A company plans to build a resort that includes a hotel with 1610 rooms, a casino, and a convention center. The company is interested in a mobility solution that provides scalability and a service-based approach, where they can rent the
WLAN infrastructure at the convention center to any customer (tenant) that hosts events at the resort.
The solution should provide:
Seamless roaming when users move from the hotel to the casino or the convention center
Simultaneous propagation of the resort and customer-owned SSIDs at the convention center
Null management access upon resort network infrastructure to the customers (tenants)
Configuration and monitor rights of rented SSIDs to the customers (tenants)
Which deployment meets the requirements?
A. Deploy an MM-MC infrastructure with multizone AP's, with one zone for tenant SSIDs.
B. Deploy IAPs along with AirWave, and deploy role-based management access control.
C. Deploy IAPs with zone based SSIDs and manage them with different central accounts.
D. Deploy an MM-MC infrastructure, and create different hierarchy groups for MCs and APs.
E. Deploy IAPs, and manage them with different central accounts.
An organization has several RAPs at different locations that broadcast two SSIDs. The internet-only SSID is in bridge/always mode, and the corporate SSID is in split-tunneling/standard mode. The network administrator deploys 10 more
RAPs in different locations.
Users can successfully connect to the corporate SSID that is propagated by a RAP at a remote location. However, they report that it takes too long to access public internet web sites.
What is one part of the configuration that should be checked by the network administrator to verify this RAP deployment?
A. User roles policies
B. IP pool
C. Operating mode
D. Assigned VLAN
An Aruba Mobility Master (MM) - Mobility Controller (MC) solution is connected to a wired network that is ready to prioritize DSCP marked traffic. A group of WMM-enabled clients sends traffic marked at L2 only.
What must the network administrator do to map those markings to DSCP equivalent values when traffic is received by the APs?
A. Enable WMM in the SSID profile.
B. Enable WMM in the VAP profile.
C. Enable Skype4Business ALG Support.
D. Enable traffic to be marked with session ACLs.
A company with 50 small coffee shops in a single country requires a single mobility solution that solves connectivity needs at both the main office and branch locations. Coffee shops must be provisioned with local WiFi internet access for customers.
The shops must also have a private WLAN that offers communication to resources at the main office to upload sales, request supplies through a computer system, and make phone calls if needed. In order to simplify network operations, network devices at the coffee shops should be cloud managed.
Which technologies best meet the company needs at the lowest cost?
A. IAP VPN
B. SD-Branch
C. Activate with RAPs
D. BOC with CAPs
Refer to the exhibit.

A 7008 Branch Office Controller (BOC) is deployed in a remote office behind a core router. This core does not support 802.1q encapsulation. The Mobility Controller (MC) is the gateway for two tunneling mode SSIDs, as shown in the exhibit. Which two different configuration options ensure that wireless users are able to reach the branch network through the router? (Choose two.)
A. Configure all ports of the BOC as access ports on the controller VLAN, and change the gateway of clients to the core router IP.
B. Configure the uplink of the BOC as an access port on the controller VLAN, and add static routes in the router for the SSID VLAN subnets.
C. Configure the uplink of the BOC as a trunk port that permits the controller and the SSID VLANs. The controller VLAN must be native.
D. Configure the uplink of the BOC as an access port on the controller VLAN, and enable NAT for the SSID VLANs.
E. Configure the uplink of the BOC as a trunk port, tagging the controller and the SSOD VLANs, and enable NAT for the SSID VLANs.
An organization owns a fully functional multi-controller Aruba network with a Virtual Mobility Master (VMM) in VLAN20. They have asked a network consultant to deploy a redundant MM on a different server. The solution must offer the lowest convergence time and require no human interaction in case of failure.
The servers host other virtual machines and are connected to different switches that implement ACLs to protect them. The organization grants the network consultant access to the servers only, and appoints a network administrator to assist with the deployment.
What must the network administrator do so the network consultant can successfully deploy the solution? (Choose two.)
A. Allocate VLAN20 to the second server, and extend it throughout the switches, then reserve one IP address for the second MM and another IP address for its gateway.
B. Allocate VLAN20 to the second server, and permit routing between them, then reserve one IP address for the second MM and another IP address for its gateway.
C. Configure an ACL entry that permits IP protocol 50, UDP port 500, and multicast IP 224.0.0.18.
D. Allocate VLAN20 to the second server, and extend it throughout the switches, then reserve one IP address for the second MM and another for the VIP.
E. Configure an ACL entry that permits UDP 500, TCP 4500, and multicast IP 224.0.0.5.
Refer to the exhibit.

