[Aug-2021] Updated Aruba Certified Switching Professional (ACSP) V1 HPE6-A45 Exam Questions BUNDLE PACK [Q42-Q67]

Share

[Aug-2021] Updated Aruba Certified Switching Professional (ACSP) V1 HPE6-A45 Exam Questions BUNDLE PACK

Master The HP Content HPE6-A45 EXAM DUMPS WITH GUARANTEED SUCCESS!

NEW QUESTION 42
A company starts to have issues with too many rules in the dynamic ACLs applied to AOS-Switch ports. Administrators decide to remove some of the common rules from the dynamic ACLs and enforce them in an ACL applied to the users' VLAN instead.
What is one rule that administrators should keep in mind to ensure that the new ACLs control traffic as they expect?

  • A. ACLs applied to VLANs cannot control ICMP traffic, do the dynamic ACLs must include the ICMP rules.
  • B. If a port supports multiple clients, every dynamic ACL applied to one client filters traffic for all clients.
  • C. Traffic must be permitted by both the dynamic ACL and the VLAN ACL in order to be permitted.
  • D. Administrators should add an explicit deny at the end of the dynamic ACLs, so traffic will hit VLAN ACL.

Answer: C

 

NEW QUESTION 43
AOS-Switches authenticate guests to ClearPass with captive portal. An administrator notices that some guests are unable to reach the captive portal page. What will resolves this issue?

  • A. Permit Allow All MAC-Auth on the ClearPass Portal.
  • B. Permit DNS on the ClearPass Portal.
  • C. Permit HTTP or HTTPS on the ClearPass Portal.
  • D. Permit DHCP on the ClearPass Portal.

Answer: C

 

NEW QUESTION 44
Refer to the exhibits.
Exhibit 1

Exhibit 2

A company does not require authentication for security, but AOS-Switches are set up to use local MAC authentication (LMA) to assign the correct VLAN and priority to IP phones. IP phones and computers belong to different VLANs. Each device is supposed to connect to a specific port, but sometimes users connect their devices to the wrong ports and cannot receive access without help from IT.
How can a network administrator configure the switches to eliminate this issue?

  • A. Add the MAC addresses for computers to the myPhones MAC group.
  • B. Apply LMA to all edge switch ports, and set the unauth VLAN to the user VLAN.
  • C. Create a user role that applies the user VLAN, and set this role as the initial role.
  • D. Set the address limit to 2 on the switch ports that apply LMA.

Answer: A

 

NEW QUESTION 45
Refer to the exhibit.
Exhibit 1

Exhibit 2

Traffic between the servers in Area 1 takes a less optimal path rather than the link associated with VLAN 1000, subnet 10.0.0.0/30. Based on the exhibits, why is this the case?

  • A. OSPF routing switches choose the best intra area routes based on Area 1 links only
  • B. Switch-1 and Switch-2 cannot achieve adjacency on VLAN 1000 due to mismatches
  • C. The metric on the VLAN 1000 interface is too low
  • D. The link between Switch-1 and Switch-2 has gone down

Answer: A

 

NEW QUESTION 46
Refer to the exhibit.

What must the network administrator do on Switch-1 to enable this switch to advertise 192.0.2.0/24 to the router at 192.168.1.1?

  • A. Enable eBGP multihop to the 192.168.1.1 neighbor.
  • B. Redistribute OSPF routes into the BGP process
  • C. Enter a static route to 192.0.2.0/24 to the black hole.
  • D. Enter the network 192.168.1.0/24 command in the BGP context.

Answer: C

 

NEW QUESTION 47
A network administrator can set the OSPF metric-type on an AOS-Switch to Type 1 or Type 2. What is the difference?

  • A. A Type 2 metric marks external routes that can be advertised in NSSAs, while a Type 1 metric marks external routes that can only be advertised in normal areas.
  • B. A Type 2 metric stays the same as the external route is advertised, while a Type 1 metric increments with internal OSPF link costs.
  • C. A Type 2 metric is assigned to multiple external routes that are aggregated together, while a Type 1 metric does not permit external route aggregation.
  • D. A Type 2 metric assigns cost 1 to a 100 Gbps link, while a Type 1 metric assigns cost 1 to all links of
    100 Mbps or higher.

Answer: B

 

NEW QUESTION 48
Refer to the exhibits.
Exhibit 1

Exhibit 2

Switch-1 and Switch-2 are configured to provide VRRP in VLAN 2. The default gateway for VLAN 2 is set to the VRRP virtual IP. Client-1 in VLAN 2 cannot ping its default gateway.
Based on the exhibits, what can administrators determine?

  • A. The VRRP preempt delay time has not yet expired, and administrators should try to ping the gateway again in several minutes.
  • B. Preempt mode is enabled on both Switch-1 and Switch-2, so the Master role continues to alternate between them, and the pings go astray.
  • C. Switch-1 and Switch-2 have the same virtual router ID. The conflict interferes with connectivity.
  • D. This is the expected behavior, and Switch-1 should still be able to route traffic for Client-1.

Answer: D

 

NEW QUESTION 49
Refer to the exhibit.

