Black Friday Special - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dm70dm

Note! The HPE6-A46 Exam is no longer available.

HPE6-A46 Delta - Implementing Aruba Campus Switching Solutions Questions and Answers

Questions 4

Refer to the exhibit.

HPE6-A46 Question 4

A network administrator needs to alter myACL so that it permits all traffic that arrives in VLAN 2 and is destined to 10.1.10.0/24. Besides this change, the ACL must continue to act as it does now. The administrator plans this new rule:

permit ip any 10.1.10.0/24

How should the administrator apply this rule to meet all requirements?

Options:

A.

Apply the new rule without a rule ID to ensure that the switch applies the automatic processing order to it.

B.

Resequence the ACL with more space, then add the new rule with a sequence ID before the ID for the current third rule.

C.

Remove the ACL from the VLAN and re-apply it as an inbound VLAN ACL (VACL). Then, add the new rule with any ID higher than 2.

D.

Enable ACL grouping on the switch. Add the new rule in a new ACL. Then, group the new ACL with myACL.

Buy Now
Questions 5

A network administrator needs to configure an AOS-Switch to classify traffic. Comparing QoS policy and global policy, what is one function that only a class-based QoS policy can fulfill?

Options:

A.

Apply a DSCP to HTTP traffic from some sources but not other sources.

B.

Apply a DSCP rather than an 802.1p value to classified traffic.

C.

Override the incoming DSCP in the received traffic.

D.

Override the DSCP or priority applied directly to an interface.

Buy Now
Questions 6

Refer to the exhibits

Exhibit 1

HPE6-A46 Question 6

Exhibit 2

HPE6-A46 Question 6

Both Switch-1 and Switch-2 have an OSPF inter-area route to 10.2.0.0/16 with metric 10 in their IP routing table. Switch-3 has the default setting for ECMP. Based on the exhibits, what should the Switch-3 routing table display if the network operates as normal?

Options:

A.

no route to 10.2.0.0/16

B.

two routes to 10.2.0.0/16 through both 10.1.0.1 and 10.1.0.5

C.

a route to 10.2.0.0/16 through 10.1.0.5

D.

a route to 10.2.0.0/16 through 10.1.0.1

Buy Now
Questions 7

A network uses MSTP and has AOS-Switches at the access layer. The company wants edge ports on the access layer switches to meet these criteria:

  • They prevent all rogue switches that run STP, RSTP, or MSTP from connecting to the network.
  • If a rogue switch connects and is then replaced by a proper endpoint, the port recovers automatically without IT staff involvement.

How should the network administrator set up the edge ports to meet these requirements?

Options:

A.

Enable loop protection with a timeout period.

B.

Enable BPDU filtering.

C.

Enable both root guard and BPDU protection.

D.

Enable BPDU protection with a timeout period.

Buy Now
Questions 8

Refer to the exhibits.

Exhibit 1

HPE6-A46 Question 8

Exhibit 2

HPE6-A46 Question 8

A company does not require authentication for security, but AOS-Switches are set up to use local MAC authentication (LMA) to assign the correct VLAN and priority to IP phones. IP phones and computers belong to different VLANs. Each device is supposed to connect to a specific port, but sometimes users connect their devices to the wrong ports and cannot receive access without help from IT.

How can a network administrator configure the switches to eliminate this issue?

Options:

A.

Set the address limit to 2 on the switch ports that apply LMA.

B.

Create a user role that applies the user VLAN, and set this role as the initial role.

C.

Add the MAC addresses for computers to the myPhones MAC group.

D.

Apply LMA to all edge switch ports, and set the unauth VLAN to the user VLAN.

Buy Now
Questions 9

A company has AOS-Switches deployed at sites with inexperienced IT staff. The main office network administrators want to track if configurations change on branch switches.

What should be set up for this purpose?

Options:

A.

an SNMP trap

B.

an RMON alarm

C.

an IP SLA profile

D.

an auto-config server

Buy Now
Questions 10

Refer to the exhibit.

HPE6-A46 Question 10

AOS-Switches will enforce 802.1X authentication on edge ports. The company has two RADIUS servers, which are meant to provide redundancy and load sharing of requests. The exhibit shows the planned RADIUS settings to deploy to the switches.

What should customers understand about this plan?

Options:

A.

AOS switches do not support two RADIUS servers for redundancy, instead, a secondary authentication method is required.

B.

Dynamic authentication is only permitted on one of the RADIUS servers and must be removed from the other.

C.

Each RADIUS server must use a unique port number for the authentication and dynamic authorization port.

