Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

HPE6-A78 Exam - Topic 10 Question 28 Discussion

You have an Aruba Mobility Controller (MC). for which you are already using Aruba ClearPass Policy Manager (CPPM) to authenticate access to the Web Ul with usernames and passwords You now want to enable managers to use certificates to log in to the Web Ul CPPM will continue to act as the external server to check the names in managers' certificates and tell the MC the managers' correct rotein addition to enabling certificate authentication. what is a step that you should complete on the MC?
A) Verify that the MC has the correct certificates, and add RadSec to the RADIUS server configuration for CPPM
B) install all of the managers' certificates on the MC as OCSP Responder certificates
C) Verify that the MC trusts CPPM's HTTPS certificate by uploading a trusted CA certificate Also, configure a CPPM username and password on the MC
D) Create a local admin account mat uses certificates in the account, specify the correct trusted CA certificate and external authentication

HPE6-A78 Exam - Topic 10 Question 28 Discussion

Actual exam question for HP's HPE6-A78 exam
Question #: 28
Topic #: 10
[All HPE6-A78 Questions]

You have an Aruba Mobility Controller (MC). for which you are already using Aruba ClearPass Policy Manager (CPPM) to authenticate access to the Web Ul with usernames and passwords You now want to enable managers to use certificates to log in to the Web Ul CPPM will continue to act as the external server to check the names in managers' certificates and tell the MC the managers' correct rote

in addition to enabling certificate authentication. what is a step that you should complete on the MC?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

0/2000 characters
Kallie
9 months ago
Not sure if this is the best approach, seems a bit off.
upvoted 0 times
...
Stephanie
9 months ago
Totally agree with A, gotta verify those certs first!
upvoted 0 times
...
Lyla
9 months ago
Wait, are we really using OCSP Responder certs for this?
upvoted 0 times
...
Joaquin
9 months ago
I think C makes more sense, though.
upvoted 0 times
...
Lavina
9 months ago
A is definitely the right move!
upvoted 0 times
...
Lauran
10 months ago
I practiced a similar question where we had to ensure the MC trusted the CA certificate, so I think option C makes the most sense here.
upvoted 0 times
...
Olen
10 months ago
I feel like installing the managers' certificates as OCSP Responder certificates might not be the right approach. It seems more like a different setup.
upvoted 0 times
...
Janine
10 months ago
I remember something about adding RadSec to the RADIUS server configuration, but I can't recall if that's necessary for certificate authentication.
upvoted 0 times
...
Lai
10 months ago
I think we need to verify the MC trusts CPPM's HTTPS certificate, but I'm not entirely sure if we also need to configure a username and password on the MC.
upvoted 0 times
...
Hobert
10 months ago
Okay, let's see. The packet capture indicates the use of TLS_RSA_WITH_RC4_128_SHA, which is a valid cipher suite. The session ID is also present, so it seems like a valid TLS session. My guess is that the issue is related to the TLS session being resumed, so I'll carefully consider that option.
upvoted 0 times
...
Ryan
10 months ago
The 'Maximum number of snapshots in memory' option in the Monitoring tab sounds like it might be the right choice. That seems like the most relevant setting to control the number of snapshots.
upvoted 0 times
...
Amie
10 months ago
Hmm, the customer wants to host Ezmeral Data Fabric on Kubernetes, so I'm thinking the Apollo systems might be a good fit since they're designed for Kubernetes workloads.
upvoted 0 times
...
Dominga
10 months ago
I remember learning that allopurinol is a structural analog of hypoxanthine, which is a purine. So I'm going to go with B, purine.
upvoted 0 times
...

Save Cancel