Your customer is a large hotel that would like to use a single VLAN per floor and isolate each room's wired network port from the others. Which CX switch feature should you recommend for the simplest solution?
Answer : C
To isolate wired ports on the same VLAN on a large scale (such as hotel rooms) but allow communication within the same VLAN for common areas, Private VLANs (PVLANs) are recommended. PVLANs allow segmentation within a single VLAN by dividing it into primary and secondary VLANs, controlling communication between ports.
VPN and VXLAN are overlay technologies for different purposes.
UBT (User-Based Tunneling) is related to wireless user segmentation, not wired port isolation.
Therefore, PVLANs provide the simplest and most effective solution to isolate room ports within a single VLAN.
Aruba Private VLAN Configuration Guide
HPE Aruba VLAN and PVLAN Best Practices
ArubaOS-CX Network Segmentation Documentation
A customer is experiencing authentication failures when clients connect to a new EAP-TLS SSID.



Based on the logs and packet capture above, what is the cause of the failure?
Answer : B
Based on the output, which Local Priority (LP) value will be applied to an incoming packet from interface 2/1/39 marked with DSCP 46 and CoS 7?


Answer : A
The Local Priority (LP) applied to an incoming packet marked with DSCP 46 and CoS 7 depends on the configured QoS mapping.
DSCP 46 corresponds to Expedited Forwarding (EF), which is typically mapped to the highest priority.
CoS 7 also indicates high priority.
According to the QoS policy shown, the LP assigned is 1, indicating the highest priority level.
ArubaOS-CX QoS Mapping Guide
HPE Aruba DSCP to Local Priority Mapping Documentation
Aruba CX Switch QoS Best Practices
You are configuring OSPF between two CX switches but cannot see any neighbors. Based on the output, how would you fix the problem?

Answer : D
OSPF neighbors not forming adjacency and stuck in the 2WAY state typically indicates that the interface is set to passive mode, preventing OSPF Hello packets from being sent or received on that interface.
Removing passive mode on VLAN 182 allows OSPF Hello messages to be exchanged and adjacency to form.
Options involving network type or costs do not affect adjacency states related to passive interfaces.
The max-metric router-lsa on-startup affects LSA advertisements, not adjacency formation.
Therefore, the fix is to configure no passive-interface vlan182.
ArubaOS-CX OSPF Troubleshooting Guide
OSPF Protocol RFC 2328
HPE Aruba Networking Configuration Guides
Which statement is valid when enabling ARP protection features on HPE Aruba Networking CX switches?
Answer : B
When enabling ARP protection, it is best practice to wait at least a week after enabling DHCP snooping before enabling ARP protection in a live network. This allows the DHCP snooping binding table to stabilize, ensuring ARP protection has accurate IP-MAC bindings, reducing false positives.
Immediate ARP protection may cause legitimate traffic to be dropped.
Lease times and DHCP server utilization are less critical.
This staged approach minimizes disruption.
ArubaOS-CX Security Features Best Practices
HPE Aruba ARP Protection Configuration Guide
Aruba Network Security Deployment Guidelines
A customer's infrastructure is set up to use both primary and secondary gateway clusters on the SSID profile based on best practices. Why do they have an equal split of their 144 APs across the primary gateway cluster and the secondary gateway cluster?
Answer : C
Refer to the exhibit.

To which devices has AP-1 established tunnels?
Answer : A