Winter Sale Special 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ex2p65

Exact2Pass Menu

Question # 4

Examine the attached exhibit.

The network administrators is trying to add a remote location as area 3 to the network shown in the diagram.

Based on current connection restrictions, the administrator cannot connect area 3 directly to area 0. The

network is using AOS-CX switches.

Which feature should the administrator implement to provide connectivity to the remote location?

A.

Not-so-stubby areas

B.

Bidirectional forward detection (BFD)

C.

OSPFv3

D.

Virtual links

Full Access
Question # 5

How is voice traffic prioritized correctly on AOS-CX switches?

A.

By defining device profiles with QOS settings

B.

By placing it in the strict priority queue

C.

By implementing voice VLANs

D.

By implementing weighted fair queueing (WFQ)

Full Access
Question # 6

Examine the following AOS-CX switch configuration:

Which access control entries would allow web traffic to the web servers 10.1.0.100 and 10.1.1.100?

A.

permit tcp servers eq 80

B.

permit tcp any 10.1.0.100 0.0.1.0 eq 80

C.

permit tcp any 10.1.0.100/10.1.1.100 eq 80

D.

permit tcp any 10.1.0.100/255.255.254.255 eq 80

Full Access
Question # 7

Which does VOQ implement that is different from most typical campus switches?

A.

Large ingress packet buffers

B.

vsx

C.

Per-port ASICs

D.

Large egress packet buffers

Full Access
Question # 8

An administrator has configured the following on an AOS-CX switch:

What is the correct ACL rule configuration that would allow traffic from anywhere to reach the web ports on the

two specified servers?

A.

access-list ip server 10 permit tcp any web-servers group web-ports

B.

access-list ip server 10 permit tcp any object-group web-servers object-group web-ports

C.

access-list ip server 10 permit tcp any group web-servers group web-ports

D.

access-list ip server 10 permit tcp any web-servers web-ports

Full Access
Question # 9

An administrator is supporting a network with the access layer consisting of AOS-CX 6300 and 6400 switches. The administrator needs to quickly deploy Aruba IAPs and security cameras in the network, ensuring that the correct QoS and VLAN settings are dynamically applied to the switch ports. Currently, switches are not configured to do device authentication, and no authentication server exists in the network.

Which AOS-CX feature should the administrator use to dynamically assign the policy settings to the correct switch ports?

A.

Device profiles

B.

Change of authorization

C.

Dynamic segmentation

D.

Voice VLANs

Full Access
Question # 10

An administrator in a company of 349 users has a pair of AOS-CX switches with connections to external

networks. Both switches are configured for OSPF. The administrator wants to import external routes on both switches, but assigns different seed metrics to the routes, as well as imports them as external type-1 routes.

What is the best way for the administrator to accomplish this?

A.

Create a route map with the correct route type and metrics

B.

Define the route type and metrics in the OSPF process

C.

Create a classifier policy with the correct route type and metrics

D.

Define a class and policy map with the correct route type and metrics

Full Access
Question # 11

A company is implementing a new wireless design and needs it to support high availability, even during times of switch system upgrades. The solution will involve Aruba Mobility Controller (MC) and Aruba AP connections requiring POE. Which campus AOS-CX switch solution and virtual switching should the company implement at the campus access layer?

A.

AOS-CX 6400 and VSX

B.

AOS-CX 6300 and VSF

C.

AOS-CX 8325 and VSF

D.

AOS-CX 8400 and VSX

Full Access
Question # 12

An administrator of a company has concerns about upgrading the access layer switches. The users rely

heavily on wireless and VoIP telephony. Which is the best recommendation to ensure a short downtime for the users during upgrading the access layer switches?

A.

Install the in-service software upgrade (ISSU) feature with clustering enabled

B.

Install AOS-CX 6300 or 6400 switches with always-on POE

C.

Implement VSF on the AOS-CX access switches

D.

Implement VSX on the AOS-CX access switches

Full Access
Question # 13

An AOS-CX switch is configured to implement downloadable user roles. Examine the AOS-CX switch output:

Based on this output, what is the state of the user’s access?

A.

No downloadable user role exists

B.

MAC authentication has passed, but 802.1X authentication is in progress

C.

The RADIUS request timed out to the AAA server

D.

The port should be configured for 802.1X

Full Access
Question # 14

A network administrator is implementing a configuration plan in NetEdit. The administrator used NetEdit to push the configuration plan to the switch. Which option in the NetEdit planning section should the administrator select to save the configuration running on the switch to the startup-config?

A.

EDIT

B.

VALIDATE

C.

COMMIT

D.

DEPLOY

Full Access
Question # 15

An administrator is managing a pair of core AOS-CX switches configured for VSX. Connected to this core are pairs of aggregation layer AOS-CX switches configured for VSX. OSPF is running between the aggregation and core layers. To speed up OSPF convergence, the administrator has configured BFD between the core and aggregation switches.

What is a best practice the administrator should implement to reduce CPU processing on the switches if a BFD neighbor fails?

A.

Disable ICMP redirects

B.

Implement graceful restart

C.

Increase the BFD echo timers

D.

