ACP Aruba ClearPass Policy Management 2 — Questions and Answers
Question 1: In ClearPass Policy Manager, what is the purpose of a Role Mapping Policy?
- To assign IP addresses to authenticated clients based on subnet location
- To map user or device attributes to defined roles used in authorization decisions (Correct answer)
- To configure the priority order of multiple authentication sources
- To create static VLAN definitions for specific network segments
Correct answer: To map user or device attributes to defined roles used in authorization decisions
A Role Mapping Policy evaluates user and device attributes (such as AD group membership or device type) and assigns them to named ClearPass roles that enforcement policies then act upon.
Question 2: What is a ClearPass Enforcement Profile?
- A document describing a network administrator's access privileges
- A configuration defining which access parameters (VLAN, ACL, etc.) to return when a role is matched (Correct answer)
- A compliance checklist used during endpoint posture assessment
- A template for creating new Active Directory authentication sources
Correct answer: A configuration defining which access parameters (VLAN, ACL, etc.) to return when a role is matched
An Enforcement Profile in ClearPass defines the specific RADIUS attributes (such as VLAN assignment or downloadable ACLs) that are sent to the network device in the Access-Accept response.
Question 3: ClearPass OnGuard is used to:
- Configure firewall rules on perimeter network devices
- Perform health and posture checks on endpoints before granting full network access (Correct answer)
- Generate compliance reports on network utilization and bandwidth
- Provision wireless access point firmware updates automatically
Correct answer: Perform health and posture checks on endpoints before granting full network access
ClearPass OnGuard is an endpoint posture assessment agent that checks health parameters like antivirus status, OS patch level, and firewall state before allowing full network access.
Question 4: Which ClearPass feature automatically identifies and categorizes devices based on network behavior, DHCP fingerprints, and HTTP attributes?
- ClearPass Insight
- Device Profiler (Correct answer)
- Policy Simulator
- ClearPass OnBoard
Correct answer: Device Profiler
The ClearPass Device Profiler passively and actively collects device fingerprint information to automatically classify devices by type, operating system, and manufacturer without requiring user authentication.
Question 5: What does the ClearPass Policy Simulation tool allow administrators to do?
- Test enforcement profiles against live traffic without affecting production users
- Simulate RF coverage changes in wireless controller deployments
- Test how services and policies respond to hypothetical authentication requests without real clients (Correct answer)
- Preview firmware changes before committing them to managed access points
Correct answer: Test how services and policies respond to hypothetical authentication requests without real clients
The Policy Simulation tool lets administrators input request attributes (like username, MAC, or NAS IP) and see exactly which service would match and what enforcement would be applied, without requiring a live client.
Question 6: Which Aruba Vendor-Specific Attribute (VSA) is commonly used in a ClearPass Enforcement Profile to place a wireless user into a specific VLAN on an Aruba controller?
- Cisco-AVPair
- Filter-ID
- Aruba-User-Vlan (Correct answer)
- Tunnel-Private-Group-ID
Correct answer: Aruba-User-Vlan
The Aruba-User-Vlan VSA is an Aruba-specific RADIUS attribute used in ClearPass Enforcement Profiles to instruct Aruba wireless controllers to assign authenticated users to a designated VLAN.
Question 7: What is the primary function of a ClearPass Enforcement Policy?
- To define the encryption algorithms used for RADIUS communication
- To match assigned roles and posture results to enforcement profiles for final access decisions (Correct answer)
- To schedule automatic configuration backups of the ClearPass database
- To define the priority order of authentication sources within a service
Correct answer: To match assigned roles and posture results to enforcement profiles for final access decisions
A ClearPass Enforcement Policy contains rules that evaluate a client's assigned role and posture status, mapping them to specific Enforcement Profiles that define the granted or denied network access.
In ClearPass Policy Manager, what is the purpose of a Role Mapping Policy?