Question 6

Refer to the scenario.
A customer has an AOS10 architecture that is managed by Aruba Central. Aruba infrastructure devices authenticate clients to an Aruba ClearPass cluster.
In Aruba Central, you are examining network traffic flows on a wireless IoT device that is categorized as
"Raspberry Pi" clients. You see SSH traffic. You then check several more wireless IoT clients and see that they are sending SSH also.
You want an easy way to communicate the information that an IoT client has used SSH to Aruba ClearPass Policy Manager (CPPM).
What step should you take?
  • Question 7

    Refer to the exhibit.

    Which security issue is possibly indicated by this traffic capture?
  • Question 8

    You need to install a certificate on a standalone Aruba Mobility Controller (MC). The MC will need to use the certificate for the Web UI and for implementing RadSec with Aruba ClearPass Policy Manager. You have been given a certificate with these settings:
    Subject: CN=mc41.site94.example.com
    No SANs
    Issuer: CN=ca41.example.com
    EKUs: Server Authentication, Client Authentication
    What issue does this certificate have for the purposes for which the certificate is intended?
  • Question 9

    Refer to the scenario.
    A customer requires these rights for clients in the "medical-mobile" AOS firewall role on Aruba Mobility Controllers (MCs):
    Permitted to receive IP addresses with DHCP
    Permitted access to DNS services from 10.8.9.7 and no other server
    Permitted access to all subnets in the 10.1.0.0/16 range except denied access to 10.1.12.0/22 Denied access to other 10.0.0.0/8 subnets Permitted access to the Internet Denied access to the WLAN for a period of time if they send any SSH traffic Denied access to the WLAN for a period of time if they send any Telnet traffic Denied access to all high-risk websites External devices should not be permitted to initiate sessions with "medical-mobile" clients, only send return traffic.
    The exhibits below show the configuration for the role.

    There are multiple issues with this configuration. What is one change you must make to meet the scenario requirements? (In the options, rules in a policy are referenced from top to bottom. For example,
    "medical-mobile" rule 1 is "ipv4 any any svc-dhcp permit," and rule 8 is "ipv4 any any any permit".)
  • Question 10

    You are configuring gateway IDS/IPS settings in Aruba Central.
    For which reason would you set the Fail Strategy to Bypass?