ExamGecko
Question list
Search
Search

Related questions











Question 118 - HPE7-A01 discussion

Report
Export

you are implementing ClearPass Policy Manager with EAP-TLS for authenticating all corporate-owned devices.

What are two possible solutions to the problem of deploying client certificates to corporate MacBooks that are joined to a Windows domain? (Select two.)

A.
ClearPass OnBoard
Answers
A.
ClearPass OnBoard
B.
Windows Server PKl and a GPO
Answers
B.
Windows Server PKl and a GPO
C.
Apple Configurator and a GPO
Answers
C.
Apple Configurator and a GPO
D.
ClearPass OnGuard
Answers
D.
ClearPass OnGuard
E.
Mobile Device Manager
Answers
E.
Mobile Device Manager
Suggested answer: A, B

Explanation:

The reason is that ClearPass OnBoard is a tool that allows you to enroll Mac computers into a ClearPass Policy Manager site using an Apple MDM push certificate. This certificate can be obtained from Apple or from a third-party PKI provider.

Apple Configurator is a tool that allows you to configure and deploy Mac computers using a GPO. This tool can also be used to enroll Mac computers into a ClearPass Policy Manager site using an Apple MDM push certificate.

The statements that are true regarding Aruba NAE agents are A and C.

A) A single NAE script can be used by multiple NAE agents. This means that you can create different instances of the same script with different parameters or settings. For example, you can use the same script to monitor different VLANs or interfaces on the switch1.

C) NAE agents will never consume more than 10% of switch processor resources. This is a built-in safeguard that prevents the agents from affecting the switch performance or stability. If an agent exceeds the 10% limit, it will be automatically disabled and an alert will be generated2.

The other options are incorrect because:

B) NAE agents are not active at all times. They can be enabled or disabled by the user, either manually or based on a schedule. They can also be disabled automatically if they encounter an error or exceed the resource limit1.

D) NAE scripts do not need to be reviewed and signed by Aruba before being used. You can create your own custom scripts using Python and upload them to the switch or Aruba Central. You can also use the scripts provided by Aruba or other sources, as long as they are compatible with the switch firmware version1.

E) A single NAE agent cannot be used by multiple NAE scripts. An agent is an instance of a script that runs on the switch. Each agent can only run one script at a time1.

asked 16/09/2024
Kefash White
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first