โ† All ACMA Flashcard Decks

Network Security Flashcards

7 cards from real ACMA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Security flashcards as text
  1. What Aruba technology allows an AP to serve both as an access point and monitor the RF environment for threats simultaneously?

    Answer: Air Monitor (AM) mode with hybrid AP

    Hybrid AP mode allows an AP to serve clients on one radio while the other radio operates as an Air Monitor for threat detection.

  2. Which Aruba Mobility Controller feature prevents IP spoofing by validating that a client's source IP matches its DHCP-assigned address?

    Answer: IP Spoofing Protection (IP anti-spoof)

    IP Spoofing Protection checks that a client's source IP matches the address assigned by DHCP, dropping packets with mismatched source IPs.

  3. When Aruba ClearPass OnGuard performs a posture check, which of the following would cause a client to be assigned to a 'quarantine' role?

    Answer: Client's antivirus definitions are out of date

    Outdated antivirus definitions fail posture requirements, causing ClearPass to assign the client to a restricted quarantine role.

  4. In Aruba role-based access, what is the 'logon' role primarily used for?

    Answer: Providing limited access before authentication completes, typically for captive portal redirect

    The logon role grants minimal access before a user authenticates, allowing only the traffic needed to complete the authentication process.

  5. Which Aruba feature detects and alerts on ad-hoc wireless networks formed between client devices?

    Answer: Wireless Intrusion Detection (WID)

    Wireless Intrusion Detection identifies ad-hoc networks, which bypass infrastructure controls and pose a security risk.

  6. What security advantage does Aruba's tunnel-mode SSID provide over bridge-mode for sensitive corporate traffic?

    Answer: Tunnel mode sends all client traffic to the controller for centralized firewall inspection before routing

    Tunnel mode forwards all wireless client traffic to the Mobility Controller, where centralized firewall and policy enforcement is applied before routing.

  7. Which standard defines the EAP-TLS authentication method commonly deployed in Aruba enterprise WLANs?

    Answer: RFC 5216

    RFC 5216 defines EAP-TLS, which uses mutual certificate-based authentication and is the strongest EAP method for enterprise deployments.