Aruba Certified Switching Professional (ACSP) HPE6-A73 — Questions and Answers
Question 1: What is the administrative distance of OSPF on an ArubaOS-CX switch by default?
- 170
- 110 (Correct answer)
- 90
- 120
Correct answer: 110
OSPF has a default administrative distance of 110 on ArubaOS-CX switches.
Question 2: When applying an IPv4 ACL on an ArubaOS-CX interface, which direction applies the ACL to traffic entering the switch from a host?
- Inbound (ingress) (Correct answer)
- Outbound (egress)
- Both directions simultaneously
- Management plane direction
Correct answer: Inbound (ingress)
Ingress (inbound) ACLs are applied to traffic arriving at the switch interface from an external host before it is forwarded.
Question 3: An ArubaOS-CX switch needs to redistribute connected routes into OSPF. Which configuration element is required?
- Connected routes are redistributed automatically
- A route map is always mandatory
- OSPF must be disabled and re-enabled after adding connected networks
- The 'redistribute connected' command under the OSPF process (Correct answer)
Correct answer: The 'redistribute connected' command under the OSPF process
The 'redistribute connected' command under the OSPF router configuration redistributes directly connected routes into OSPF as external routes.
Question 4: Which statement best describes IP Source Guard on an Aruba switch?
- It validates IP addresses against a static ACL
- It filters traffic based on IP and MAC from the DHCP snooping table (Correct answer)
- It blocks all non-IP traffic on a port
- It prevents IP fragmentation attacks
Correct answer: It filters traffic based on IP and MAC from the DHCP snooping table
IP Source Guard uses the DHCP snooping binding table to permit only traffic whose source IP and MAC match a valid binding.
Question 5: On an Aruba CX switch, a security policy requires that all RADIUS packets use a specific source IP. Which configuration achieves this?
- Set the RADIUS server IP as the source address
- Configure 'radius-server host <ip> source-interface <intf>' (Correct answer)
- Apply an outbound ACL on the management port
- Use a loopback interface as the default route next-hop
Correct answer: Configure 'radius-server host <ip> source-interface <intf>'
The 'source-interface' option on the RADIUS server configuration forces all RADIUS packets to use the IP of the specified interface.
Question 6: Which Aruba Central feature allows an administrator to set up automated alerts when a switch CPU exceeds a defined threshold?
- AI Insights
- Traffic Analysis
- Threshold-based alerts in the Alerts & Events module (Correct answer)
- Audit Trails
Correct answer: Threshold-based alerts in the Alerts & Events module
Aruba Central's Alerts & Events module allows configuring threshold-based alerts that trigger notifications when metrics like CPU utilization exceed defined limits.
Question 7: On an Aruba switch, what is the primary purpose of a 'remark' entry in an ACL configuration?
- To mark DSCP bits in packet headers
- To temporarily disable the ACL entry below it
- To add a human-readable comment to the ACL without affecting traffic (Correct answer)
- To log remarks to a syslog server
Correct answer: To add a human-readable comment to the ACL without affecting traffic
A 'remark' is a comment line in an ACL that is visible in the configuration for documentation purposes but has no effect on packet processing.
Question 8: Which RSTP port role replaces the STP Blocked port and provides an alternate path to the root bridge?
- Designated port
- Alternate port (Correct answer)
- Edge port
- Backup port
Correct answer: Alternate port
The RSTP Alternate port provides a redundant path to the root and can rapidly transition to Forwarding if the root port fails.
Question 9: Which SNMP operation does a management station use to retrieve a series of consecutive MIB variables from a switch?
- SNMP Get
- SNMP Inform
- SNMP GetBulk (Correct answer)
- SNMP Set
Correct answer: SNMP GetBulk
GetBulk retrieves multiple MIB variables in a single request, making it more efficient than issuing repeated GetNext operations for table data.
Question 10: An Aruba CX switch has an ACL applied with 'deny ip any any' as the last entry. A packet matching no other ACE arrives. What happens?
- It is sent to the CPU for inspection
- It is rate-limited before dropping
- It is forwarded due to the implicit permit
- It is dropped by the explicit deny any any rule (Correct answer)
Correct answer: It is dropped by the explicit deny any any rule
An explicit 'deny ip any any' at the end of an ACL drops all unmatched traffic, overriding no other behavior.
