โ† All ACA Flashcard Decks

Network Security & Access Control Flashcards

7 cards from real ACA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Security & Access Control flashcards as text
  1. Which Aruba Mobility Controller feature detects and classifies rogue APs operating on the same RF spectrum?

    Answer: Air Monitor (AM) mode

    APs in Air Monitor mode continuously scan all channels and report rogue devices to the controller for classification and containment.

  2. A ClearPass administrator wants to allow guests to self-register. Which ClearPass module provides the guest self-registration portal?

    Answer: ClearPass Guest

    ClearPass Guest provides customizable captive portals, self-registration workflows, and guest account management.

  3. Which Aruba security feature automatically moves a client to a quarantine role when ClearPass sends a RADIUS Change of Authorization (CoA)?

    Answer: Dynamic Authorization

    Dynamic Authorization (RFC 5176) allows ClearPass to send CoA or Disconnect-Message packets to the controller mid-session to change a client's role or terminate the session.

  4. In Aruba's layered security model, which layer is responsible for encrypting the wireless data frames over the air?

    Answer: Layer 2 (CCMP/AES encryption)

    CCMP (AES-based) operates at Layer 2 and encrypts the 802.11 data frames between the client and the AP over the air.

  5. What Aruba feature uses DHCP fingerprinting and OUI lookup to automatically identify the type of device connecting to the network?

    Answer: ClearPass Device Insight / Profiling

    ClearPass Device Profiling uses DHCP fingerprinting, HTTP user-agent, OUI, and other signals to identify device type, OS, and manufacturer.

  6. Which wireless attack does Aruba's Wireless Intrusion Protection (WIP) detect by identifying a legitimate SSID broadcast from an unauthorized MAC address?

    Answer: Evil twin / honeypot AP

    An evil twin attack uses a rogue AP broadcasting a legitimate SSID to lure clients; WIP detects the SSID/BSSID mismatch against the valid AP table.

  7. In an Aruba network, what is the primary function of the Pairwise Master Key (PMK) derived during 802.1X authentication?

    Answer: It seeds the 4-Way Handshake to derive per-session PTK/GTK keys

    The PMK is derived from the EAP exchange and is used as input to the 4-Way Handshake, which produces the PTK (unicast) and GTK (multicast) encryption keys.