Filters
Question type

Study Flashcards

A customer is setting up Guest access with ClearPass. They are considering using 802.1X for both the Employee network and the Guest network. What are two issues the customer may encounter when deploying 802.1X with the Guest network? (Choose two.)


A) ClearPass will not be able to enforce individual Access Control policies.
B) difficult to maintain in an environment with a large number of transient guest users.
C) the lack of encryption during the authentication process.
D) Guests will not be able to be uniquely identified.
E) the high level of complexity for users to join the guest network.

F) C) and D)
G) A) and B)

Correct Answer

verifed

verified

What is RADIUS Change of Authorization (CoA) ?


A) It is a mechanism that enables ClearPass to assigned a User-Based Tunnel (UBT) between a switch and controller for Dynamic Segmentation.
B) It allows clients to issue a privilege escalation request to ClearPass using RADIUS to switch to TACACS+.
C) It allows ClearPass to transmit messages to the Network Attached Device/Network Attached Server (NAD/NAS) to modify a user's session status.
D) It forces the client to re-authenticate upon roaming to an access point controlled by a foreign mobility controller.

E) A) and D)
F) A) and C)

Correct Answer

verifed

verified

Refer to the exhibit. Refer to the exhibit.   When creating a new ClearPass Service, the [Time Source] has been added as an authorization source. What time source is ClearPass referencing? A)  the ClearPass server where Insight Master has been enabled the ClearPass server where Insight Master has been enabled B)  the local clock of the ClearPass server doing the authentication C)  the local time setting found on the authenticating client machine D)  the NTP (Network Time Protocol)  source indicated in the Cluster settings When creating a new ClearPass Service, the [Time Source] has been added as an authorization source. What time source is ClearPass referencing?


A) the ClearPass server where Insight Master has been enabled the ClearPass server where Insight Master has been enabled
B) the local clock of the ClearPass server doing the authentication
C) the local time setting found on the authenticating client machine
D) the NTP (Network Time Protocol) source indicated in the Cluster settings

E) C) and D)
F) B) and D)

Correct Answer

verifed

verified

When ClearPass is communicating with external context servers, which connection protocol is typically used?


A) FTP over SSH
B) REST APIs over HTTPS
C) SOAP and XML
D) YAML

E) All of the above
F) None of the above

Correct Answer

verifed

verified

Which authentication method requires a client certificate?


A) EAP-TLS
B) Guest self-registration
C) PEAP
D) MAC Authentication

E) C) and D)
F) A) and D)

Correct Answer

verifed

verified

Sponsorship has been enabled on the guest network. A guest user connects and completes the self-registration form indicating a valid sponsor. The guest then clicks submit . What is the current state of the guest account?


A) The guest account is created in an enabled state with the "Log In" button functional.
B) The guest account is created in disabled state, the "Log In" button will appear only after the sponsor approval process is completed.
C) The guest account is created in a disabled state with the "Log In" button grayed out.
D) The guest account is not yet created and remains in a disabled state. There is not "Log In" button yet displayed.

E) C) and D)
F) All of the above

Correct Answer

verifed

verified

What are "known" endpoints in ClearPass?


A) "Known" endpoints have be fingerprinted to determine their operating system and manufacturer.
B) These are endpoints whose beacons have been detected but have never completed authentication.
C) The label "Known" indicates rogue endpoints labeled as "friendly" or "ignore".
D) "Known" endpoints can be authenticated based on MAC address to bypass the captive portal login.

E) B) and D)
F) B) and C)

Correct Answer

verifed

verified

A customer with 677 employees would like to authenticate employees using a captive portal guest web login page. Employees should use their AD credentials to login on this page. Which statement is true?


A) The customer needs to add second guest service in the policy manager for the guest network.
B) The customer needs to add the AD server as an authentication source in a guest service.
C) Employees must be taken to a separate web login page on the guest network.
D) The customer needs to add the AD servers RADIUS certificate to the guest network.

