Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

HPE6-A88 Exam - Topic 4 Question 12 Discussion

A network administrator is configuring a corporate network enforcement policy. The policy includes rules for corporate-issued laptops, MDM-enabled tablets, and personal smart devices. However, the administrator notices that some clients are failing all rules due to a lack of profile data. What should the administrator do to ensure these unprofiled clients can access the profiler collectors and receive a profile using best practices?
A) Add a rule that identifies clients without profiles and assigns them a role allowing limited access to the profiler.
B) Increase the frequency of profile data updates from the endpoint profiler.
C) Set the default enforcement profile to 'Allow Access' for all unprofiled clients.

HPE6-A88 Exam - Topic 4 Question 12 Discussion

Actual exam question for HP's HPE6-A88 exam
Question #: 12
Topic #: 4
[All HPE6-A88 Questions]

A network administrator is configuring a corporate network enforcement policy. The policy includes rules for corporate-issued laptops, MDM-enabled tablets, and personal smart devices. However, the administrator notices that some clients are failing all rules due to a lack of profile dat

a. What should the administrator do to ensure these unprofiled clients can access the profiler collectors and receive a profile using best practices?

Show Suggested Answer Hide Answer
Suggested Answer: A

Best practice for profiling is to never grant full access by default. Instead, the enforcement policy should include a fallback rule for unprofiled devices. This rule assigns a 'Limited Access' or 'Quarantine' role that allows only DHCP and HTTP traffic. This allows the device to communicate just enough to trigger the profiler collectors (like DHCP fingerprinting), after which the device can be re-authenticated with the correct role.


Contribute your Thoughts:

0/2000 characters
Michael
3 days ago
I've seen this issue before, option A is the best practice for sure!
upvoted 0 times
...
Mi
8 days ago
Wait, can unprofiled clients really get access? That seems risky...
upvoted 0 times
...
Maryann
13 days ago
Increasing profile update frequency (option B) might help too!
upvoted 0 times
...
Tijuana
19 days ago
I disagree, option C could lead to security risks.
upvoted 0 times
...
Iola
24 days ago
Definitely go with option A, it makes the most sense!
upvoted 0 times
...
Sunny
29 days ago
I practiced a similar question where we had to manage unprofiled devices, and I think the best practice was to assign them a role. So, I’m leaning towards A.
upvoted 0 times
...
Dante
1 month ago
Setting the default enforcement profile to 'Allow Access' sounds risky. I think it could lead to security issues, but I can't recall if it’s option C or not.
upvoted 0 times
...
Mozell
1 month ago
I feel like increasing the frequency of profile updates could help, but I’m not confident if that’s the right answer here. It seems more like a workaround than a solution.
upvoted 0 times
...
Natalie
1 month ago
I think I remember something about allowing limited access for unprofiled clients. It might be option A, but I'm not entirely sure if that's the best approach.
upvoted 0 times
...

Save Cancel