DRAG DROP
Use the arrows to soft the steps to request a Policy on the left into the order they are performed on the right.
Select and Place:
Refer to the exhibit.
Based on the Authentication sources configuration shown, which statement accurately describes the outcome if the user is not found?
A. If the user is not found in the remotelab AD but is present in the local user repository, a reject message is sent back to the NAD.
B. If the user is not found in the local user repository but is present in the remotelab AD, a reject message is sent back to the NAD.
C. If the user is not found in the local user repository a reject message is sent back to the NAD.
D. If the user is not found in the local user repository and remotelab AD, a reject message is sent back to the NAD.
E. If the user is not found in the local user repository a timeout message is sent back to the NAD.
Which authorization servers are supported by ClearPass? (Select two.)
A. Aruba Controller
B. LDAP server
C. Cisco Controller
D. Active Directory
E. Aruba Mobility Access Switch
Refer to the exhibit.
When configuring a Web Login Page in ClearPass Guest, the information shown is displayed. What is the page name field used for?
A. for forming the Web Login Page URL
B. for Administrators to access the PHP page, but not guests
C. for Administrators to reference the page only
D. for forming the Web Login Page URL where Administrators add guest users
E. for informing the Web Login Page URL and the page name that guests must configure on their laptop wireless supplicant.
Refer to the exhibit.
Based on the Access Tracker output for the user shown, which statement describes the status?
A. The Aruba Terminate Session enforcement profile as applied because the posture check failed.
B. A Healthy Posture Token was sent to the Policy Manager.
C. A RADIUS-Access-Accept message is sent back to the Network Access Device.
D. The authentication method used is EAP-PEAP.
E. A NAP agent was used to obtain the posture token for the user.
Why can the Onguard posture check not be performed during 802.1x authentication?
A. Health Checks cannot be used with 802.1x.
B. Onguard uses RADIUS, so an additional service must be created.
C. Onguard uses HTTPS, so an additional service must be created.
D. Onguard uses TACACS, so an additional service must be created.
E. 802.1x is already secure, so Onguard is not needed.
Refer to the exhibit.
Based on the Enforcement Profile configuration shown, which statement accurately describes what is sent?
A. A limited access VLAN value is sent to the Network Access Device.
B. An unhealthy role value is sent to the Network Access Device.
C. A message is sent to the Onguard Agent on the client device.
D. A RADIUS CoA message is sent to bounce the client.
E. A RADIUS access-accept message is sent to the Controller
A ClearPass administrator wants to make Enforcement decisions during 802.1x authentication based on a client's Onguard posture token.
Which Enforcement profile should be used on the health check service?
A. RADIUS CoA
B. Quarantine VLAN
C. Full Access VLAN
D. RADIUS Accept
E. RADIUS Reject
Refer to the exhibit.
Which statements accurately describe the cp82 ClearPass node? (Select two.)
A. It becomes the Publisher when the primary Publisher fails.
B. It operated as a Publisher in the same cluster as the primary Publisher when the primary is active.
C. It operated as a Publisher in a separate cluster when the Publisher is active.
D. It operates as a Subscriber when the Publisher is active.
E. It stays as a Subscriber when the Publisher fails.
Which devices support Apple over-the-air provisioning? (Select two.)
A. IOS 5
B. Laptop running Mac OS X 10.8
C. Laptop running Mac OS X 10.6
D. Android 2.2
E. Windows XP
Refer to the exhibit.
An AD user's department attribute value is configured as "Product Management". The user connects on Monday to a NAD that belongs to the Device Group HQ. Which role is assigned to the user in ClearPass?
A. HR Local
B. [Guest]
C. [Employee]
D. Linux User
E. Executive
Refer to the exhibit.
Which statements accurately describe the status of the Onboarded devices in the configuration for the network settings shown? (Select two.)
A. They will connect to Employee_Secure SSID after provisioning.
B. They will connect to Employee_Secure SSID for provisioning their devices.
C. They will use WPA2-PSK with AES when connecting to the SSID.
D. They will connect to secure_emp SSID after provisioning.
E. They will perform 802.1X authentication when connecting to the SSID.
Use this form to make changes to the RADIUS Web Login Guest Network.
A Web Login page is configured in Clear Pass Guest as shown.
What is the purpose of the Pre-Auth Check?
A. To authenticate users after the NAD sends an authentication request to ClerPass
B. To authenticate users before the client sends the credentials to the NAD
C. To authenticate users when they are roaming from one NAD to another
D. To authenticate users before they launch the Web Login Page
E. To replace the need for the NAD to send an authentication request to ClearPass
Refer to the exhibit.
Based on the guest Self-Registration with Sponsor Approval workflow shown, at which stage does the sponsor approve the user's request?
A. After the RADIUS Access-Request
B. After the NAS login, but before the RADIUS Access-Request
C. Before the user can submit the registration form
D. After the RADIUS Access-Response
E. After the receipt page is displayed, before the NAS login
What is the purpose of ClearPass Onboard?
A. to provide MAC authentication for devices that don't support 802.1x
B. to run health checks on end user devices
C. to provision personal devices to securely connect to the network
D. to configure self-registration pages for guest users
E. to provide guest access for visitors to connect to the network