Question 11: In Aruba's QoS queuing model, which scheduling algorithm gives each queue a guaranteed minimum bandwidth while allowing unused bandwidth to be shared?
- First In First Out (FIFO)
- Weighted Round Robin (WRR) (Correct answer)
- Random Early Detection (RED)
- Strict Priority
Correct answer: Weighted Round Robin (WRR)
WRR assigns weights to queues, guaranteeing minimum bandwidth proportional to each weight while redistributing unused capacity to other queues.
Question 12: A network administrator configures an ArubaOS-CX switch for OSPF. The administrator wants to advertise the network associated with interface 1/1/5 into OSPF, but prevent the switch from forming OSPF adjacencies on that interface. Which command sequence achieves this goal?
- switch(config)# router ospf 1 switch(config-ospf-1)# passive-interface default
- switch(config)# interface 1/1/5 switch(config-if)# ip ospf shutdown
- switch(config)# router ospf 1 switch(config-ospf-1)# passive-interface 1/1/5
- switch(config)# interface 1/1/5 switch(config-if)# ip ospf passive (Correct answer)
Correct answer: switch(config)# interface 1/1/5 switch(config-if)# ip ospf passive
On ArubaOS-CX switches, the `ip ospf passive` command, configured under a specific interface, is the correct method to prevent OSPF Hello packets from being sent on that interface while still allowing the interface's network to be advertised. The `passive-interface <interface>` command is not a valid syntax in the router OSPF context on ArubaOS-CX. `passive-interface default` would make all interfaces passive, and `ip ospf shutdown` would disable OSPF entirely on the interface.
Question 13: What is the effect of removing the ISL port-channel from a VSX configuration while the system is live?
- VSX enters split-brain mode immediately (Correct answer)
- VSX gracefully migrates to keepalive-only mode
- The system automatically rebuilds the ISL on an alternate path
- Both peers reload to clear the split state
Correct answer: VSX enters split-brain mode immediately
Removing the ISL port-channel while live breaks state synchronization and peer connectivity, triggering split-brain behavior where the Secondary shuts its MCLAG interfaces.
Question 14: A trunk port on an Aruba CX switch is receiving frames tagged with VLAN 10, but VLAN 10 is not in the allowed VLAN list. What happens to these frames?
- They trigger a VLAN mismatch SNMP trap
- They are forwarded to the management VLAN
- They are dropped by the switch (Correct answer)
- They are forwarded in the native VLAN
Correct answer: They are dropped by the switch
Frames tagged with a VLAN not in the trunk's allowed VLAN list are dropped at ingress on the trunk port.
Question 15: A network administrator is configuring a multi-area OSPF network on ArubaOS-CX switches. An interface on a switch connects to Area 0.0.0.0. What is the common name for this area?
- The Not-So-Stubby Area (NSSA)
- The Backbone Area (Correct answer)
- The Transit Area
- The Stub Area
Correct answer: The Backbone Area
In OSPF, Area 0 (or 0.0.0.0) has a special designation as the backbone area. All other areas in a multi-area OSPF design must connect to the backbone area, either directly or through a virtual link, to ensure that routing information can be exchanged between non-backbone areas.
Question 16: Which of the following is a key difference between VRRPv2 and VRRPv3?
- VRRPv2 supports both IPv4 and IPv6, while VRRPv3 only supports IPv6.
- VRRPv3 supports both IPv4 and IPv6, while VRRPv2 only supports IPv4. (Correct answer)
- VRRPv3 uses a higher default priority value than VRRPv2.
- VRRPv3 supports authentication, while VRRPv2 does not.
Correct answer: VRRPv3 supports both IPv4 and IPv6, while VRRPv2 only supports IPv4.
The primary enhancement of VRRPv3 over VRRPv2 is the addition of support for IPv6 networks. VRRPv2 is limited to IPv4 only. Additionally, authentication was removed in VRRPv3.
Question 17: Which of the following commands would an administrator use on an ArubaOS-CX switch to change the OSPF network type on an interface to support a direct, two-router link efficiently?
- switch(config-if)# ip ospf network point-to-point (Correct answer)
- switch(config-if)# ip ospf network point-to-multipoint
- switch(config-if)# ip ospf network non-broadcast
- switch(config-if)# ip ospf network broadcast
Correct answer: switch(config-if)# ip ospf network point-to-point
For a link that connects only two routers, the `point-to-point` network type is the most efficient. It eliminates the need for Designated Router (DR) and Backup Designated Router (BDR) elections, which are unnecessary in a two-router topology, leading to faster convergence. The command to set this is `ip ospf network point-to-point` under the interface configuration.
