DRAG DROP
Match the security description to the term that best fits. Options are used only once.
Select and Place:

A customer is setting up Guest access with ClearPass. They are considering using 802.1X for both the Employee network and the Guest network.
What are two issues the customer may encounter when deploying 802.1X with the Guest network? (Choose two.)
A. ClearPass will not be able to enforce individual Access Control policies.
B. difficult to maintain in an environment with a large number of transient guest users.
C. the lack of encryption during the authentication process.
D. Guests will not be able to be uniquely identified.
E. the high level of complexity for users to join the guest network.
When ClearPass is communicating with external context servers, which connection protocol is typically used?
A. FTP over SSH
B. REST APIs over HTTPS
C. SOAP and XML
D. YAML
Which statement is true about OnGuard? (Choose two.)
A. It is used to ensure that Antivirus/Antispyware programs are running
B. It supports both Windows and Mac OS X clients
C. It is used to identify and remove any malware/viruses
D. It only supports 802.1X authentication
Which are valid enforcement profile types? (Choose two.)
A. ClearPass Entity Update Enforcement
B. Aruba Script Enforcement
C. Policy Service Enforcement
D. RADIUS Change of Authorization (CoA)
What happens when a client successfully authenticates but does not match any Enforcement Policy rules?
A. A RADIUS reject is returned for the client.
B. A RADIUS Accept is returned with no Enforcement Profile applied.
C. A RADIUS Accept is returned, and the default Enforcement Profile is applied.
D. A RADIUS Accept is returned, and the default rule is applied to the device.
What are benefits of using Network Device Groups in ClearPass? (Choose two.)
A. Network Access Devices (NADs) only require Aruba factory installed certificates to join a Network Device Group.
B. Allows Service selection rules to match based upon which Network Device Group the Network Access Device (NAD) belongs to.
C. A Network Access Device is must be discovered by ClearPass prior to be added to a Network Device Group.
D. Another way to add a customizable "attribute" field to reference when processing authentication requests.
E. Can apply to both Network Access Devices (NADs) as well as client machines as a way to filter authentication requests.
Refer to the exhibit.

What does a bold field indicate?
A. The field is a non-system field
B. The field is currently enabled
C. The field has been customized
D. The field is required
Refer to the exhibit.

What will be the enforcement for the user "neil"?
A. Allow Full Access
B. Secure Corp BYOD Access
C. Allow Internet Only Access
D. Corp Secure Contractor
What are two ways to add guest accounts to ClearPass? (Choose two.)
A. Importing accounts from Active Directory once ClearPass is added with Admin credentials.
B. Assigning the default role "Lobby Ambassador to a receptionist to then add the accounts.
C. Using the "Import Accounts" under ClearPass Guest.
D. Using the "Create Account" or "Create Multiple" options under ClearPass Guest.
E. Using the "Sync Accounts" under ClearPass Guest.