ACA Network Security & Access Control 2 — Questions and Answers
Question 1: Which Aruba feature uses machine learning to detect anomalous client behavior on the wireless network?
- AirMatch
- UCC
- ArubaAI / Aruba Client Insights (Correct answer)
- Adaptive Radio Management
Correct answer: ArubaAI / Aruba Client Insights
Aruba Client Insights (part of ArubaAI) uses ML to baseline client behavior and flag deviations indicative of threats.
Question 2: In ClearPass Policy Manager, what object defines the conditions under which a policy rule is applied?
- Enforcement Profile
- Role Mapping Policy
- Conditions (Correct answer)
- Service
Correct answer: Conditions
Conditions in ClearPass are logical expressions (attributes compared to values) that determine whether a policy rule matches a request.
Question 3: An Aruba AP is configured with a WLAN that uses WPA3-Enterprise. Which key management protocol does WPA3-Enterprise mandate?
- TKIP
- CCMP-128 with 192-bit mode optional (Correct answer)
- WEP-104
- PEAP-MSCHAPv2 only
Correct answer: CCMP-128 with 192-bit mode optional
WPA3-Enterprise requires CCMP-128 at minimum and optionally supports a 192-bit security mode (CNSA suite) for high-security environments.
Question 4: Which Aruba solution provides posture assessment to check endpoint compliance before granting network access?
- AirWave
- ClearPass OnGuard (Correct answer)
- Aruba Central
- NetEdit
Correct answer: ClearPass OnGuard
ClearPass OnGuard is the posture assessment agent that checks endpoint health (antivirus, patch level, firewall status) before allowing access.
Question 5: What is the purpose of a 'deny' ACL entry placed at the end of an Aruba user role firewall policy?
- It logs all allowed traffic
- It acts as an implicit catch-all to block any traffic not explicitly permitted (Correct answer)
- It resets the session timer
- It triggers a RADIUS CoA
Correct answer: It acts as an implicit catch-all to block any traffic not explicitly permitted
An explicit deny-all at the end ensures any traffic not matched by earlier permit rules is dropped, enforcing a default-deny posture.
Question 6: Which 802.1X EAP method tunnels inner authentication inside a TLS tunnel established with server-side certificates only?
- EAP-TLS
- EAP-MD5
- PEAP (Correct answer)
- LEAP
Correct answer: PEAP
PEAP creates an outer TLS tunnel using only a server certificate, then carries an inner method (e.g., MSCHAPv2) inside that tunnel.
Question 7: When Aruba's Role-Based Access Control (RBAC) is used, what determines which firewall policy is applied to a wireless client?
- The SSID name alone
- The user role assigned after authentication (Correct answer)
- The AP group the client connects to
- The VLAN tag from the upstream switch
Correct answer: The user role assigned after authentication
The user role — assigned by ClearPass or the controller based on authentication outcome — determines which firewall policy governs the client's traffic.
Which Aruba feature uses machine learning to detect anomalous client behavior on the wireless network?