Question 18: Which encryption standard is commonly used for wireless networks?
- TKIP
- WEP
- WPA2
- WPA
WPA2 (Wi-Fi Protected Access II) is the most widely adopted and recommended encryption standard for securing wireless networks. It uses the Advanced Encryption Standard (AES) for strong encryption, providing robust protection against unauthorized access and data interception. While WPA3 is newer, WPA2 remains the prevalent standard in use today.
Question 19: In Aruba AOS-CX, which command correctly creates a named IPv4 ACL called 'RESTRICT_GUEST'?
- access-list ip RESTRICT_GUEST extended
- ip access-list RESTRICT_GUEST (Correct answer)
- ip acl RESTRICT_GUEST standard
- create acl ipv4 RESTRICT_GUEST
Correct answer: ip access-list RESTRICT_GUEST
On Aruba AOS-CX, 'ip access-list <name>' enters ACL configuration mode to define an IPv4 named ACL.
Question 20: Two ArubaOS-CX switches are configured in a VRRP group with the same priority value and preemption disabled. Which switch will become the VRRP Master?
- The election is random and non-deterministic.
- The switch that boots up first and initializes its VRRP instance.
- The switch with the lower physical MAC address.
- The switch with the higher IP address configured on the VRRP interface. (Correct answer)
Correct answer: The switch with the higher IP address configured on the VRRP interface.
When VRRP priorities are identical, the switch with the highest IP address on the interface participating in the VRRP group is elected as the Master. This is the standard tie-breaking mechanism.
Question 21: Which ArubaOS-CX command enables DHCP snooping on a specific VLAN?
- ip dhcp snooping vlan <id> (Correct answer)
- set dhcp-snooping vlan <id>
- ip dhcp snooping enable vlan <id>
- dhcp-snooping vlan <id>
Correct answer: ip dhcp snooping vlan <id>
The correct ArubaOS-CX syntax to enable DHCP snooping on a VLAN is 'ip dhcp snooping vlan <id>' entered in global configuration mode.
Question 22: An Aruba switch is generating excessive syslog messages. Which command limits syslog to only critical and above messages?
- logging level critical
- logging severity critical (Correct answer)
- logging severity-filter 2
- logging facility critical
Correct answer: logging severity critical
The 'logging severity critical' command filters syslog output to only transmit messages at the critical severity level (2) and above (emergency, alert).
Question 23: What is the OSPF cost assigned to a 10 Gbps interface on an Aruba switch using the default reference bandwidth of 100 Mbps?
- 100
- 1000
- 1 (Correct answer)
- 10
Correct answer: 1
OSPF cost = reference bandwidth / interface bandwidth; 100 Mbps / 10,000 Mbps = 0.01, which rounds up to the minimum cost of 1.
Question 24: Which protocol replaces ARP in IPv6 networks for resolving IPv6 addresses to MAC addresses?
- DHCPv6
- IGMPv3
- RARP
- ICMPv6 Neighbor Discovery Protocol (NDP) (Correct answer)
Correct answer: ICMPv6 Neighbor Discovery Protocol (NDP)
IPv6 uses ICMPv6 Neighbor Discovery Protocol (NDP) instead of ARP, using multicast Neighbor Solicitation and Neighbor Advertisement messages for address resolution.
Question 25: Which VLAN range is reserved for internal use and cannot be assigned to user ports on Aruba CX switches?
- 2000-2999
- 1-100
- 1000-1999
- 4094 and above (implementation-specific reserved range) (Correct answer)
Correct answer: 4094 and above (implementation-specific reserved range)
Aruba CX reserves certain VLAN IDs at the upper end of the range (near 4094) for internal switch operations, and these cannot be assigned to user-facing ports.
Question 26: An engineer is setting up a new access switch that connects to a distribution switch using two bundled links. The distribution switch is configured for a dynamic LACP LAG. The new access switch is unconfigured (factory default). To allow the access switch to boot up, obtain a DHCP address, and download its configuration via Zero-Touch Provisioning (ZTP), what feature must be enabled on the distribution switch's LAG interface?
