โ† All ACSP Flashcard Decks

Switch Security Features Flashcards

7 cards from real ACSP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Switch Security Features flashcards as text
  1. What does the ArubaOS-CX 'port-access authenticator' command with 'reauthenticate' enforce?

    Answer: Clients must re-authenticate after a configured time interval

    The reauthentication timer forces clients to periodically re-authenticate with the RADIUS server, ensuring continued authorization validity.

  2. Which ArubaOS-CX feature allows a downloadable ACL (dACL) to be applied to a port after successful 802.1X authentication?

    Answer: RADIUS-assigned ACL via Filter-Id or Aruba VSA

    After 802.1X authentication, RADIUS can return a Filter-Id or Aruba VSA attribute containing an ACL name, which the switch applies to the authenticated port.

  3. What is the effect of enabling 'loop protection' on an ArubaOS-CX access port?

    Answer: Detect and disable ports that create Layer 2 loops by sending probe frames

    Loop protection sends probe frames and disables a port if it receives its own probes back, detecting loops even on ports where STP BPDUs are filtered.

  4. In ArubaOS-CX, which command applies a previously defined user-role to an authenticated port-access session?

    Answer: aaa authentication port-access dot1x authenticator role

    User-roles in ArubaOS-CX define access policies (ACLs, QoS, VLAN) that can be assigned dynamically to ports after 802.1X or MAB authentication.

  5. Which ArubaOS-CX switch security feature prevents rogue devices from sending gratuitous ARP replies to poison ARP caches?

    Answer: Dynamic ARP Inspection (DAI)

    DAI validates all ARP packets including gratuitous ARPs against the DHCP snooping binding table, dropping those with mismatched IP-to-MAC bindings.

  6. What is the recommended ArubaOS-CX configuration to secure the management access interface against brute force login attacks?

    Answer: Configure login delay and maximum login attempts with lockout

    Configuring login delay and lockout thresholds (maximum failed attempts before lockout) directly mitigates brute force attacks on management interfaces.

  7. On ArubaOS-CX, which feature ensures that only traffic from authenticated clients is forwarded while traffic from unauthenticated clients is dropped or redirected?

    Answer: Port-access authentication with client roles

    Port-access authentication with client roles enforces that unauthenticated clients have no forwarding access or are placed in a restricted VLAN until they complete authentication.