Increase the VSX keepalive timer

Full Access
Question # 16

Examine the partial output of the BGP routing table of an AOS-CX switch:

The switch is learning about four possible path to reach the 1.0.0.0/8 network. Based on this output, which next-hop route will the AOS-CX select to be placed in the IP routing table?

A.

192.168.1.5

B.

192.168.2.5

C.

192.168.3.5

D.

192 1684 5

Full Access
Question # 17

A network administrator wants to centralize the management of AOS-CX switches by implementing NetEdit.

How should the administrator purchase and/or install the NetEdit solution?

A.

Install as a hardware appliance

B.

Installed on a supported version of RedHat Enterprise Linux

C.

Installed in a virtualized solution by using the Aruba-supplied OVA file

D.

Installed on a supported version of Debian Linux

Full Access
Question # 18

A network administrator is installing NetEdit. In order for NetEdit to manage the AOS-CX switches in the network, what must be defined on the AOS-CX switches? (Choose two.)

A.

Enabling telnet

B.

Defining an admin user password

C.

Defining the https user-group

D.

Enabling the RESTful API for read and write access

E.

Enabling SFTP

Full Access
Question # 19

Which protocol does NetEdit use to discover devices in a subnet during the discovery process?

A.

LLDP

B.

ARP

C.

DHCP

D.

ICMP

Full Access
Question # 20

Examine the following ACL rule policies:

Permit traffic from 10.2.2.1 through 10.2.2.30 to anywhere

Permit traffic from 10.2.2.40 through 10.2.2.55 to anywhere

Deny all others

Based on this policy, place the following ACL rule statements in the correct order to accomplish the above

filtering policy.

A.

deny ip 10.2.2.31 255.255.255.255 any

permit ip 10.2.2.40 255.255.255.248 any

permit ip 10.2.2.48 255.255.255.248 any

deny ip 10.2.2.32 255.255.255.224 any

permit ip 10.2.2.0 255.255.255.192 any

B.

permit ip 10.2.2.40 255.255.255.248 any

permit ip 10.2.2.48 255.255.255.248 any

permit ip 10.2.2.0 255.255.255.192 any

deny ip 10.2.2.31 255.255.255.255 any

deny ip 10.2.2.32 255.255.255.224 any

C.

deny ip 10.2.2.31 255.255.255.255 any

deny ip 10.2.2.32 255.255.255.224 any

permit ip 10.2.2.40 255.255.255.248 any

permit ip 10.2.2.48 255.255.255.248 any

permit ip 10.2.2.0 255.255.255.192 any

D.

deny ip 10.2.2.31 255.255.255.255 any

permit ip 10.2.2.40 255.255.255.248 any

deny ip 10.2.2.32 255.255.255.224 any

permit ip 10.2.2.48 255.255.255.248 any

permit ip 10.2.2.0 255.255.255.192 any

Full Access
Question # 21

Examine the AOS-CS switch output:

Based on this output, what is correct?

A.

802.1X authentication was successful, but MAC authentication is yet to start

B.

802.1X authentication occurred and downloadable user roles are deployed

C.

A local user role was deployed using a ClearPass solution

D.

Only 802.1X authentication is configured on the port

Full Access
Question # 22

An administrator creates an ACL rule with both the “count” and “log” option enabled. What is correct about the

action taken by an AOS-CX switch when there is a match on this rule?

A.

By default, a summarized log is created every minute with a count of the number of matches

B.

Logging will not include certificate and TLS events, but counting will

C.

The “count” and “log” options are processed by the AOS-CX switch’s hardware ASIC

D.

The total in the “log” record and the count could contain different rule matching statistics

Full Access
Question # 23

An administrator has an aggregation layer of 8325CX switches configured as a VSX pair. The administrator is

concerned that when OSPF network changes occur, the aggregation switches will respond to the changes

slowly, and this will affect network connectivity, especially VoIP calls, in the connected access layer switches.

What should the administrator do on the aggregation layer switches to alleviate this issue?D18912E1457D5D1DDCBD40AB3BF70D5D

A.

Implement route aggregation

B.

Implement bidirectional forwarding detection (BFD)

C.

Reduce the hello and dead interval timers

D.

Implement graceful restart

Full Access
Question # 24

A network engineer for a company with 896 users across a multi-building campus wants to gather statistics on an important switch uplink and create actions based on issues that occur on the uplink. How often does an NAE agent gather information from the current state database in regard to the uplink interfaces?

A.

Once every 60 seconds

B.

Once every 1 second

C.

Once every 30 seconds

D.

Once every 5 seconds

Full Access
Question # 25

A company has a third-party AAA server solution. The campus access layer was just upgraded to AOS-CX

switches that perform access control with MAC-Auth and 802.1X. The company has an Aruba Mobility

Controller (MC) solution for wireless, and they want to leverage the firewall policies on the controllers for the wired traffic.

What is correct about how the company should implement a security solution where the wired traffic is

processed by the gateways?

A.

Implement downloadable user roles with a gateway role defined on the AOS-CX switches

B.

Implement local user roles with a gateway role defined on the AOS-CX switches

C.