- VLAN trunking
- LACP fallback-static (Correct answer)
- Spanning Tree Protocol (STP) PortFast
- Static LAG
Correct answer: LACP fallback-static
LACP fallback-static is designed for scenarios like ZTP or PXE booting. When the distribution switch does not receive LACP PDUs from the downstream device (like a factory-default switch), LACP fallback-static allows one port of the LAG to come up as a normal, non-bonded interface. This enables the new switch to communicate on the network to get its configuration.
Question 27: What happens to STP topology when two switches have the same bridge priority and the same MAC address is theoretically used?
- STP fails to converge and loops form
- The switch with the lower MAC address becomes root (Correct answer)
- Both switches become root simultaneously
- The switch with the higher MAC address becomes root
Correct answer: The switch with the lower MAC address becomes root
When bridge priorities are equal, STP uses the MAC address as a tiebreaker, and the numerically lower MAC address wins the root election.
Question 28: What STP feature causes a switch port to immediately enter Forwarding state when connected to an end device, bypassing Listening and Learning states?
- PortFast (Correct answer)
- Loop Guard
- BPDU Guard
- Root Guard
Correct answer: PortFast
PortFast enables edge ports to skip the Listening and Learning states and go directly to Forwarding, reducing connectivity delays for end hosts.
Question 29: In Aruba AOS-CX EVPN-VXLAN, what is the primary purpose of a VRF (Virtual Routing and Forwarding) instance for tenant networks?
- To manage BGP peer relationships and route reflector sessions between VTEPs
- To separate management traffic from data-plane forwarding
- To define VXLAN encapsulation parameters and VNI-to-VLAN mappings
- To provide Layer 3 tenant isolation by maintaining a separate, independent routing table per tenant (Correct answer)
Correct answer: To provide Layer 3 tenant isolation by maintaining a separate, independent routing table per tenant
VRFs provide multi-tenant isolation by maintaining completely separate routing tables per tenant, preventing route leaks and supporting overlapping IP address spaces across tenants.
Question 30: When OSPF is configured on an Aruba switch with multiple areas, what is the requirement for inter-area communication?
- All non-backbone areas must connect directly or via virtual link to Area 0 (Correct answer)
- Each area must have a unique DR to facilitate inter-area routing
- Non-backbone areas can communicate directly without passing through Area 0
- All areas must have at least one ABR connecting them to another area
Correct answer: All non-backbone areas must connect directly or via virtual link to Area 0
OSPF's hierarchical design mandates that all non-backbone areas connect to Area 0 (backbone), either directly or through a virtual link, for inter-area route exchange.
Question 31: Which VSX configuration element uses the out-of-band management network (OOBM) as its recommended transport?
- ISL port-channel
- MCLAG LACP PDU path
- VSX keepalive link (Correct answer)
- Active Gateway virtual IP
Correct answer: VSX keepalive link
The VSX keepalive link is recommended to use the OOBM network so it remains reachable even when all in-band ISL paths fail, ensuring accurate split-brain detection.
Question 32: Which Aruba switch ACL feature allows you to assign a QoS priority to packets matching a specific ACE?
- ACL remarking with DSCP set action (Correct answer)
- ACL mirroring action
- ACL rate-limit action only
- ACL logging action
Correct answer: ACL remarking with DSCP set action
Aruba AOS-Switch ACEs support a 'set dscp' or priority action that remarks the DSCP value of matching packets for QoS treatment.
Question 33: What is the primary difference between SNMP traps and SNMP informs?
- Informs require an acknowledgment from the receiver; traps do not (Correct answer)
- Traps support SNMPv3 encryption; informs do not
- Informs can only be sent to one destination; traps support multiple
- Traps use TCP while informs use UDP
Correct answer: Informs require an acknowledgment from the receiver; traps do not
SNMP informs are acknowledged by the receiving NMS, providing delivery confirmation; traps are unacknowledged fire-and-forget messages.
Question 34: An administrator has created a MAC ACL named `IOT-SECURITY` to restrict device access on a specific port. Which of the following commands correctly applies this ACL to interface 1/1/5 for inbound traffic?