Several interfaces on an AOS-Switch enforce 802.1X to a Radius server at
10.254.202.202. The interface 802.1X settings are shown in the exhibit, and 802.1X is also enabled globally. The security team have added a requirement for port security on the interfaces as well. Before administrators enable port security, which additional step must they complete to prevent issues?

  • A. Manually add legitimate MAC addresses to the switch authorized MAC list.
  • B. Enable eavesdropping protection on the interfaces.
  • C. Enable DHCP snooping on VLAN 20.
  • D. Set 802.1X client limit on the interfaces.

Answer: C

 

NEW QUESTION 50
Exhibit

Several interface on an AOS-Switch enforce 802. 1X to a RADIUS server at
10.254.202.202. The interface
802. 1X settings are shown in the exhibit, and 802. 1X is also enabled globally. The security team have added a requirement for port security on the interfaces as well. Before administrators enable port security, which additional step must they complete to prevent issues?

  • A. Enable DHCP snooping on VLAN 20.
  • B. Enable eavesdropping protection on the interfaces.
  • C. Manually add legitimate MAC addresses to the switch authorized MAC list.
  • D. Set an 802.1X client limit on the interfaces.

Answer: C

 

NEW QUESTION 51
Refer to the exhibit.

The exhibit shows configurations for interface 5 and VLAN 20. Note that DHCP snooping and ARP protection are also enabled.
A network administrator finds that interface 5 on an AOS-Switch is disabled. The administrator re-enables the interface, but it shuts down again. What should the administrator investigate?

  • A. a device that sends unauthorized ARP messages
  • B. a loop on the interface
  • C. rogue DHCP server
  • D. a device that sends too much unicast traffic

Answer: B

 

NEW QUESTION 52
Refer to the exhibit.

An AOS-Switch has the ACL shown in the exhibit. A network administrator then enters these commands:
Switch(config)# mac-access-list standard myACL
Switch(config-std-macl)# 25 deny 007d.45cc.0000 0000.0000.ffff
How does this ACL treat these frames:
1 = 007d.45cc.ffff 2 = 007d.45cc.0000

  • A. It permits both frames.
  • B. It denies frame 1 and permits frame 2.
  • C. It denies both frames.
  • D. It permits frame 1 and denies frame 2.

Answer: C

 

NEW QUESTION 53
A company has AOS-Switches, Aruba ClearPass, and Aruba AirWave. A network administrator needs to set up a new switch with the same settings found on other switches in the company.
Which action is likely to be the most useful to perform the task?

  • A. Retrieve the running config from ClearPass.
  • B. Use the configuration audit tool on AirWave.
  • C. Access the Network Device view on ClearPass.
  • D. View usage patterns on the switches on AirWave.

Answer: A

 

NEW QUESTION 54
Refer to the exhibits.
Exhibit 1

Exhibit 2

The IP phone in the exhibit is set up to complete 802.1x authentication to the network. How can the netwotk administrator prevent a user on the computer from receiving network access without authentication?

  • A. Set an 802.1X client limit of 2 on interface 1.
  • B. Enable MAC-based VLANs on interface 1.
  • C. Enable static mode port security on interface 1.
  • D. Set up the MAC filter on interface 1.

Answer: A

 

NEW QUESTION 55
A company has a wireless Aruba solution and wired users that connect to AOS-Switches. The company wants deep insight into the types of applications that wired users run. The company also wants more control over the traffic.
What can the company do to meet these goals?

  • A. Configure extended IP ACLs on the AOS-Switches to filter the traffic.
  • B. Set up remote traffic mirroring between the AOS-Switches and Aruba Mobility Controllers.
  • C. Configure RMON receives on the switches.
  • D. Use tunneled node to send traffic through an Aruba Mobility Controller

Answer: D

 

NEW QUESTION 56
An AOS-Switch needs to use captive portal to integrate with an Aruba ClearPass Guest solution. The solution should allow guests to connect their own devices to the network, be redirected to a portal, log in, and be granted access transparently.
What is one setting administrators should configure for this solution?

  • A. RADIUS MAC-Auth should be enabled on the guest ports.
  • B. Web-Auth should be enabled on the guest ports.
  • C. ClearPass should be defined as the enhanced Web Auth (EWA) server.
  • D. BYOD redirect should be enabled globally.

Answer: A

 

NEW QUESTION 57
Exhibit


In the exhibits, VLAN 20 under a device name indicates that device is configured with that VLAN.
The exhibits also indicate whether VLAN 20 is statically configured on each link, either as an untagged or a tagged VLAN. If the link has no label, VLAN 20 is not statically configured on that link.
A network administrator needs to deploy AOS-Switches that use port-based tunneled node.
The plan calls for tunneled-node endpoints to be assigned to VLAN 20 and for the Aruba Mobility Controller to handle the tunneled-node traffic at Layer 2. Which exhibit shows the correct plan for VLAN 20 in the wired infrastructure?

  • A. B
  • B. D
  • C. A
  • D. C

Answer: D

 

NEW QUESTION 58
Refer to the exhibit.

