← All ACMA Flashcard Decks

Authentication Methods Flashcards

7 cards from real ACMA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Authentication Methods flashcards as text
  1. What is the primary security advantage of using certificate-based authentication (EAP-TLS) over credential-based methods (PEAP-MSCHAPv2) in enterprise Wi-Fi?

    Answer: Certificates eliminate the risk of password theft or phishing since no password is transmitted

    EAP-TLS uses X.509 certificates instead of passwords, so there are no credentials to phish or steal — the private key never leaves the client device.

  2. In Aruba ClearPass, what is the 'Posture' check used for during authentication?

    Answer: Assessing the security compliance state of the client device (e.g., antivirus, OS patch level)

    Posture assessment in ClearPass evaluates the health of the connecting device (antivirus status, OS updates, firewall state) to enforce compliance-based access policies.

  3. Which RADIUS attribute is used to set a session timeout, forcing client re-authentication after a specified number of seconds?

    Answer: Session-Timeout (Attribute 27)

    Session-Timeout (RADIUS attribute 27) specifies the maximum number of seconds a client session is allowed before the NAS terminates it or forces re-authentication.

  4. What is Opportunistic Wireless Encryption (OWE) and in which scenario is it typically deployed?

    Answer: OWE encrypts traffic on open (unauthenticated) networks without requiring any credentials

    OWE (defined in IEEE 802.11ax and WPA3 Transition mode) provides encryption for open networks using a Diffie-Hellman key exchange, so no password is needed but traffic is still encrypted.

  5. When configuring a RADIUS server on an Aruba Mobility Controller, what is the 'NAS IP address' used for?

    Answer: The source IP address the controller uses in RADIUS packets sent to the authentication server

    The NAS IP address is the source IP the Aruba controller includes in RADIUS packets and is used by the RADIUS server to identify and authorize the NAS (controller) device.

  6. Which authentication method is most appropriate for IoT devices that cannot run an 802.1X supplicant?

    Answer: MAC Authentication Bypass (MAB)

    MAC Authentication Bypass (MAB) is used for devices incapable of 802.1X (printers, sensors, cameras) by authenticating them based on their MAC address via RADIUS.

  7. In an Aruba deployment using Captive Portal, what is the function of the RADIUS server in a 'web login' profile?

    Answer: The RADIUS server validates the username and password submitted through the portal page

    In a captive portal web login, the AP or controller forwards the credentials entered on the portal page to the RADIUS server for validation before granting network access.