Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

HP Exam HPE6-A84 Topic 10 Question 18 Discussion

Actual exam question for HP's HPE6-A84 exam
Question #: 18
Topic #: 10
[All HPE6-A84 Questions]

Refer to the scenario.

A customer requires these rights for clients in the ''medical-mobile'' AOS firewall role on Aruba Mobility Controllers (MCs):

External devices should not be permitted to initiate sessions with ''medical-mobile'' clients, only send return traffic.

The line below shows the effective configuration for the role.

There are multiple issues with this configuration. What is one change you must make to meet the scenario requirements? (In the options, rules in a policy are referenced from top to bottom. For example, ''medical-mobile'' rule 1 is ''ipv4 any any svc-dhcp permit,'' and rule 6 is ''ipv4 any any any permit'.)

Show Suggested Answer Hide Answer
Suggested Answer: D

This is because this URI specifies the exact attribute that contains the number of access rejects from the RADIUS server, which is the information that the NAE script needs to monitor and trigger an alert.

A) /rest/v1/system/vrfs/mgmt/radius/servers/cp.acnsxtest.local/2083/tcp?attributes=authstatistics. This is not the correct URI because it returns the entire authstatistics object, which contains more information than the access rejects, such as access accepts, challenges, timeouts, etc. This might make the NAE script more complex and inefficient to parse and process the data.

B) /rest/v1/system/vrfs/mgmt/radius/servers/cp.acnsxtest.local/2083/tcp?attributes=authstatistics?attributes=access_rejects. This is not a valid URI because it has two question marks, which is a syntax error. The question mark is used to indicate the start of the query string, which can have one or more parameters separated by ampersands. The correct way to specify multiple attributes is to use a comma-separated list after the question mark, such as ?attributes=attr1,attr2,attr3.

C) /rest/v1/system/vrfs/mgmt/radius/_servers/cp.acnsxtest.local/2083/tcp. This is not a valid URI because it has an extra underscore before servers, which is a typo. The correct resource name is servers, not _servers. Moreover, this URI does not specify any attributes, which means it will return the default attributes of the RADIUS server object, such as name, port, protocol, etc., but not the authstatistics or access_rejects.

7of30


Contribute your Thoughts:

Ciara
1 months ago
I wonder if the firewall role was named 'medical-mobile' because the customers are using it to monitor their patients' vital signs on the go. Gotta stay healthy, even on the move!
upvoted 0 times
...
Pete
1 months ago
Wait, is the answer supposed to be a secret? I'm not going to share it with anyone, I promise!
upvoted 0 times
Bettyann
2 days ago
A: Exactly, it's important to ensure the security requirements are met for the scenario.
upvoted 0 times
...
Linette
9 days ago
B: That makes sense, it would help restrict external devices from initiating sessions with 'medical-mobile' clients.
upvoted 0 times
...
Tamera
28 days ago
A: I think the answer is B) In the 'medical-mobile' policy, change the action for rules 2 and 3 to reject.
upvoted 0 times
...
...
Audry
1 months ago
Hmm, this is a tricky one. I think I need to re-read the scenario a few more times to make sure I understand it fully.
upvoted 0 times
Stephen
23 days ago
Maybe changing the action for rules 2 and 3 to reject could help.
upvoted 0 times
...
Dominga
26 days ago
I think we need to focus on the 'medical-mobile' policy.
upvoted 0 times
...
Chau
29 days ago
Let's break it down step by step.
upvoted 0 times
...
...
Linn
1 months ago
Haha, I bet the person who wrote this question was trying to trick us. But I'm not falling for it!
upvoted 0 times
...
Cletus
2 months ago
The correct answer is B. The scenario requires that external devices should not be permitted to initiate sessions with 'medical-mobile' clients, so we need to change the action for rules 2 and 3 to reject.
upvoted 0 times
Oliva
12 days ago
Oh, I see. Thanks for clarifying.
upvoted 0 times
...
Fernanda
13 days ago
No, the correct answer is B. We need to change the action for rules 2 and 3 to reject.
upvoted 0 times
...
Dorothy
23 days ago
I think the correct answer is A.
upvoted 0 times
...
...
Annelle
2 months ago
But rule 2 and 3 need to be changed to reject to meet the scenario requirements.
upvoted 0 times
...
Alease
2 months ago
I disagree, I believe the answer is B.
upvoted 0 times
...
Annelle
2 months ago
I think the correct answer is A.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77