An administrator created a backplane stack with the plug-and-play method and did not alter the default backplane stacking settings. Later, two backplane stacking links failed as shown in the exhibit. The network administrator then restored the failed links.
When the stack is reformed, which switches become commander and standby?

  • A. Member 4 remains commander, and Member 1 becomes standby
  • B. Member 1 becomes commander, and Member 2 becomes standby
  • C. Member 1 becomes commander, and Member 4 becomes standby
  • D. Member 4 remains commander, and Member 5 remains standby

Answer: A

 

NEW QUESTION 59
Refer to the exhibits.
Exhibit 1

Exhibit 2

Network administrators are alerted to high interface utilization on a switch by a management solution. They examine the utilization on the uplink interfaces several times an hour during problem times. The exhibit shows output typical of times of congestion. The administrators want to allocate bandwidth fairly and reduce congestion on the uplinks.
What could help meet these requirements?

  • A. an outbound rate limit on interfaces 1 and 2
  • B. an outbound rate limit on each edge port
  • C. a per-queue rate limit on interfaces 1 and 2
  • D. a broadcast rate limit on each edge port

Answer: D

 

NEW QUESTION 60
Refer to the exhibits.
Exhibit 1

Exhibit 2

The network administrator needs to set up BGP between the two company switches, Switch-1 and Switch-2. The BGP connection does not establish. Based on the exhibits, what does the administrator need to do to fix the issue?

  • A. Enable the multihop option for the neighbor on each of the switches.
  • B. Set the update source for the neighbor to the local loopback interface on each switch.
  • C. Enable BGP on the interfaces that the switches use to reach each other.
  • D. Enter the network command for 10.0.0.0/24 in the router BGP mode on each switch.

Answer: B

 

NEW QUESTION 61
A customer wants access layer switches that support routing, ACLs, backplane stacking, and Smart rate ports.
The customer asks about Aruba 5400R z 12 switches.
Which Aruba Switch model would better meet the customer's requirements?

  • A. 0
  • B. 1
  • C. 2930F
  • D. 2

Answer: B

Explanation:
Reference: https://www.arubanetworks.com/assets/so/SB_CampusSwitching.pdf

 

NEW QUESTION 62
Refer to the exhibit.

Switch-1 and Switch-2 connect on interface A23. The switches experience a connectivity issue. The network administrator sees that both switches show this interface as up. The administrator sees the output shown in the exhibit on Switch-1.
What is a typical issue that could cause this output?

  • A. asymmetric routing introduced by a routing protocol
  • B. a jumbo frame mismatch
  • C. mismatched subnet mask on the VLAN for the link
  • D. an issue with VLAN mismatch

Answer: A

 

NEW QUESTION 63
Refer to the exhibits.
Exhibit 1.

Exhibit 2.

The VoIP phone connects, authenticates successfully, and is dynamically assigned to tagged VLAN 6. The endpoint connected to the phone does not authenticate but starts to send untagged traffic.
How does the switch handle this traffic?

  • A. It forwards the traffic in VLAN 6.
  • B. It drops the traffic.
  • C. It relays the traffic to the RADIUS server for authentication.
  • D. It forwards the traffic in VLAN 5.

Answer: C

 

NEW QUESTION 64
Refer to the exhibits.
Exhibit 1

Exhibit 2

Switch-1 and Switch-2 are configured to provide VRRP in VLAN 2. The default gateway for VLAN 2 is set to the VRRP virtual IP. Client-1 in VLAN 2 cannot ping its default gateway.
Based on the exhibits, what can administrators determine?

  • A. This is the expected behavior, and Switch-1 should still be able to route traffic for Client-
    1.
  • B. The VRRP preempt delay time has not yet expired, and administrators should try to ping the gateway again in several minutes.
  • C. Preempt mode is enabled on both Switch-1 and Switch-2, so the Master role continues to alternate between them, and the pings go astray.
  • D. Switch-1 and Switch-2 have the same virtual router ID. The conflict interferes with connectivity.

Answer: B

 

NEW QUESTION 65
An AOS-Switch enforces 802.1X. It receives an Access-Accept with this HPE VSA from its Radius server:
Attribute Name and ID = HPE-User-Role (25) Value = contractor
The switch then rejects the client. What is one requirement for the switch to accept the message and authorize the client?

  • A. The initial user role must be set to the factory default permit any role.
  • B. The RADIUS server settings must permit dynamic authorization.
  • C. User role authorization must be enabled globally on the switch.
  • D. An aaa authentication local user group must have the contractor name.

Answer: B

 

NEW QUESTION 66
Network administrators need to configure a BGP neighbor on an AOS-Switch. What defines the neighbor as an iBGP neighbor?

  • A. It has BGP synchronization enabled.
  • B. Its update source is set to a private company IP address.
  • C. Its remote-AS is the same as the AOS-Switch BGP AS.
  • D. It has an AS number in the range of 64512 to 64535.

Answer: C

 

NEW QUESTION 67
......

Pass HP HPE6-A45 Exam – Experts Are Here To Help You: https://www.premiumvcedump.com/HP/valid-HPE6-A45-premium-vce-exam-dumps.html