HPE Networking ClearPass HPE6-A88 Exam Questions

Page: 1 / 14
Total 111 questions
Question 1

A company is setting up a custom Enforcement Profile for operator logins in ClearPass. They decide to copy an existing operator login profile and modify the value of the admin_privileges attribute. What additional step must they take to properly assign this custom profile to the users?



Answer : A

Operator logins (logins to the CPPM/Guest/Onboard admin interfaces) are managed by the Admin User Repository. To apply a custom enforcement profile, you must first define a new Role that signifies those specific privileges. You then create a rule in the admin enforcement policy that says: 'If User has [New Role], then apply [Custom Enforcement Profile].' This links the user's identity to the specific administrative rights you've defined.


Question 2

A company is setting up a new secure network service and has configured EAP TLS with OCSP enabled. What additional step must be taken to ensure proper authentication?



Answer : A

Even if a specialized authentication method (like EAP-TLS with OCSP) is configured globally in ClearPass, it is not active for a specific request until it is assigned to a Service. The administrator must navigate to the service being used for that network access and explicitly add the desired method to the Authentication Methods list. Without this step, ClearPass will not attempt to use that specific protocol logic when processing incoming requests for that service.


Question 3

A network administrator is troubleshooting connectivity issues between clients and the ClearPass server. They suspect that the firewall configuration might be causing the problem. Which action should the administrator take to ensure the OnGuard agent can properly communicate with the ClearPass server?



Answer : A

Communication between the OnGuard agent and ClearPass requires specific firewall ports to be open. TCP Port 443 (HTTPS) is used for the initial control channel and software updates. TCP Port 6658 is the proprietary port used for the agent's 'heartbeat,' which provides real-time health updates and session monitoring. If either port is blocked, the agent will appear offline or fail to report its posture status.


Question 4

An IT administrator notices that endpoints are being re-evaluated with the same enforcement decisions even after client status changes. They realize this is causing inefficient network access control. What could be the underlying issue?



Answer : C

While caching can sometimes cause issues (as seen in Q76), enabling 'Use Cached Results' is often necessary for efficiency in complex multi-stage authentications. If this is not enabled, ClearPass may fail to properly correlate new status changes (like a profile update) with the existing session, leading the system to revert to a default or previous decision rather than dynamically adjusting the access based on the latest context.


Question 5

An IT administrator is managing a network with ClearPass and notices that one of the devices is sending multiple health checks throughout the day via different networks (wired, wireless, and VPN). How does OnGuard handle the license usage for this device?



Answer : A

ClearPass OnGuard licensing is based on the unique endpoint, not the number of connections or checks. A single device that connects via wired in the morning, Wi-Fi in the afternoon, and VPN in the evening---triggering a health check each time---will only consume one OnGuard license for that 24-hour period. This 'per-device' model makes licensing predictable for enterprise deployments with roaming users.


Question 6

A security analyst notices the system is set to gather device location information from network device attributes. Which attribute is likely being used?



Answer : C

ClearPass can extract location context from the NAD's RADIUS attributes. Common attributes used include NAS-Port-Id (for wired switches to show the specific port/closet) or Called-Station-Id (for wireless to show the AP Name or MAC). By configuring the Network Device attribute settings in ClearPass, these raw strings can be mapped to human-readable locations (e.g., 'Building 5, 2nd Floor').


Question 7

An IT administrator is setting up guest access on a corporate network using ClearPass. They have configured the RADIUS service correctly and enabled the Allow All MAC AUTH method. However, they notice that clients are not redirected to the captive portal for authentication. What is the likely reason for this issue?



Answer : C

Redirection to a captive portal is triggered by the Network Access Device (NAD) based on the RADIUS response from ClearPass. If ClearPass returns a role or attribute (like a redirect-URL or a specific 'logon' role) that the gateway does not recognize or support, the gateway will not intercept the user's web traffic. The 'captive portal access' value (often a VSA or a filter-ID) must exactly match a pre-configured role on the Aruba gateway that has the 'Captive Portal' profile attached.


Page:    1 / 14   
Total 111 questions