Which of the following statements is true based on the Access Tracker output shown below?
A. The client wireless profile is incorrectly setup.
B. Clearpass does not have a service enabled for MAC authentication.
C. The client MAC address is not present in the Endpoints table in the Clearpass database.
D. The client used incorrect credentials to authenticate to the network.
E. The RADIUS client on the Windows server failed to categorize the service correctly.
Which of the following are valid policy simulation types in Clearpass? (Choose 3)
A. Role Mapping
B. Endpoint Profiler
C. Authorization Attributes
D. Chained Simulation
E. Enforcement Policy
Below is a screenshot of the Guest Role Mapping Policy: What is the purpose of this Role Mapping Policy?
A. To send a firewall role back to the controller based on the Guest User's Role ID.
B. To assign Controller roles to guests.
C. To display a role name on the Self-registration receipt page.
D. To assign ClearPass roles to guests based on the guest's Role ID as seen during authentication.
E. To assign all 3 roles of [Contractor], [Guest] and [Employee] to every guest user.
Below is a screenshot of a self-registration receipt: Which of the following is true?
A. Expiration time for guest accounts can be modified by the visitor.
B. Receipt Actions such as 'Download account details' cannot be modified in the self-registration editor.
C. Company Name field cannot be removed from the registration page using the self-registration editor.
D. The user will only be able to login between the Activation and Expiration time.
E. The user must be logged in before they can use the 'Download account details' link.
Refer to the screenshot below:
Which of the following is true of the MAC-Guest-Check SQL query authorization source?
A. It's used to check if the MAC address status is known in the endpoints table
B. It's used to check if the guest account has expired
C. It's used to check if the MAC address status is unknown in the endpoints table
D. It's used to check how long it's been since the last web login authentication
E. It's used to check if the MAC address is in the MAC Caching repository
Below is a screenshot of a user logged in to the Self-Service Portal:
Notice the traffic received and traffic sent statistics. Which of the following is true?
A. These show the total amount of traffic the guest transmitted after account expiration, as seen through RADIUS accounting messages sent from the NAD to ClearPass.
B. These show the total amount of traffic the guest transmitted, as seen through RADIUS accounting messages sent from the NAD to ClearPass.
C. These show the total amount of traffic the NAD transmitted to ClearPass, as seen through RADIUS accounting messages from the NAD to ClearPass.
D. These show the total amount of traffic the guest transmitted, as seen through RADIUS CoA packets from the NAD to ClearPass.
Which of the following statements is true about the skin plugins in ClearPass guest?
A. Skins are created by Aruba Professional Services.
B. Skins allow addition of content items to web login pages.
C. Skins are used to create hotspot login pages.
D. Skins are used to create Onboard registration pages.
E. Skins allow customers to implement advertising.
What does a client need for it to perform EAP-TLS successfully? (Choose 2)
A. Username and Password
B. Client Certificate
C. Pre-shared key
D. Certificate Authority
E. Server Certificate
Which of the following is NOT a function of ClearPass Onboard?
A. Configure network settings
B. Provision device credentials
C. Remote wipe and control
D. Revoke device credentials
E. Provisioning of VPN Settings
Which of the following authentication protocols can be used for authenticating Windows clients that are Onboarded? (Choose 2)
A. PEAP with MSCHAPv2
B. EAP-GTC
C. EAP-TLS
D. PAP
E. CHAP
Which of the following statements is true about the Clearpass hardware appliances?
A. DHCP can be used to assign IP addresses to management and data ports.
B. Both Management and Data Ports must be configured.
C. Clearpass has a default management IP of 172.16.0.254.
D. Only static IP addresses are allowed on the management and data ports.
E. The maximum number of devices supported is 5000.
What must be configured to enable RADIUS authentication with Clearpass on a network access device (NAD)? (Choose 2)
A. An NTP server needs to be set up on the NAD.
B. A bind username and bind password must be provided.
C. A shared secret must be configured on the Clearpass server and NAD.
D. The Clearpass server must have the network device added as a valid NAD.
E. The Clearpass server certificate must be installed on the NAD.
Refer to the screen capture below If a user from the department "HR" connects on Monday using their Windows Laptop to a switch that belongs to the Device Group HQ, what role is assigned to the user in Clearpass?
A. Executive
B. HR Local
C. Employee
D. Guest
E. Vendor
Which of the following statements is NOT true about the configuration of a generic LDAP server as an External Authentication Server in Clearpass?
A. The bind DN can be in the administrator@domain format.
B. The list of attributes fetched from an LDAP server can be customized.
C. An LDAP Browser can be used to search the Base DN.
D. Multiple LDAP servers cannot be configured as authentication sources.
E. Generic LDAP servers can be used as authentication sources.
What does the Posture Token QUARANTINE imply?
A. The client is compliant. However, there is an update available to remediate the client to HEALTHY state.
B. The posture of the client is unknown.
C. The client is infected and is a threat to other systems in the network.
D. The client is out of compliance.
E. The client is out of compliance, but has HEALTHY state.