Network Security Flashcards
7 cards from real ACMA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network Security flashcards as text
In Aruba ClearPass, what is the function of an 'Enforcement Profile'?
Answer: It specifies the actions applied to a session after policy evaluation, such as VLAN assignment
Enforcement Profiles define what actions ClearPass applies to an authenticated session, such as assigning a VLAN or applying a role.
Which Aruba mechanism prevents a compromised controller from being used to intercept AP communication by validating controller identity?
Answer: Certificate-based AP provisioning using factory-installed certificates
Aruba APs use factory-installed X.509 certificates to mutually authenticate with controllers, preventing rogue controller attacks.
What is the difference between 'deny' and 'blacklist' actions in an Aruba firewall policy?
Answer: Deny blocks matching traffic; blacklist blocks ALL traffic from that client for a configured duration
Deny blocks only the specific matching traffic, while blacklist blocks all traffic from the offending client for a set time period.
Which Aruba feature inspects Layer 7 application traffic to enforce policies based on application type?
Answer: AppRF
AppRF uses deep packet inspection at Layer 7 to identify and enforce policies based on specific applications.
When configuring a RADIUS server in Aruba Mobility Controller, what is the purpose of the 'NAS IP' setting?
Answer: It defines the IP the controller uses as the source of RADIUS packets
The NAS IP defines the source IP address that the controller uses when sending RADIUS authentication and accounting requests.
Which attack is mitigated by enabling 'Management Frame Protection' (802.11w) on an Aruba SSID?
Answer: Deauthentication and disassociation flood attacks
802.11w (MFP) cryptographically protects management frames, preventing spoofed deauthentication and disassociation attacks.
In an Aruba environment, what does a 'captive portal' primarily provide in terms of network security?
Answer: User identity collection and acceptance of terms before granting network access
A captive portal redirects unauthenticated users to a web page for credential entry or ToS acceptance before granting internet access.