BlackFriday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

HP Exam HPE6-A84 Topic 7 Question 31 Discussion

Actual exam question for HP's HPE6-A84 exam
Question #: 31
Topic #: 7
[All HPE6-A84 Questions]

A customer needs you to configure Aruba ClearPass Policy Manager (CPPM) to authenticate domain users on domain computers. Domain users, domain computers, and domain controllers receive certificates from a Windows C

Show Suggested Answer Hide Answer
Suggested Answer: C

EAP (Extensible Authentication Protocol) is a framework that allows different authentication methods to be used for network access. EAP is used for RADIUS/EAP authentication, which is a common method for authenticating domain users on domain computers using certificates. EAP requires that the RADIUS server, such as ClearPass Policy Manager (CPPM), validates the certificates presented by the clients and verifies their identity against an identity source, such as Windows AD. Therefore, the root certificate for the Windows CA that issues the certificates to the clients should have the EAP usage in the ClearPass CA Trust list.

Radsec (RADIUS over TLS) is a protocol that allows secure and encrypted communication between RADIUS servers and clients using TLS. Radsec is used for encrypting all communications between CPPM and the domain controllers, which act as RADIUS clients. Radsec requires that both the RADIUS server and the RADIUS client validate each other's certificates and establish a TLS session. Therefore, the root certificate for the Windows CA that issues the certificates to the domain controllers should have the Radsec usage in the ClearPass CA Trust list.


Contribute your Thoughts:

Brock
21 days ago
Haha, Jeffrey's comment about the secret handshake made me chuckle. But he's right, C is the answer that ticks all the boxes.
upvoted 0 times
...
Jeffrey
25 days ago
C is the way to go, no doubt. Radsec is like the secret handshake of secure RADIUS communications, you know?
upvoted 0 times
Oneida
1 days ago
C is definitely the best choice. Radsec adds an extra layer of security to RADIUS communications.
upvoted 0 times
...
...
Mi
29 days ago
Hmm, I was thinking option B, but now that I reread the question, C does seem more appropriate. Gotta love those encryption requirements!
upvoted 0 times
Danica
14 days ago
Definitely, option C for EAP and Radsec seems like the right choice for this scenario.
upvoted 0 times
...
Ruby
20 days ago
Yeah, I think option C covers all the necessary usages for authentication with domain users and computers.
upvoted 0 times
...
Edna
21 days ago
I agree, option C seems like the best choice for encryption requirements.
upvoted 0 times
...
...
Garry
1 months ago
The question specifically mentions that the customer requires encryption for all communications, so I agree that C is the right choice here.
upvoted 0 times
Rashida
19 days ago
Great, let's go ahead and add EAP and Radsec to the root certificate for the Windows CA in ClearPass.
upvoted 0 times
...
Staci
19 days ago
It's important to follow the customer's requirements for encryption, so C) EAP and Radsec is the best option.
upvoted 0 times
...
Cassandra
25 days ago
I agree, adding EAP and Radsec will ensure encryption for all communications between CPPM and the domain controllers.
upvoted 0 times
...
Tabetha
28 days ago
I think C) EAP and Radsec is the correct choice for this scenario.
upvoted 0 times
...
...
Kristian
1 months ago
I'm not sure. Maybe we should also consider adding Radsec for additional security.
upvoted 0 times
...
Vernell
2 months ago
I agree with Erasmo. It makes sense to add those usages for authentication.
upvoted 0 times
...
Erasmo
2 months ago
I think we should add EAP and AD/LDAP Server to the root certificate.
upvoted 0 times
...
Tracie
2 months ago
I think option C is the correct answer. EAP and Radsec provide the encryption required for the communication between CPPM and the domain controllers.
upvoted 0 times
Rolland
1 months ago
Yes, EAP and Radsec will provide the necessary security for the communication. Good choice!
upvoted 0 times
...
Queenie
2 months ago
I agree, option C is the best choice for ensuring encryption between CPPM and the domain controllers.
upvoted 0 times
...
...

Save Cancel