D.

Each AOS-Switch will send all RADIUS requests to the first server on the list unless that server becomes unreachable.

Buy Now
Questions 11

An AOS-Switch enforces 802.1X. It receives an Access-Accept with this HPE VSA from its Radius server:

Attribute Name and ID = HPE-User-Role (25) Value = contractor

The switch then rejects the client. What is one requirement for the switch to accept the message and authorize the client?

Options:

A.

The initial user role must be set to the factory default permit any role.

B.

User role authorization must be enabled globally on the switch.

C.

An aaa authentication local user group must have the contractor name.

D.

The RADIUS server settings must permit dynamic authorization.

Buy Now
Questions 12

Refer to the exhibit.

HPE6-A46 Question 12

A known unicast packet is received from Switch-1 on the standby and must be forwarded to Switch-2. How does the VSF fabric decide which port in the aggregated link should forward the packet?

Options:

A.

The standby uses its own port in the link aggregation to forward the fabric.

B.

The standby sends the packet to the commander over a VSF link, and the commander decides the correct port.

C.

The standby uses the typical load sharing algorithm, and it might select either its port or the commander’s port.

D.

The standby selects the port on the designated forwarder for the aggregation.

Buy Now
Questions 13

A company has a mixed wireless and wired Aruba solution. It wants to encrypt messages used to send configurations and other important messages to the APs carried outside the GRE tunnels. What can the company do to meet these goals?

Options:

A.

Deploy Aruba Meridian and integrate the AOS-Switches with it.

B.

Configure extended IP ACLs on the AOS-Switches to filter the traffic.

C.

Use PAPI enhanced security.

D.

Use tunneled node to send traffic through an Aruba Mobility Controller.

Buy Now
Questions 14

An AOS-Switch needs to be configured to support tunneled node in role-based mode. The Mobility Controller administrators tell the switch administrators that the AOS-Switch will integrate with a cluster of Mobility Controllers. The cluster virtual IP address is 10.1.1.10.

How should switch administrator integrate the AOS-Switch with the cluster?

Options:

A.

Double-check the settings with the Mobility Controller administrators because the planned configuration is incomplete with the switch settings.

B.

Configure the virtual IP address as the tunneled-node-server address, tunneled node will work, but the clustering features will not provide redundancy.

C.

Configure the virtual IP address as the tunneled-node-server address. The switch will automatically learn controller IP addresses to which to tunnel various traffic.

D.

Configure the virtual IP address for the primary tunneled-node-server and an actual controller IP address for the backup tunneled-node-server in order to receive redundancy.

Buy Now
Questions 15

Refer to the exhibits.

Exhibit 1

HPE6-A46 Question 15

Exhibit 2

HPE6-A46 Question 15

A network administrator sets up PIM-DM to route traffic from the multicast source to clients in VLAN 24. The server begins to forward multicasts, and the clients are set up to receive them. However, the multicasts do not reach the clients.

Based on the output, what should the administrator verify?

Options:

A.

that VLAN 24 on Switch-1 runs both IGMP and PIM-DM

B.

that Switch-2 has PIM-DM enabled on VLAN 10

C.

that state refreshes are enabled on Switch-2

D.

that Switch-1 has selected Switch-2 as its RP for 239.1.1.1

Buy Now
Questions 16

Refer to the exhibit.

HPE6-A46 Question 16

An AOS-Switch has the ACL shown in the exhibit. A network administrator then enters these commands:

Switch(config)# mac-access-list standard myACL

Switch(config-std-macl)# deny 007d.45cc.0000 0000.0000.ffff

How does this ACL treat these frames:

1 = 007d.45cc.ffff 2 = 007d.45cc.0000

Options:

A.

It denies both frames.

B.

It permits both frames.

C.

It denies frame 1 and permits frame 2.

D.

It permits frame 1 and denies frame 2.

Buy Now
Questions 17

Network administrators decide to change OSPF Area 1 to a stub area in order to solve some performance issues. No routes are redistributed into area 1.

What is one implication of making this change?

Options:

A.

Endpoints in Area 1 will no longer be able to reach external networks.

B.

Routing devices in area 1 will no longer exchange Type 1 and Type 2 LSAs with each other.

C.

Endpoints in Area 1 will no longer be able to reach endpoints in other areas.

D.

Routing devices in area 1 will temporarily lose adjacency while the change is made.

Buy Now
Questions 18

Refer to the exhibit.

