above information, what is correct? A)  Area 0 has 13 routes B)  Core1 has no OSPF routes C)  Core1 has received one LSA Type 5 from the ASBR D)  Area 1 has 23 routes The network is configured for OSPF with the following attributes: Core1 and Core2 and ABRs Area 1 has 20 networks in the 10.1.0.0/16 range Area 0 has 10 networks in the 10.0.0.0/16 range Area 2 has 50 networks in the 10.2.0.0/16 range The ASBR is importing a static route into Area 1 Core2 has a summary for Area 2: area 0.0.0.2 range 10.2.0.0/16 type inter-area Here is the OSPF configuration performed on Core1: Examine the network topology.   The network is configured for OSPF with the following attributes: Core1 and Core2 and ABRs Area 1 has 20 networks in the 10.1.0.0/16 range Area 0 has 10 networks in the 10.0.0.0/16 range Area 2 has 50 networks in the 10.2.0.0/16 range The ASBR is importing a static route into Area 1 Core2 has a summary for Area 2: area 0.0.0.2 range 10.2.0.0/16 type inter-area Here is the OSPF configuration performed on Core1:   Based on the above information, what is correct? A)  Area 0 has 13 routes B)  Core1 has no OSPF routes C)  Core1 has received one LSA Type 5 from the ASBR D)  Area 1 has 23 routes Based on the above information, what is correct?


A) Area 0 has 13 routes
B) Core1 has no OSPF routes
C) Core1 has received one LSA Type 5 from the ASBR
D) Area 1 has 23 routes

E) None of the above
F) All of the above

Correct Answer

verifed

verified

Which concept is implemented using Aruba's dynamic segmentation?


A) Root of trust
B) Device fingerprinting
C) Zero Touch Provisioning
D) Colorless port

E) A) and B)
F) A) and C)

Correct Answer

verifed

verified

An administrator is implementing a downloadable user role solution involving AOS-CX switches. The AAA solution and the AOS-CX switches can successfully authenticate users; however, the role information fails to download to the switches. What policy should be added to an intermediate firewall to allow the downloadable role function to succeed?


A) Allow TCP 443
B) Allow UDP 1811
C) Allow UDP 8211
D) Allow TCP 22

E) A) and B)
F) B) and C)

Correct Answer

verifed

verified

What are best practices when implementing VSX on AOS-CX switches? (Choose two.)


A) The ISL lag should use the default MTU size.
B) Timers should be left at their default values.
C) The default system MAC addresses should be used.
D) The keepalive connection should use a direct layer-3 connection.
E) The ISL lag should use at least 10GbE links or faster.

F) None of the above
G) B) and C)

Correct Answer

verifed

verified

Which option correctly defines how to identify a VLAN as a voice VLAN on an AOS-CX switch?


A) Switch(config) # port-access lldp-group <LLDP-group-name> Switch(config-lldp-group) # vlan <VLAN-ID>
B) Switch(config) # port-access role <role-name> Switch(config-pa-role) # vlan access <VLAN-ID>
C) Switch(config) # vlan <VLAN-ID> Switch(config-vlan-<VLAN-ID>) # voice
D) Switch(config) # vlan <VLAN-ID> voice

E) A) and B)
F) B) and C)

Correct Answer

verifed

verified

Showing 81 - 98 of 98

Related Exams

Show Answer