- interface 1/1/5; apply access-list IOT-SECURITY in
- vlan 1; apply access-list mac IOT-SECURITY in
- interface 1/1/5; apply access-list mac IOT-SECURITY routed-in
- interface 1/1/5; apply access-list mac IOT-SECURITY in (Correct answer)
Correct answer: interface 1/1/5; apply access-list mac IOT-SECURITY in
To apply an ACL to a physical interface, you must enter the interface context. The command `apply access-list` is used, followed by the ACL type (`mac`), the ACL name (`IOT-SECURITY`), and the direction (`in` for inbound traffic). The `routed-in` direction is used for SVI/VLAN interfaces, not physical Layer 2 ports.
Question 35: In a VSF stack, which member role is responsible for running the control plane and making forwarding decisions for the entire stack?
- Standby
- Member
- Conductor (Correct answer)
- Relay
Correct answer: Conductor
The Conductor is the primary control-plane switch in a VSF stack, managing all forwarding and configuration for the virtual fabric.
Question 36: What is the purpose of a firewall?
- Assigning IP addresses
- Speeding up network traffic
- Preventing unauthorized access
- Encrypting data
A firewall acts as a security barrier, monitoring and controlling incoming and outgoing network traffic based on predefined security rules. Its primary purpose is to prevent unauthorized access to or from a private network. By filtering traffic, firewalls protect against various cyber threats and enforce network security policies.
Question 37: What is the purpose of BPDU Filter when applied globally (not per-port) on an Aruba switch?
- It prevents the switch from sending any BPDUs
- It drops all BPDUs on all ports including uplinks
- It enables PortFast on all edge ports automatically
- It suppresses BPDUs only on PortFast-enabled ports that have not yet received a BPDU (Correct answer)
Correct answer: It suppresses BPDUs only on PortFast-enabled ports that have not yet received a BPDU
Global BPDU Filter suppresses BPDU transmission on PortFast-enabled ports, but if a BPDU is received on such a port, PortFast is disabled and normal STP resumes.
Question 38: An Aruba switch is configured to use 802.1Q trunking to an IP phone. What VLAN configuration ensures the voice traffic gets QoS treatment separate from data traffic?
- Disable 802.1Q tagging and rely on native VLAN
- Use LACP to bundle phone and PC ports
- Configure the phone port as an access port in the data VLAN
- Configure a voice VLAN (auxiliary VLAN) separate from the data VLAN on the port (Correct answer)
Correct answer: Configure a voice VLAN (auxiliary VLAN) separate from the data VLAN on the port
A voice VLAN (auxiliary VLAN) separates phone traffic from PC data traffic, allowing independent QoS policies, DSCP marking, and queue assignment for each.
Question 39: Which Aruba CX feature allows a single physical switch to be logically divided, with each partition having its own VLAN and routing table?
- VLAN pooling
- VSF (Virtual Switching Framework)
- MSTP regions
- VRF (Virtual Routing and Forwarding) (Correct answer)
Correct answer: VRF (Virtual Routing and Forwarding)
VRF creates multiple independent routing instances on a single switch, each with its own routing and forwarding table, enabling network segmentation.
Question 40: What is the purpose of VRRP (Virtual Router Redundancy Protocol) on ArubaOS-CX switches?
- To provide a virtual default gateway that survives a single router failure (Correct answer)
- To synchronize routing tables between switches
- To authenticate OSPF neighbors between switches
- To load-balance traffic across multiple uplinks
Correct answer: To provide a virtual default gateway that survives a single router failure
VRRP creates a virtual IP address shared between routers, providing default gateway redundancy so hosts continue forwarding traffic if one router fails.
Question 41: A network administrator notices frequent topology changes causing MAC table flushes. Which STP enhancement can reduce unnecessary topology change notifications on access ports?
- PortFast (Correct answer)
- BPDU Guard
- Uplink Fast
- Root Guard
Correct answer: PortFast
PortFast suppresses Topology Change Notifications (TCNs) on edge ports since link flaps on host ports should not trigger network-wide MAC table flushes.
Question 42: What is the primary advantage of using LACP over a static LAG on an Aruba CX switch?
- LACP reduces CPU overhead compared to static LAG
- LACP automatically detects and responds to link failures and misconfigurations without manual intervention (Correct answer)
- LACP provides higher bandwidth than static LAG
- LACP supports more member ports than static LAG
Correct answer: LACP automatically detects and responds to link failures and misconfigurations without manual intervention
LACP continuously exchanges PDUs to detect link failures, miscabling, and configuration mismatches, providing automatic recovery that static LAG cannot offer.
