โ† All ACMA Flashcard Decks

Security Protocols & Network Access Control Flashcards

7 cards from real ACMA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Protocols & Network Access Control flashcards as text
  1. Which 802.1X authentication framework component is responsible for making the final access decision based on user credentials?

    Answer: Authentication Server

    The Authentication Server (typically a RADIUS server) validates credentials and makes the final access decision in the 802.1X framework.

  2. In Aruba's ClearPass Policy Manager, what is the primary purpose of an Enforcement Profile?

    Answer: Specify the network access attributes applied after authentication

    An Enforcement Profile in ClearPass defines the set of attributes (VLAN, role, ACL) that are applied to a session after successful authentication and authorization.

  3. What EAP method provides both server-side and client-side certificate authentication, making it one of the most secure options?

    Answer: EAP-TLS

    EAP-TLS requires certificates on both the server and the client, providing mutual authentication and strong security.

  4. In Aruba WPA3-Enterprise, what is the minimum key length required for the CNSA suite mode?

    Answer: 192-bit AES

    WPA3-Enterprise CNSA (Commercial National Security Algorithm) suite mode requires a minimum of 192-bit AES encryption.

  5. When a wireless client is placed in a VLAN after 802.1X authentication, which component on an Aruba controller sends the VLAN assignment back to the AP?

    Answer: Mobility Controller

    The Aruba Mobility Controller receives the RADIUS Access-Accept (with VLAN attributes) and then communicates the VLAN assignment to the AP over the GRE tunnel.

  6. Which Aruba security feature inspects client traffic for malicious activity and can quarantine devices without requiring network re-authentication?

    Answer: Aruba Intrusion Detection System (IDS)

    Aruba's IDS monitors wireless frames for attack signatures and can quarantine suspicious clients without forcing a full re-authentication cycle.

  7. What does the 'role' concept in Aruba's firewall policy engine represent?

    Answer: A named policy container that defines traffic permissions for a user or device group

    A role in Aruba's stateful firewall is a named container that groups ACL policies and is assigned to users or devices based on their identity or posture.