ACP Professional Standards & Best Practices 2 — Questions and Answers
Question 1: When deploying an Aruba ClearPass Policy Manager in a large enterprise, which high-availability configuration is considered best practice?
- Active-Active cluster with a shared database
- Active-Standby with Publisher and Subscriber nodes (Correct answer)
- Single node with RAID redundancy only
- Dual publishers with no subscriber nodes
Correct answer: Active-Standby with Publisher and Subscriber nodes
Aruba best practice recommends an Active-Standby ClearPass cluster using a Publisher for configuration and one or more Subscribers for policy processing and redundancy.
Question 2: A network engineer is configuring Aruba APs in a RF-sensitive hospital environment. Which power management practice best minimizes interference with medical equipment?
- Use maximum TX power on all APs to ensure coverage
- Disable ARM and set TX power manually to the lowest acceptable level
- Enable ARM and allow it to auto-adjust power based on neighbor discovery (Correct answer)
- Set all APs to 2.4 GHz only and disable 5 GHz radios
Correct answer: Enable ARM and allow it to auto-adjust power based on neighbor discovery
Enabling Adaptive Radio Management (ARM) allows APs to automatically adjust transmit power to the minimum necessary for reliable coverage, reducing RF interference.
Question 3: Which practice should be followed when assigning VLANs to Aruba user roles in a segmented network?
- Map every role to VLAN 1 to simplify management
- Assign unique VLANs per user role to enforce traffic segmentation (Correct answer)
- Use the same VLAN for wired and wireless guest users regardless of role
- Avoid VLAN assignment in roles and rely solely on firewall policies
Correct answer: Assign unique VLANs per user role to enforce traffic segmentation
Assigning unique VLANs per user role ensures proper traffic segmentation and limits the blast radius of a security breach.
Question 4: During an Aruba Mobility Controller (MC) software upgrade, what is the recommended procedure to minimize user downtime?
- Upgrade all MCs simultaneously during business hours
- Upgrade the Standby MC first, failover, then upgrade the formerly Active MC (Correct answer)
- Upgrade the Active MC first without failover
- Disable all APs before upgrading the MC
Correct answer: Upgrade the Standby MC first, failover, then upgrade the formerly Active MC
Upgrading the Standby MC first, then performing a controlled failover, ensures continuous service while the formerly Active MC is upgraded.
Question 5: What is the Aruba best practice for securing management access to Mobility Controllers?
- Allow management access from all VLANs using Telnet for simplicity
- Restrict management to a dedicated out-of-band management VLAN and use SSH/HTTPS only (Correct answer)
- Use HTTP and Telnet within a private address range
- Enable management access via the wireless SSID used by end users
Correct answer: Restrict management to a dedicated out-of-band management VLAN and use SSH/HTTPS only
Aruba recommends isolating management traffic on a dedicated VLAN and enforcing encrypted protocols (SSH/HTTPS) to prevent unauthorized access.
Question 6: An Aruba professional is documenting a wireless deployment. Which artifact is considered essential for post-deployment validation according to best practices?
- A marketing summary of SSID names
- A post-installation RF heat map and channel plan report (Correct answer)
- A list of user device serial numbers
- A vendor comparison chart for competing products
Correct answer: A post-installation RF heat map and channel plan report
A post-installation RF heat map and channel plan report validates that coverage, signal strength, and channel allocation meet design requirements.
Question 7: Which Aruba best practice applies when configuring 802.1X authentication for corporate devices on a campus network?
- Use PSK authentication for all corporate devices to simplify deployment
- Deploy EAP-TLS with device certificates for the strongest mutual authentication (Correct answer)
- Use EAP-MD5 as it is supported by all Aruba controllers
- Disable certificate validation on the client side to ease onboarding
Correct answer: Deploy EAP-TLS with device certificates for the strongest mutual authentication
EAP-TLS with device certificates provides the highest level of mutual authentication and is the recommended method for corporate device 802.1X deployments.
When deploying an Aruba ClearPass Policy Manager in a large enterprise, which high-availability configuration is considered best practice?