Implement standards-based RADIUS VSAs to pass policy information directly to the AOS-CX switches and MCs

D.

Implement downloadable user roles with a device role defined on the AOS-CX switches and MCs

Full Access
Question # 26

Examine the network exhibit:

The ACL configuration defined on Core-1 is as follows:

If telnet was being used, which device connection would be permitted and functional in both directions?

(Choose two.)

A.

Client 3 to Client 2

B.

Client 1 to Client 2

C.

Server 2 to Client 2

D.

Server 1 to Client 1

E.

Client 1 to Client 3

Full Access
Question # 27

An administrator is defining a VSX LAG on a pair of AOS-CX switches that are defined as primary and

secondary. The VSX LAG fails to establish successfully with a remote switch; however, after verification, the remote switch is configured correctly. The administrator narrows down the problem to the configuration on the AOS-CX switches.

What would cause this problem?

A.

Local optimization was not enabled on the VSX LAG

B.

The VSX LAG hash does not match the remote peer

C.

The VSX LAG interfaces are in layer-3 mode

D.

LACP was enabled in active mode on the VSX LAG

Full Access
Question # 28

What is required when implementing captive portal an AOS-CX switches?

A.

Certificate installed on the switch

B.

Web server running on the switch

C.

Device fingerprinting

D.

AAA server

Full Access
Question # 29

An administrator will be implementing tunneling between AOS-CX switches and Aruba gateways. Which list of protocols must minimally be allowed by an intermediate firewall between two sets of devices?

A.

IP protocol 50 and UDP 8209

B.

UDP 4500 and IP protocol 47

C.

UDP 8211 and IP protocol 47

D.

UDP 4500 and UDP 8209

Full Access
Question # 30

An administrator will be replacing a campus switching infrastructure with AOS-CX switches that support VSX capabilities. The campus involves a core, as well as multiple access layers. Which feature should the

administrator implement to allow both VSX-capable core switches to process traffic sent to the default gateway in the campus VLANs?

A.

VRF

B.

VRRP

C.

IP helper

D.

Active gateway

Full Access
Question # 31

An administrator has an AOS-CX switch configured with:

router ospf 1

area 0

area 1 stub no-summary

It is the only ABR for area 1. The switch has the appropriate adjacencies to routing switches in areas 0 and 1.

The current routes in each area are:

Area 0: 5 routes (LSA Type 1 and 2)

Area 1: 10 routes (LSA Type 1 and 2)

External routes: 2 (LSA Type 5)

Based on the above configuration, how many OSPF routes will routing switches see in Area 1?

A.

15

B.

6

C.

11

D.

12

Full Access
Question # 32

What is correct regarding rate limiting and egress queue shaping on AOS-CX switches?

A.

Only a traffic rate and burst size can be defined for a queue

B.

Limits can be defined only for broadcast and multicast traffic

C.

Rate limiting and egress queue shaping can be used to restrict inbound traffic

D.

Rate limiting and egress queue shaping can be applied globally

Full Access
Question # 33

An administrator is implementing a multicast solution in a multi-VLAN network. Which statement is true about the configuration of the switches in the network?

A.

IGMP snooping must be enabled on all interfaces on a switch to intelligently forward traffic

B.

IGMP requires join and leave messages to graft and prune multicast streams between switches

C.

IGMP must be enabled on all routed interfaces where multicast traffic will traverse

D.

IGMP must be enabled on all interfaces where multicast sources and receivers are connected

Full Access
Question # 34

An administrator is designing an access layer solution in a data center. A key requirement is to dual-home mission-critical server connections to two different switches, ensuring that the servers always have network access, even during switch software upgrades. This feature should support strictly-controlled provisioning.

What would best meet the administrator's needs when deploying AOS-CX switches?

A.

VSF

B.

Dynamic segmentation

C.

VSX

D.

NAE

Full Access
Question # 35

When implementing user-based tunneling on an AOS-CX switch, which component defines the primary and backup Aruba gateways?

A.

Transit VLAN

B.

Gateway role

C.

Server group

D.

Zone

Full Access
Question # 36

What are best practices when implementing VSX on AOS-CX switches? (Choose two.)

A.

The ISL lag should use the default MTU size.

B.

Timers should be left at their default values.

C.

The default system MAC addresses should be used.

D.

The keepalive connection should use a direct layer-3 connection.

E.

The ISL lag should use at least 10GbE links or faster.

Full Access
Question # 37

An administrator is implementing a downloadable user role solution involving AOS-CX switches. The AAA

solution and the AOS-CX switches can successfully authenticate users; however, the role information fails to

download to the switches. What policy should be added to an intermediate firewall to allow the downloadable

role function to succeed?

A.

Allow TCP 443

B.

Allow UDP 1811

C.

Allow UDP 8211

D.

Allow TCP 22

Full Access
Question # 38

Examine the configuration performed on newly deployed AOS-CX switches:

After performing this configuration, the administrator notices that the switch ports always remain in the EAP start state. What should the administrator do to fix this problem?

A.

Define the server group cppm

B.

Set the ports to client-mode

C.

Create and assign a local user role to the ports

D.

Enable change of authorization (CoA)

Full Access