Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

HPE6-A78 Exam - Topic 3 Question 91 Discussion

You have an Aruba solution with multiple Mobility Controllers (MCs) and campus APs. You want to deploy a WPA3-Enterprise WLAN and authenticate users to Aruba ClearPass Policy Manager (CPPM) with EAP-TLS.What is a guideline for ensuring a successful deployment?
D) Deploy certificates to clients, signed by a CA that CPPM trusts.
A) Avoid enabling CNSA mode on the WLAN, which requires the internal MC RADIUS server.
B) Ensure that clients trust the root CA for the MCs' Server Certificates.
C) Educate users in selecting strong passwords with at least 8 characters.

HPE6-A78 Exam - Topic 3 Question 91 Discussion

Actual exam question for HP's HPE6-A78 exam
Question #: 91
Topic #: 3
[All HPE6-A78 Questions]

You have an Aruba solution with multiple Mobility Controllers (MCs) and campus APs. You want to deploy a WPA3-Enterprise WLAN and authenticate users to Aruba ClearPass Policy Manager (CPPM) with EAP-TLS.

What is a guideline for ensuring a successful deployment?

Show Suggested Answer Hide Answer
Suggested Answer: D

For WPA3-Enterprise with EAP-TLS, it's crucial that clients have a trusted certificate installed for the authentication process. EAP-TLS relies on a mutual exchange of certificates for authentication. Deploying client certificates signed by a CA that CPPM trusts ensures that the ClearPass Policy Manager can verify the authenticity of the client certificates during the TLS handshake process. Trust in the root CA is typically required for the server side of the authentication process, not the client side, which is covered by the client's own certificate.


Contribute your Thoughts:

0/2000 characters
Alonso
12 hours ago
I think option B is crucial. Trusting the root CA is key.
upvoted 0 times
...
Elenor
6 days ago
I thought strong passwords were enough, but EAP-TLS seems more complex!
upvoted 0 times
...
Marvel
11 days ago
A is a good point, but I think educating users is key too.
upvoted 0 times
...
Paz
16 days ago
Wait, why is CNSA mode a problem?
upvoted 0 times
...
Luisa
21 days ago
I disagree, D is more critical for security.
upvoted 0 times
...
Marica
26 days ago
Definitely B, clients need to trust the root CA!
upvoted 0 times
...
Ariel
1 month ago
I practiced a question similar to this, and I think educating users about strong passwords is important, but it might not be the main guideline here.
upvoted 0 times
...
Gertude
3 months ago
I feel like option A could be a trap. I vaguely recall something about CNSA mode causing issues with RADIUS.
upvoted 0 times
...
Dierdre
3 months ago
I'm not entirely sure, but I remember something about certificates being crucial for EAP-TLS. Maybe option D is the right choice?
upvoted 0 times
...
Trina
3 months ago
I think option B makes sense because if clients don't trust the root CA, they won't connect properly.
upvoted 0 times
...

Save Cancel