โ† All ACMA Flashcard Decks

Network Security Flashcards

7 cards from real ACMA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Security flashcards as text
  1. Which protocol does Aruba use for centralized key management to support fast BSS transitions (802.11r)?

    Answer: Fast BSS Transition (FT) with PMK-R0/R1 key hierarchy

    802.11r uses a PMK-R0/R1 key hierarchy managed by the mobility domain to enable fast transitions between APs.

  2. In Aruba's role-based access control, what happens to traffic that does not match any firewall policy rule?

    Answer: It is implicitly denied by the default deny rule

    Aruba firewalls have an implicit deny-all at the end of each policy, dropping unmatched traffic.

  3. What does Aruba's 'Client Match' feature do in a security context?

    Answer: Steers clients away from overloaded or poorly performing APs

    Client Match steers clients to the best available AP based on RF conditions and load, improving performance and security posture.

  4. Which encryption protocol is used by WPA3-Enterprise to provide 192-bit security mode?

    Answer: GCMP-256 with SHA-384

    WPA3-Enterprise 192-bit mode uses GCMP-256 for data encryption and SHA-384 for integrity, meeting Suite-B requirements.

  5. An administrator wants to prevent wireless clients from communicating directly with each other on the same SSID. Which Aruba feature accomplishes this?

    Answer: Station Isolation (Client Isolation)

    Station (Client) Isolation blocks peer-to-peer traffic between clients on the same SSID, preventing lateral movement.

  6. Which port must be open on a firewall between an Aruba AP and its controller for PAPI control traffic?

    Answer: UDP 8211

    PAPI (Process Application Programming Interface) uses UDP port 8211 for control communication between APs and the Mobility Controller.

  7. What is the primary security benefit of Aruba's GRE tunnel mode for remote APs (RAPs)?

    Answer: It tunnels all client traffic back to the controller, bypassing untrusted local networks

    GRE tunnel mode sends all RAP client traffic through an encrypted tunnel to the controller, ensuring it does not traverse untrusted local networks unprotected.

Network Security Flashcards โ€” ACMA Study Cards with Answers