Based on the output shown in the exhibit, which channel offers the highest quality?
A. Channel 1
B. Channel 6
C. Channel 11
D. Channel 14
A fully functional WLAN is deployed in a campus network using the following script.

Which part of the script can a network administrator re-use to assign a different default role to users when they connect to the same SSID in a second building?
A. server group and ssid profile
B. server group and VAP profile
C. server group, aaa profile, and ssid profile
D. server group and VAP
A joint venture between two companies results in a fully functional WLAN Aruba solution. The network administrator uses the following script to integrate the WLAN solution with two radius servers, radius1 and radius2.

While all users authenticate with [email protected] type of credentials, radius1 has user accounts with the domain name portion. Which additional configuration is required to authenticate corp1.com users with radius1 and corp2 users with radius2?

A. Option A
B. Option B
C. Option C
D. Option D
A network administrator has updated the ArubaOS code of a standalone Mobility Controller (MC) that is used for User-Based Tunneling (UBT) to a newer early release. Ever since the MC seems to reject PAPI sessions from the switch with the 10.1.10.10 IP address. Also the controller's prompt is now followed by a star mark: "(MC_VA) [mynode] *#"
When opening a support ticket, an Aruba TAC engineer asks the administrator to gather the crash logs and if possible replicate UBT connection attempts from the switch while running packet captures of PAPI traffic on the controller and obtain the PCAP files. The administrator has a PC with Wireshark and TFTP server using the 10.0.20.20 IP address.
What commands must the administrator issue to accomplish these requests? (Choose two.)

A. Option A
B. Option B
C. Option C
D. Option D
E. Option E
Refer to the exhibit

A network administrator deploys a standalone Mobility Controller (MC) and configures some VAPs within the CAMPUS AP group. The network administrator realizes that none of the VAPs are being broadcasted.
Based on the output shown in the exhibit, what should the network administrator do to solve this problem?
A. Install MC-VA licenses, then install PEF licenses and enabled the PEF feature.
B. Install MC-VA licenses, then reprovision the APs.
C. Install MM licenses, then install PEF licenses and enable the PEF feature.
D. Install MM licenses and install MC-VA licenses, then install RFP licenses.
Users run Skype for Business on wireless clients with no WMM support over an Aruba Mobility Master (MM) - Mobility Controller (MC) based network. When traffic arrives at the wired network, it does not include either L2 or L3 markings.
Which configuration steps should the network administrator take to classify and mark voice and video traffic with UCC heuristics mode?
A. Enable WMM in a VAP profile, and explicitly permit voice and video UDP ports in a firewall policy.
B. Confirm OpenFlow is enabled in the user role and VAP profile. Then enable WMM in a SSID profile, and explicitly permit voice and video UDP ports in a firewall policy.
C. Confirm the MC is the Openflow controller of the MMs and Openflow is enabled in VAP and firewall roles. Enable Skype4Business ALG in UCC profiles.
D. Confirm MM is the Openflow controller of MCs and Openflow is enabled in VAP and firewall roles. Enable Skype4Business ALG in UCC profiles.
Refer to the exhibit.

A network administrator has recently enabled WMM on the VAP's SSID profile and enabled UCC Skype4B ALG at the Mobility Master level. During testing, some voice and video conference calls were made, and it was concluded that the call quality has dramatically improved. However, end to end information isn't displayed in the call's details. Also, Skype4B app-sharing's performance is poor at times.
What must the administrator do next in order to enable end to end call visibility and QoS correction to app-sharing service?
A. Deploy the SDN API Software in the Skype4B Solution and point to the MM.
B. Increase the app-sharing DSCP value in the Skype4B ALG profile.
C. Enable UCC monitoring on the "default-controller" mgmt.-server profile.
D. Enable the App-sharing ALG profile at both MM and MD hierarchy levels.
Refer to the exhibit.

A network administrator is evaluating a deployment to validate that a user is assigned the proper role and reviews the output in the exhibit. How is the role assigned to user?
A. The MC assigned the role based on Aruba VSAs.
B. The MC assigned the machine authentication default user role.
C. The MC assigned the default role based on the authentication method.
D. The MC assigned the role based on server derivation rules.
Refer to the exhibits.

A network administrator deploys User Based Tunneling (UBT) in a corporate network to unify the security policies enforcement. When users authenticate with 802.1X, ClearPass shows Accept results, and sends the Aruba-User-Role attribute as expected. However, the AOS-CX based switch does not seem to build the tunnel to the Mobility Controller (MC) for this user.
Why does the switch fail to run UBT for the user?
A. The switch has not fully associated to the MC.
B. ClearPass is sending the wrong Vendor ID.
C. The switch is not configured with the gateway-role.
D. ClearPass is sending the wrong VSA type.
E. The switch is not configured with the port-access role.