Question 43: A network administrator configures VLAN translation on an Aruba CX switch. What does this feature accomplish?
- It maps an incoming VLAN tag to a different VLAN ID as traffic enters the switch (Correct answer)
- It duplicates frames across multiple VLANs simultaneously
- It converts 802.1Q tagged frames to 802.1ad (QinQ) frames
- It removes VLAN tags from all frames on a port
Correct answer: It maps an incoming VLAN tag to a different VLAN ID as traffic enters the switch
VLAN translation (also called VLAN mapping) rewrites the VLAN ID of incoming frames, enabling connectivity between networks using different VLAN numbering schemes.
Question 44: Which Aruba AOS-CX CLI command is used to display VXLAN VTEP status and information about discovered remote tunnel peers?
- show nve peers
- show interface vxlan
- show vxlan vteps (Correct answer)
- show vxlan vni
Correct answer: show vxlan vteps
The 'show vxlan vteps' command on AOS-CX displays the status of remote VTEPs that have been discovered, along with their IP addresses and the VNIs they are associated with.
Question 45: What action does BPDU Guard take when it receives a BPDU on a protected PortFast-enabled access port?
- Sends a BPDU trap to the NMS and continues
- Places the port into an err-disabled state (Correct answer)
- Transitions the port to the STP root state
- Increases the STP bridge priority
Correct answer: Places the port into an err-disabled state
BPDU Guard immediately disables (err-disables) a PortFast port upon receiving any BPDU, protecting the STP topology.
Question 46: A network engineer needs to track when interfaces go up or down on Aruba switches. What is the most efficient method?
- Configuring SNMP traps for linkUp and linkDown events (Correct answer)
- Using syslog with severity level 7 (debug)
- Running a script with repeated SSH show interface commands
- Polling SNMP OID ifOperStatus every 30 seconds
Correct answer: Configuring SNMP traps for linkUp and linkDown events
SNMP traps send immediate event-driven notifications when interface state changes occur, eliminating the latency and overhead of polling.
Question 47: In VSX, what is the Active Gateway feature used for?
- Managing keepalive intervals
- Providing a shared virtual IP and MAC so both VSX peers can route traffic locally (Correct answer)
- Synchronizing OSPF adjacencies across the ISL
- Electing the primary VSX switch
Correct answer: Providing a shared virtual IP and MAC so both VSX peers can route traffic locally
Active Gateway assigns both VSX peers the same virtual IP and virtual MAC, allowing each peer to locally route traffic without bouncing across the ISL.
Question 48: What is the purpose of VPNs?
- To speed up the internet
- To share data between users
- To secure communication over the internet
- To block access to websites
Virtual Private Networks (VPNs) are designed to create a secure, encrypted connection over a public network, such as the internet. This secure tunnel protects data from eavesdropping and tampering, ensuring privacy and integrity for communications. VPNs are essential for remote access to corporate networks and for users seeking enhanced online privacy.
Question 49: A network engineer is analyzing the STP topology on a network of Aruba CX switches. A non-root switch has two redundant uplinks to two different distribution switches. One uplink port is in the Root Port role. According to RSTP (802.1w), what is the most likely role of the second uplink port that is currently blocked?
- Disabled Port
- Alternate Port (Correct answer)
- Backup Port
- Designated Port
Correct answer: Alternate Port
In RSTP, an Alternate Port is a port that provides a redundant path toward the root bridge but is currently in a discarding state. It receives more useful BPDUs from another switch but is not the Root Port. If the current Root Port fails, the Alternate Port can quickly transition to the forwarding state, providing fast convergence. A Backup Port provides a redundant link to the same segment and is less common.
Question 50: A network engineer must limit the number of MAC addresses learned on an access port to 5. Which ArubaOS-CX feature accomplishes this?
- DHCP snooping binding limit
- IP Source Guard address filter
- Dynamic ARP Inspection
- Port security with a MAC limit (Correct answer)
Correct answer: Port security with a MAC limit
Port security on ArubaOS-CX allows limiting MAC addresses per port and defining violation actions when the limit is exceeded.
Question 51: What is the total length of an IPv6 address?
- 128 bits (Correct answer)
- 64 bits
- 32 bits
- 256 bits
Correct answer: 128 bits
IPv6 addresses are 128 bits long, written as eight groups of four hexadecimal digits separated by colons.
