โ† All ACA Flashcard Decks

Network Security & Access Control Flashcards

7 cards from real ACA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Security & Access Control flashcards as text
  1. Which Aruba CLI command on the Mobility Controller displays the current firewall policy applied to a specific connected client?

    Answer: show datapath user

    'show datapath user' reveals the client's applied role, firewall ACLs, VLAN, and session details in the controller's datapath.

  2. An organization wants to segment IoT devices onto a dedicated VLAN using dynamic policy. Which technology enables the controller to apply the correct VLAN based on ClearPass authentication results?

    Answer: RADIUS VLAN assignment (Tunnel-Private-Group-ID)

    ClearPass returns the RADIUS attribute Tunnel-Private-Group-ID (VLAN ID) in the Access-Accept, and the controller assigns that VLAN to the authenticated client.

  3. What is the role of the Group Temporal Key (GTK) in 802.11 security?

    Answer: It encrypts broadcast and multicast frames sent by the AP

    The GTK is a shared key used by the AP to encrypt broadcast/multicast frames; all associated clients receive it during the 4-Way Handshake.

  4. Which Aruba feature allows an administrator to restrict a user role so that the client can only communicate with the ClearPass server for remediation?

    Answer: Quarantine role with limited ACL

    A quarantine role uses a restrictive ACL that only permits traffic to the remediation server (e.g., ClearPass OnGuard), blocking all other destinations.

  5. In ClearPass, which component is responsible for enforcing the policy decision by communicating directly with the network device (e.g., controller or switch)?

    Answer: Enforcement Profiles & Policies

    Enforcement Profiles define what action to take (e.g., VLAN, role, ACL), and the Enforcement Policy maps those profiles to policy rule outcomes sent to the network device.

  6. Which IEEE standard defines port-based Network Access Control (PNAC) used in Aruba wired and wireless deployments?

    Answer: IEEE 802.1X

    IEEE 802.1X defines the port-based NAC framework, using EAP over LAN (EAPOL) to authenticate clients before granting port access.

  7. An Aruba controller is configured to use 'stateful firewall' for wireless clients. What distinguishing capability does a stateful firewall provide over a stateless ACL?

    Answer: It tracks connection state and automatically permits return traffic for established sessions

    A stateful firewall tracks TCP/UDP session state, so return traffic for an established outbound session is automatically allowed without an explicit inbound permit rule.