E) B) and D)
F) B) and C)

Correct Answer

verifed

verified

When using Guest Authentication with MAC Caching service template, which statements are true? (Choose two.)


A) The guest authentication is provided better security than without using MAC caching.
B) The endpoint status of the client will be treated as "known" the first time the client associates to the network.
C) Which wireless SSID and wireless controller must be indicated when configuring the template.
D) The client will be required to re-enter their credentials even if still within the MAC-Auth Expiry term.

E) B) and C)
F) None of the above

Correct Answer

verifed

verified

What happens when a client successfully authenticates but does not match any Enforcement Policy rules?


A) A RADIUS reject is returned for the client.
B) A RADIUS Accept is returned with no Enforcement Profile applied.
C) A RADIUS Accept is returned, and the default Enforcement Profile is applied.
D) A RADIUS Accept is returned, and the default rule is applied to the device.

E) B) and C)
F) A) and B)

Correct Answer

verifed

verified

What is an effect of the Cache Timeout setting on the authentication source settings for Active Directory?


A) ClearPass will validate the user credentials, then, for the duration of the cache, ClearPass will just fetch account attributes.
B) The Cache Timeout is designed to reduce the amount of traffic between ClearPass and the A/D server by caching the attributes.
C) ClearPass will validate the user credentials on the first attempt, then will always fetch the account attributes.
D) The Cache Timeout is designed to reduce the amount of traffic between ClearPass and the A/D server by caching the credentials.

E) B) and D)
F) All of the above

Correct Answer

verifed

verified

Which Authorization Source supports device profile enforcement?


A) Local User Repository
B) OnGuard Repository
C) Endpoints Repository
D) Guest User Repository

E) None of the above
F) A) and C)

Correct Answer

verifed

verified

What needs to be configured for ClearPass use an enforcement rule base on client Data Cap?


A) Enable Logging of Accounting Start-Stop packets. Enable Logging of Accounting Start-Stop packets.
B) Interim Accounting on the Network Access Device (NAD) .
C) Make sure the Endpoint Profiling is configured.
D) Enable Active Sessions in ClearPass Guest

E) A) and B)
F) All of the above

Correct Answer

verifed

verified

Your boss suggests configuring a guest self-registration page in ClearPass for an upcoming conference event. What are the benefits of using guest self-registration? (Choose two.)


A) This will allow conference employees to pre-load additional device information as guests arrive and register.
B) This strategy effectively stops employees from putting their own corporate devices on the guest network.
C) This will enable additional information to be gathered about guests during the conference.
D) This allows guest users to create and manage their own login account.
E) This will allow employee personal devices to be Onboarded to the corporate network.

F) A) and B)
G) A) and C)

Correct Answer

verifed

verified

An organization has configured guest self-registration with internal sponsorship. Which options can be configured to send guest users their credentials outside of the initial login web-page? (Choose two.)


A) Configure a Simple Mail Transport Protocol (SMTP) server in ClearPass Policy Manager administration.
B) Configure a Simple Mail Transport Protocol (SMTP) server in ClearPass Guest administration.
C) Configure a Short Message Service (SMS) Gateway in ClearPass Policy Manager administration.
D) Configure a Short Message Service (SMS) Gateway under ClearPass Guest configuration.
E) Configure the self-registration page for the guest to receive a Simple Mail Transport Protocol (SMTP) receipt.

F) A) and B)
G) A) and C)

Correct Answer

verifed

verified

When joining ClearPass to an Active Directory (AD) domain, what information is required? (Choose two.)


A) Fully Qualified Domain Name (FQDN) of the AD Domain Controller.
B) ClearPass Policy Manager (CPPM) enterprise credentials.
C) Domain Administrator credentials with at least read access.
D) Cache Timeout value set to at least 10 hours.
E) Domain User credentials with read-write access.

F) All of the above
G) B) and E)

Correct Answer

verifed

verified

Showing 21 - 36 of 36

Related Exams

Show Answer