HPE6-A46 Question 18

A company requires distribution layer switches that can provide Layer 2 and Layer 3 redundancy. The exhibit shows the proposal for these switches. Which change to the proposal will help meet the company’s requirements?

Options:

A.

The proposed switches should be replaced with switches such as the Aruba 2930M to support the backplane stacking technology.

B.

VRRP should be implemented instead of backplane stacking to support the Layer 3 redundancy requirements.

C.

Link aggregations should be established without LACP to support the Layer 2 redundancy requirements and backplane stacking limitations.

D.

The proposed switches should be replaced with switches that support VSF to support the required distance between stack members.

Buy Now
Questions 19

A network administrator wants to prevent changes in the spanning tree topology if a rogue switch connects to interface 1 on an AOSSwitch. The interface should NOT shut down because it receives BPDUs, but it should shut down if it receives superior BPDUs. Which feature should the administratorconfigure on interface 1?

Options:

A.

Loop guard

B.

BPDU protection

C.

BPDU filtering

D.

Root guard

Buy Now
Questions 20

Refer to the exhibits.

Exhibit 1

HPE6-A46 Question 20

Exhibit 2

HPE6-A46 Question 20

The IP phone in the exhibit is set up to complete 802.1x authentication to the network. How can the netwotk administrator prevent a user on the computer from receiving network access without authentication?

Options:

A.

Set an 802.1X client limit of 2 on interface 1.

B.

Set up the MAC filter on interface 1.

C.

Enable static mode port security on interface 1.

D.

Enable MAC-based VLANs on interface 1.

Buy Now
Questions 21

A customer wants to authenticate AOS-Switch managers to a RADIUS server. The CIO wants to assign different rights to different management users for granular control over their rights and privileges. What must the network administrator enable on the AOS-Switches to ensure they comply with this plan?

Options:

A.

RADIUS-based command authorization

B.

a manager and operator password

C.

authentication login privileges

D.

SNMPv3 and SNMPv3 restricted access.

Buy Now
Questions 22

What must an OSPF router do to ensure nonstop routing should a standby member take over as commander when the original VSF commander fails?

Options:

A.

It must run the shortest path first algorithm.

B.

It must participate in a new election for the Designated Router.

C.

It must initiate a graceful restart.

D.

It must re-establish adjacency with its Designated Router.

Buy Now
Questions 23

An AOS-Switch runs IGMP on A VLAN.

What is a requirement for the switch to be a potential IGMP querier on that VLAN?

Options:

A.

The switch must run PIM-SM or PIM-DM on that VLAN.

B.

The switch must have an IP address on that VLAN.

C.

The switch must have IGMP fast leave disabled globally.

D.

The switch must have at least one IGMP group configured on it manually.

Buy Now
Questions 24

Refer to the exhibit.

HPE6-A46 Question 24

A network administrator sets up 802.1X authentication to a RADIUS server on an AOS-Switch. The RADIUS server and user devices are both set up to use PEAP MSCHAPv2. The administrator tests the authentication and sees the output shown in the exhibit. Which issue could cause this output?

Options:

A.

The administrator entered the wrong password for the test account

B.

The RADIUS shared secret does not match on the switch and the server

C.

The switch does not have a certificate for port-access installed on the switch

D.

The switch port is set for user mode 802.1X, but the RADIUS server is set for port mode

Buy Now
Questions 25

A company starts to have issues with too many rules in the dynamic ACLs applied to AOS-Switch ports. Administrators decide to remove some of the common rules from the dynamic ACLs and enforce them in an ACL applied to the users’ VLAN instead.

What is one rule that administrators should keep in mind to ensure that the new ACLs control traffic as they expect?

Options:

A.

ACLs applied to VLANs cannot control ICMP traffic, do the dynamic ACLs must include the ICMP rules.

B.

Administrators should add an explicit deny at the end of the dynamic ACLs, so traffic will hit VLAN ACL.

C.

Traffic must be permitted by both the dynamic ACL and the VLAN ACL in order to be permitted.

D.

If a port supports multiple clients, every dynamic ACL applied to one client filters traffic for all clients.

Buy Now
Exam Code: HPE6-A46
Exam Name: Delta - Implementing Aruba Campus Switching Solutions
Last Update: Nov 28, 2023
Questions: 169
dumpsmate guaranteed to pass
24/7 Customer Support

DumpsMate's team of experts is always available to respond your queries on exam preparation. Get professional answers on any topic of the certification syllabus. Our experts will thoroughly satisfy you.

Site Secure

mcafee secure

TESTED 24 Nov 2024