Question 52: On ArubaOS-CX, which feature ensures that only traffic from authenticated clients is forwarded while traffic from unauthenticated clients is dropped or redirected?
- Port-access authentication with client roles (Correct answer)
- MAC-based VLAN assignment
- Private VLAN isolation
- DHCP snooping trusted port configuration
Correct answer: Port-access authentication with client roles
Port-access authentication with client roles enforces that unauthenticated clients have no forwarding access or are placed in a restricted VLAN until they complete authentication.
Question 53: What is the maximum number of switches that can be combined in a single AOS-CX VSF stack?
- 4
- 16
- 2
- 8 (Correct answer)
Correct answer: 8
AOS-CX VSF supports up to 8 members in a single virtual switching fabric.
Question 54: What is the primary role of PIM (Protocol Independent Multicast) in a multicast network?
- To manage multicast address allocation across the network
- To build multicast distribution trees and forward multicast traffic between routers (Correct answer)
- To convert unicast routing protocols to support multicast
- To discover IGMP group members on a subnet
Correct answer: To build multicast distribution trees and forward multicast traffic between routers
PIM builds multicast distribution trees (shortest path trees or shared trees) and leverages the existing unicast routing table to forward multicast traffic between routers.
Question 55: When the VRRP master's tracked uplink fails and its priority drops below a backup router's priority, what must be enabled for the backup to take over?
- Object tracking must be enabled on the backup as well
- The backup must have a static route pointing to the virtual IP
- Preemption must be enabled on the backup router (Correct answer)
- VRRP authentication must be disabled
Correct answer: Preemption must be enabled on the backup router
Even with object tracking causing the master's priority to fall, the backup router will only preempt if preemption is enabled on that backup.
Question 56: In BGP, what is the effect of prepending your own AS number multiple times to the AS_PATH attribute before advertising a route?
- It makes the path appear longer, making it less preferred by external peers (Correct answer)
- It marks the route as an aggregate
- It prevents the route from being advertised beyond one AS hop
- It increases the local preference of the route
Correct answer: It makes the path appear longer, making it less preferred by external peers
AS path prepending artificially lengthens the AS_PATH, making the route less preferred by BGP peers that use AS path length as a selection criterion.
Question 57: Which of the following is a valid reason to place an extended ACL close to the traffic source on an Aruba switch?
- To drop unwanted traffic early and reduce unnecessary transit (Correct answer)
- Extended ACLs only function correctly near the source
- To save ACL TCAM resources on core switches
- Because standard ACLs cannot be applied near the source
Correct answer: To drop unwanted traffic early and reduce unnecessary transit
Placing extended ACLs near the source drops unwanted traffic before it traverses the network, reducing bandwidth consumption on transit links.
Question 58: What IEEE standard defines the 802.1Q VLAN tagging mechanism used on Aruba switches?
- 802.1X
- 802.3ad
- 802.1Q (Correct answer)
- 802.1D
Correct answer: 802.1Q
IEEE 802.1Q defines the standard for VLAN tagging, including the 4-byte tag inserted into Ethernet frames to identify the VLAN.
Question 59: An Aruba switch is running OSPF. Which LSA type is generated by an ABR to describe routes from one area to another?
- Type 5 - AS External LSA
- Type 2 - Network LSA
- Type 3 - Summary LSA (Correct answer)
- Type 1 - Router LSA
Correct answer: Type 3 - Summary LSA
ABRs generate Type 3 Summary LSAs to advertise inter-area routes between OSPF areas.
Question 60: Which AF (Assured Forwarding) DSCP class provides the highest drop precedence within that class on an Aruba switch?
- AF13 (DSCP 14)
- AF11 (DSCP 10)
- AF43 (DSCP 38) (Correct answer)
- AF41 (DSCP 34)
Correct answer: AF43 (DSCP 38)
Within each AF class, the third drop precedence level (AFx3) has the highest probability of being dropped during congestion; AF43 (DSCP 38) is class 4, drop precedence 3.
Aruba Certified Switching Professional (ACSP) HPE6-A73
The ACSP exam validates the ability to implement and operate enterprise-level HPE Aruba campus switching solutions, covering wired network planning, installation and configuration of AOS-CX switches, troubleshooting, and network management and monitoring.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds