Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

HPE6-A68 Aruba Certified ClearPass Professional (ACCP) 6.7 Questions and Answers

Questions 4

A university wants to deploy ClearPass with the Guest module. The university has two types that need to use web login authentication. The first type of users are students whose accounts are in an Active Directory server. The second type of users are friends of students who need to self-register to access the network.

How should the service be set up in the Policy Manager for this network?

Options:

A.

Guest User Repository and Active Directory server both as authentication sources

B.

Active Directory server as the authentication source, and Guest User Repository as the authorization source

C.

Guest User Repository as the authentication source, and Guest User Repository and Active Directory server as authorization sources

D.

Either the Guest User Repository or Active Directory server should be the single authentication source

E.

Guest User Repository as the authentication source and the Active Directory server as the authorization source

Buy Now
Questions 5

Refer to the exhibit.

HPE6-A68 Question 5

In the Aruba RADIUS dictionary shown, what is the purpose of the RADIUS attributes?

In the Aruba RADIUS dictionary shown, what is the purpose of the RADIUS attributes?

Options:

A.

to send information via RADIUS packets to Aruba NADs

B.

to gather and send Aruba NAD information to ClearPass

C.

to send information via RADIUS packets to clients

D.

to gather information about Aruba NADs for ClearPass

E.

to send CoA packets from ClearPass to the Aruba NAD

Buy Now
Questions 6

Refer to the exhibit.

HPE6-A68 Question 6

A customer wants to enable Publisher redundancy.

Based on the network topology diagram shown, which node should the network administrator configure as the standby Publisher for the Publisher in the main data center?

Options:

A.

Subscriber in the main data center

B.

Publisher in the regional office

C.

Any of the other three Publishers

D.

Publisher in the mid-size branch

E.

Publisher in the DMZ

Buy Now
Questions 7

Which licenses are included in the built-in Starter kit for ClearPass?

Options:

A.

10 ClearPass Guest licenses, 10 ClearPass Onguard licenses and 10 ClearPass Onboard licenses

B.

25 ClearPass Profiler licenses

C.

25 ClearPass Enterprise licenses

D.

10 ClearPass Enterprise licenses

E.

25 ClearPass Redundancy licenses

Buy Now
Questions 8

What is the certificate format PKCS #7, or .p7b, used for?

Options:

A.

Certificate Signing Request

B.

Binary encoded X.509 certificate

C.

Binary encoded X.509 certificate with public key

D.

Certificate with an encrypted private key

E.

Certificate chain

Buy Now
Questions 9

ClearPass and a wired switch are configured for 802.1x authentication with RADIUS CoA (RFC 3576) on UDP port 3799. This port has been blocked by a firewall between the wired switch and ClearPass.

What will be the outcome of this state?

Options:

A.

RADIUS Authentications will fail because the wired switch will not be able to reach the ClearPass server.

B.

During RADIUS Authentication, certificate exchange between the wired switch and ClearPass will fail.

C.

RADIUS Authentications will timeout because the wired switch will not be able to reach the ClearPass server.

D.

RADIUS Authentication will succeed, but Post-Authentication Disconnect-Requests from ClearPass to the wired switch will not be delivered.

E.

RADIUS Authentication will succeed, but RADIUS Access-Accept messages from ClearPass to the wired switch for Change of Role will not be delivered.

Buy Now
Questions 10

Refer to the exhibit.

HPE6-A68 Question 10

Based on the Enforcement Policy configuration shown, when a user with Role Remote Worker connects to the network and the posture token assigned is quarantine, which Enforcement Profile will be applied?

Options:

A.

RestrictedACL

B.

Remote Employee ACL

C.

[Deny Access Profile]

D.

EMPLOYEE_VLAN

E.

HR VLAN

Buy Now
Questions 11

Which IP address should be set as the DHCP relay on an Aruba Controller for device fingerprinting on ClearPass?

Options:

A.

DHCP server IP

B.

Active Directory IP

C.

Switch IP

D.

Microsoft NPS server IP

E.

ClearPass server IP

Buy Now
Questions 12

Which settings need to be validated for a successful EAP-TLS authentication? (Select two.)

Options:

A.

Username and Password

B.

Pre-shared key

C.

WPA2-PSK

D.

Server Certificate

E.

Client Certificate

Buy Now
Questions 13

Refer to the exhibit.

HPE6-A68 Question 13

An AD user’s department attribute is configured as “HR”. The user connects on Monday using an Android phone to an Aruba Controller that belongs to the Device Group Remote NAD.

Which roles are assigned to the user in ClearPass? (Select two.)

Options:

A.

Executive

B.

iOS Device

C.

Vendor

D.

Remote Employee

E.

HR Local

Buy Now
Questions 14

Refer to the exhibit.

HPE6-A68 Question 14

An Enforcement Profile has been created in the Policy Manager as shown.

Which action will ClearPass take based on the Enforcement Profile?

Options:

A.

It will send the Session-Timeout attribute in the RADIUS Access-Request packet to the NAD and the NAD will end the user’s session after 600 seconds.

B.

It will send the Session-Timeout attribute in the RADIUS Access-Accept packet to the User and the user’s session will be terminated after 600 seconds.

C.

It will count down 600 seconds and send a RADUIS CoA message to the NAD to end the user’s session after this time is up.

D.

It will count down 600 seconds and send a RADUIUS CoA message to the user to end the user’s session after this time is up.

E.

It will send the session –Timeout attribute in the RADIUS Access-Accept packet to the NAD and the NAD will end the user’s session after 600 seconds.

Buy Now
Questions 15

A customer wants all guests who access a company’s guest network to have their accounts approved by the receptionist, before they are given access to the network.

How should the network administrator set this up in ClearPass? (Select two.)

Options:

A.

Enable sponsor approval confirmation in Receipt actions.

B.

Configure SMTP messaging in the Policy Manager.

C.

Configure a MAC caching service in the Policy Manager.

D.

Configure a MAC auth service in the Policy Manager.

E.

Enable sponsor approval in the captive portal authentication profile on the NAD.

Buy Now
Questions 16

A bank would like to deploy ClearPass Guest with web login authentication so that their customers can selfregister on the network to get network access when they have meetings with bank employees. However, they’re concerned about security.

What is true? (Choose three.)

Options:

A.

If HTTPS is used for the web login page, after authentication is completed guest Internet traffic will all be encrypted as well.

B.

During web login authentication, if HTTPS is used for the web login page, guest credentials will be

encrypted.

C.

After authentication, an IPSEC VPN on the guest’s client be used to encrypt Internet traffic.

D.

HTTPS should never be used for Web Login Page authentication.

E.

If HTTPS is used for the web login page, after authentication is completed some guest Internet traffic may be unencrypted.

Buy Now
Questions 17

Which authentication protocols can be used for authenticating Windows clients that are Onboarded? (Select two.)

Options:

A.

EAP-GTC

B.

PAP

C.

EAP-TLS

D.

CHAP

E.

PEAP with MSCHAPv2

Buy Now
Questions 18

Which authorization servers are supported by ClearPass? (Select two.)

Options:

A.

Aruba Controller

B.

LDAP server

C.

Cisco Controller

D.

Active Directory

E.

Aruba Mobility Access Switch

Buy Now
Questions 19

Which devices support Apple over-the-air provisioning? (Select two.)

Options:

A.

IOS 5

B.

Laptop running Mac OS X 10.8

C.

Laptop running Mac OS X 10.6

D.

Android 2.2

E.

Windows XP

Buy Now
Questions 20

Refer to the exhibit.

HPE6-A68 Question 20

Based on the Attribute configuration shown, which statement accurately describes the status of attribute values?

Options:

A.

Only the attribute values of department and memberOf can be used in role mapping policies.

B.

The attribute values of department, title, memberOf, telephoneNumber, and mail are directly applied as ClearPass.

C.

Only the attribute value of company can be used in role mapping policies, not the other attributes.

D.

The attribute values of department and memberOf are directly applied as ClearPass roles.

E.

Only the attribute values of title, telephoneNumber, and mail can be used in role mapping policies.

Buy Now
Questions 21

An administrator enabled the Pre-auth check for their guest self-registration.

At what stage in the registration process in this check performed?

Options:

A.

after the user clicks the login button and after the NAD sends an authentication request

B.

after the user self-registers but before the user logs in

C.

after the user clicks the login button but before the NAD sends an authentication request

D.

when a user is re-authenticating to the network

E.

before the user self-registers

Buy Now
Questions 22

When a third party Mobile Device Management server is integrated with ClearPass, where is the endpoint information from the MDM server stored in ClearPass?

Options:

A.

Endpoints repository

B.

Onboard Device repository

C.

MDM repository

D.

Guest User repository

E.

Local User repository

Buy Now
Questions 23

Refer to the exhibit.

HPE6-A68 Question 23

A guest connects to the Guest SSID and authenticates successfully using the guest.php web login page.

Based on the MAC Caching service information shown, which statement about the guests’ MAC address is accurate?

Options:

A.

It will be visible in the Guest User Repository with Unknown Status

B.

It will be deleted from the Endpoint table.

C.

It will be visible in the Guest User Repository with Known Status.

D.

It will be visible in the Endpoints table with Known Status.

E.

It will be visible in the Endpoints table with Unknown Status.

Buy Now
Questions 24

A hotel chain deployed ClearPass Guest. When hotel guests connect to the Guest SSID, launch a web browser and enter the address www.google.com, they are unable to immediately see the web login page.

What are the likely causes of this? (Select two.)

Options:

A.

The ClearPass server has a trusted server certificate issued by Verisign.

B.

The ClearPass server has an untrusted server certificate issued by the internal Microsoft Certificate server.

C.

The ClearPass server does not recognize the client’s certificate.

D.

The DNS server is not replying with an IP address for www.google.com.

Buy Now
Questions 25

Refer to the exhibit.

HPE6-A68 Question 25

What information can be drawn from the audit row detail shown? (Select two.)

Options:

A.

radius01 was deleted from the list of authentication sources.

B.

The policy service was moved to position number 4.

C.

radius01 was moved to position number 4.

D.

The policy service was moved to position number 3.

E.

raduis01 was added as an authentication source.

Buy Now
Questions 26

What is the purpose of the Audit Viewer in the Monitoring section of ClearPass Policy Manager?

Options:

A.

to audit client authentications

B.

to display changes made to the ClearPass configuration

C.

to display the entire configuration of the ClearPass Policy Manager

D.

to audit the network for PCI compliance

E.

to display system events like high CPU usage.

Buy Now
Questions 27

A guest self-registered through a Publisher’s Register page.

Which statement accurately describes how the guest’s account will be stored?

Options:

A.

It will be stored in the Publisher’s guest user repository and the Subscriber’s Onboard user repository.

B.

It will be stored in the Publisher’s local user repository and the Subscriber’s guest user repository.

C.

It will be stored in the Publisher’s guest user repository permanently, but only for 14 days in the Subscriber’s guest user repository,

D.

It will be stored in both the Publisher’s guest user repository and the Subscriber’s guest user repository.

E.

It will be stored in the Publisher’s guest user repository, but not the Subscriber’s.

Buy Now
Questions 28

When is the RADIUS server certificate used? (Select two.)

Options:

A.

During dual SSID onboarding, when the client connects to the Guest network

B.

During EAP-PEAP authentication in single SSID onboarding

C.

During post-Onboard EAP-TLS authentication, when the client verifies the server certificate

D.

During Onboard Web Login Pre-Auth, when the client loads the Onboarding web page

E.

During post-Onboard EAP-TLS authentication, when the server verifies the client certificate

Buy Now
Questions 29

Why is a terminate session enforcement profile used during posture checks with 802.1x authentication?

Options:

A.

To send a RADIUS CoA message from the ClearPass server to the client

B.

To disconnect the user for 30 seconds when they are in an unhealthy posture state

C.

To blacklist the user when they are in an unhealthy posture state

D.

To force the user to re-authenticate and run through the service flow again

E.

To remediate the client applications and firewall do that updates can be installed

Buy Now
Questions 30

Refer to the exhibit.

HPE6-A68 Question 30

Which statement accurately reflects the status of the Policy Simulation test figure shown?

Options:

A.

The test verifies that a client with username test1 can authenticate using EAP-PEAP.

B.

Role mapping simulation verifies if the remote lab AD has the ClearPass server certificate.

C.

Role mapping simulation verifies that the client certificate is valid during EAP-TLS authentication.

D.

The simulation test result shows the firewall roles assigned to the client by the Aruba Controller.

E.

The roles assigned in the results tab are based on rules matched in the AD Role Mapping Policy.

Buy Now
Questions 31

Refer to the exhibit.

HPE6-A68 Question 31

What does the Cache Timeout Value refer to?

Options:

A.

The amount of time the Policy Manager caches the user credentials stored in the Active Directory.

B.

The amount of time the Policy Manager waits for a response from the Active Directory before checking the backup authentication source.

C.

The amount of time the Policy Manager caches the user attributes fetched from Active Directory.

D.

The amount of time the Policy Manager waits for response from the Active Directory before sending a timeout message to the Network Access Device.

E.

The amount of time the Policy Manager caches the user\s client certificate.

Buy Now
Questions 32

Refer to the exhibit.

HPE6-A68 Question 32

Based on the information shown, what will be the outcome when the administrator chooses “Deny Access to this Device? (Select two.)

Options:

A.

EAP-TLS Authentication will be unaffected

B.

The user can Onboard their device again

C.

A new device certificate will be automatically pushed out to the device

D.

The user cannot Onboard their device again

E.

EAP-TLS Authentication will fail

Buy Now
Questions 33

Which statement is true? (Choose two.)

Options:

A.

Mobile device Management is the result of Onboarding.

B.

Third party Mobile Device Management solutions can be integrated with ClearPass.

C.

Mobile Device Management is the authentication that happens before Onboarding.

D.

Mobile Device Management is an application container that is used to provision work applications.

E.

Mobile Device Management is used to control device functions post-Onboarding.

Buy Now
Questions 34

A client’s authentication is failing and there are no entries in the ClearPass Access tracker.

What is a possible reason for the authentication failure?

Options:

A.

The user account has expired.

B.

The client used a wrong password.

C.

The shared secret between the NAD and ClearPass does not match.

D.

The user’s certificate is invalid.

E.

The user is not found in the database.

Buy Now
Exam Code: HPE6-A68
Exam Name: Aruba Certified ClearPass Professional (ACCP) 6.7
Last Update: Apr 30, 2026
Questions: 116

PDF + Testing Engine

$63.52  $181.49

Testing Engine

$50.57  $144.49
buy now HPE6-A68 testing engine

PDF (Q&A)

$43.57  $124.49
buy now HPE6-A68 pdf