While configuring a guest solution, the customer is requesting that guest user receive access for four hours from their first login. Which Guest Account Expiration would you select?
A. expire_after
B. do_expire
C. expire_time
D. expire_ postlogin
Refer to the Exhibit:


A customer wants to integrate posture validation into an Aruba Wireless 802.1X authentication service
During testing, the client connects to the Aruba Employee Secure SSID and is redirected to the Captive Portal page where the user can download the OnGuard Agent After the Agent is installed, the client receives the Healthy token the client remains connected to the Captive Portal page ClearPass is assigning the endpoint the following roles: T2-Staff-User. (Machine Authenticated! and T2-SOL-Device. What could cause this behavior?
A. The Enforcement Policy conditions for rule 1 are not configured correctly.
B. Used Cached Results: has not been enabled In the Aruba 802.1X Wireless Service
C. RFC-3576 Is not configured correctly on the Aruba Controller and does not update the role.
D. The Enforcement Profile should bounce the connection instead of a Terminate session
When is it recommended to use a certificate with multiple entries on the Subject Alternative Name?
A. The ClearPass servers are placed in different OnGuard zones to allow the client agent to send SHV updates.
B. Using the same certificate to Onboard clients and the Guest Captive Portal on a single ClearPass server.
C. The primary authentication server Is not available to authenticate the users.
D. The ClearPass server will be hosting captive portal pages for multiple FQDN entries
Under Onboard management and control, which option will deny the user from re-provisioning the device a second time?
A. Revoke and Delete certificate
B. Delete user
C. Revoke certificate
D. Delete certificate
Refer to the exhibit: A customer has configured a service with the Onboard Devices Repository as an Authentication Source and an Active Directory Domain Server as an Authorization Source. What will happen if the client certificate is still valid and the user account associated with the certificate is disabled in Active Directory?


A. ClearPass will not process the request
B. Enforcement will apply the [Deny Access Profile]
C. ClearPass will redirect the client to Onboard again
D. ClearPass will block network access to the device
E. ClearPass will allow the device to access the network.
Refer to the exhibit:


The customer configured an 802.1x service with different enforcement actions for personal and corporate
laptops. The corporate laptops are always being redirected to the BYOD Portal. The customer has sent
you the above screenshots.
How would you resolve the issue? (Select two)
A. Modify the enforcement policy and change the rule evaluation algorithm to select first match
B. Modify the enforcement policy and re-order the condition with posture not_equals to healthy as the sixth condition
C. Modify the enforcement policy and re-order the EAP-PEAP with [user authenticated] rule to the last condition.
D. Modify the enforcement policy and re-order the condition with Posture - Unknown as the fifth condition
E. Remove the EAP-PEAP with [user authenticated] condition for Onboard and create another service
A customer has acquired another company that has its own Active Directory infrastructure The 802 1X authentication works with the customers original Active Directory servers but the customer would like to authenticate users from the acquired company as well. What steps are required, in regards to the Authentication Sources, in order to support this request? (Select two.)
A. Create a new Authentication Source, type Active Directory.
B. Join the ClearPass server(s) to the new AD domain.
C. Add the new AD server(s) as backup into the existing Authentication Source.
D. There is no need to Join ClearPass to the new AD domain.
E. Create a new Authentication Source, type Generic LDAP.
Refer to the exhibit:




You have been asked to help a Customer troubleshoot an issue. They have configured an Aruba OS
switch (Aruba 2930 with 16.09) to do MAC authentication with profiling using ClearPass as the
authentication source. They cannot get it working.
Using the screenshots as a reference, how will you fix the issue?
A. Delete the initial role in the Aruba OS switch to force the device to get the server derived user roles
B. Use a CoA to bounce the switch port to force the port to change to the correct Aruba user role
C. Change the Vendor settings for the Aruba OS switch to "Aruba" so that the enforcement will use the correct VSAs
D. Modify the enforcement profile conditions with Aruba Vendor specific attributes and Aruba-user- roles
E. User-roles are case sensitive, update the correct role with correct case in the enforcement profile
Refer to the exhibit:



Your company has a postgres SQL database with the MAC addresses of the company-owned tablets You
have configured a role mapping condition to tag the SQL devices. When one of the tablets connects to the
network, it does not get the correct role and receives a deny access profile.
How would you resolve the issue?
A. Remove SQL condition from role mapping policy and add it under the enforcement policy conditions.
B. Edit the SQL authentication source niter attributes and modify the SQL server filter query.
C. Add the SQL server as an authentication source and map .t under the authentication tab in the service.
D. Enable authorization tab in the service and add the SQL server as an authorization source.
What is the Secure SSID {otherwise referred to as Single SSID) OnBoard deployment service workflow?
A. OnBoard Provisioning RADIUS service, OnBoard Authorization RADIUS service. OnBoard Pre-Auth Application service, OnBoard Provisioning RADIUS service
B. OnBoard Provisioning RADIUS service, OnBoard Pre-Auth RADIUS service, OnBoard Authorization Application service. OnBoard Provisioning RADIUS service
C. OnBoard Provisioning RADIUS service, OnBoard Pre-Auth Application service. OnBoard Authorization Application service, OnBoard Provisioning RADIUS service
D. OnBoard Provisioning RADIUS service, OnBoard Authorization Application service, OnBoard Pre- Auth Application service, OnBoard Provisioning RADIUS service