Valid HPE6-A47 Dumps shared by ExamDiscuss.com for Helping Passing HPE6-A47 Exam! ExamDiscuss.com now offer the newest HPE6-A47 exam dumps, the ExamDiscuss.com HPE6-A47 exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com HPE6-A47 dumps with Test Engine here:
Read this scenario thoroughly, and then answer each question that displays on the right side of the screen. An architect proposes these products for a customer who wants a wireless and wired upgrade: Aruba 2930M switches at the access layer Aruba 5406R switches at the core Aruba AP-325s Aruba 7205 Mobility Controllers (MCs), deployed in a cluster Aruba Mobility Master (MM) Aruba ClearPass Cx000V Aruba AirWare The architect also needs to propose a security plan for the solution. The customer has 900 employees and up to 30 guests a day. The customer wants to protect the internal perimeter of the network with authentication and simple access controls. The customer is most concerned about wireless security, but also wants to ensure that only trusted users connect on the wire. However, the customer also wants all wired traffic to be forwarded locally on access layer switches. The customer already has a third-party firewall that protects the data center. The customer wants to use certificates to authenticate user devices, but is concerned about the complexity of deploying the solution. The architect should recommend a way to simplify. For the most part users connect company-issued laptops to the network. However, users can bring their own devices and connect them to the network. The customer does not know how many devices each user will connect, but expects about two or three per-user. DHCP logs indicate that the network supports a maximum of 2800 devices. Refer to the provided scenario. Which solution should the architect recommend on the 2930M switches to authenticate and control wired employee devices?
Correct Answer: C
The solution that the architect should recommend on the 2930M switches to authenticate and control wired employee devices is 802.1X on edge ports and no tunneled node. This solution would provide strong authentication and authorization for the wired devices using certificates, which can be issued and managed by ClearPass. The 802.1X protocol would allow the switches to communicate with ClearPass and enforce user roles and policies based on the device identity and context. The no tunneled node option would allow the wired traffic to be forwarded locally on the access layer switches, as the customer prefers, without tunneling it to the MCs. This option would also reduce the bandwidth consumption and latency on the network core. The other solutions are not optimal for the customer requirements because they either provide weak authentication or require tunneling the wired traffic to the MCs. MAC-Authon edge ports and no tunneled node would provide weak authentication based on the MAC address of the device, which can be easily spoofed or bypassed. MAC-Auth on edge ports and per-user tunneled node would also provide weak authentication and require tunneling the wired traffic to the MCs, which the customer does not want. 802.1X on edge ports and per-user tunneled node would provide strong authentication but also require tunneling the wired traffic to the MCs, which the customer does not want. References: Aruba 2930M Switch Series Data Sheet (Aruba Networks) Designing Aruba Solutions Study Guide (HPE Press)