Question: 1

Which licenses are included in the built-in starter kit for ClearPass?

A. 10 ClearPass Guest licenses,10 ClearPass OnGuard licenses and 10 ClearPass Onboard licenses
B. 10 ClearPass Enterprise licenses
C. 25 ClearPass Policy Manager licenses
D. 25 ClearPass Profiler licenses
E. 25 ClearPass Enterprise licenses

Answer: E

Question: 2

What happens when a client successfully authenticates but does not match any Enforcement Policy rules?

A. no role is applied to the device
B. logon profile is applied to the device
C. default Enforcement profile is applied
D. guest rule is applied to the device
E. defaultrule is applied to the device

Answer: C

The first time a device connects, it’s allowed on in a limited state (session timeout is a low value and DHCP is allowed) because it doesn’t match any Enforcement policy rules based on Endpoint Category. The default enforcement profile is used.
Question: 3

When Active Directory is added as an authentication source, what should the format be for the Active Directory bin DN?

A. admin.domain.com
B. domain.com\admin
C. domain.com
D. admin@domain.com
E. admin\domain.com

Answer: D

For Active Directory, the bind DN can also be in the administrator@domain format (for example,administrator@acme.com).
Question: 4

Refer to the exhibit. A user has enabled ‘department’ and ‘memberOf’ as roles.
What is the direct effect of the user’s action?

A. The user’s authentication will be rejected if the user does not have an admin user group membership in AD
B. The user’s memberOf attribute is sent back to the controller as a firewall role.
C. The user’s department and group membership will be seen in the Access tracker roles section.
D. The user’s authentication will be rejected if the user does nothave a department attribute in AD
E. The user’s department is sent back to the controller as a firewall role.

Answer: A

Question: 5

When enforcement action is used in ClearPass to bounce a client?

A. Webpage redirect
C. VLAN attribute

Answer: E

In the Profiler tab, change the RADIUS CoA Action to “[Cisco – Bounce-Host-Port]”. Make sure your switch is configured for this.
Question: 6

Refer to the exhibit. A user connects to an Aruba Access Point wireless SSID named “secure-corporate” and performs an 802.1X authentication with ClearPass as the authentication server.
Based on this service configuration, which service will be triggered?

A. pod8-mac auth
B. Noservice will be triggered
C. pod8wireless
D. [Policy Manager Admin Network Service]
E. pod8wired

Answer: A

Question: 7

A ClearPass deployment needs to be designed to determine whether a user authenticating is an HR department employee in the Active Directory Server and whether the user’s device is healthy.
Which policy service components will the network administrator need to use?

A. Posture, Authentication and Authorization
B. Posture and Firewall Roles
C. Posture and Onboard
D. Authentication andAuthorization
E. Posture, Authentication and Onboarding

Answer: A

Question: 8

What is Radius CoA used for?

A. to validate a host MAC against a white and a black list
B. to force the client to re-authenticate upon roaming to a new controller
C. to authenticate users or devices before granting them access to a network
D. to transmit messages to the NAD/NAS to modify a user’s session status
E. to apply firewall policies based on authentication credentials

Answer: B

Question: 9

Which statement most accurately describes how users with Active Directory credentials authenticate with ClearPass when Active Directory is used as an authentication source for an 802.1x service in ClearPass?

A. A Kerberos request is sent from the Network Access Device to ClearPass which initiates a RADUIS request to the AD server.
B. A RADIUS request is sent from the Network Access Device to the AD server which communicates with ClearPass.
C. An LDAP request is sent from the Network AccessDevice to the AD server which communicates with ClearPass.
D. An LDAP request is sent from the Network Access Device to ClearPass which initiates a RADIUS request to the AD server.
E. A RADIUS request is sent from the Network Access Device to the ClearPasswhich communicates with the AD server.

Answer: C

Question: 10

Refer to the exhibit. Based on the information shown, why did the Joining AD fail?

A. the GSS is wrong
B. the wrong FQDN of the AD was entered while joining
C. thewrong domain name was selected while joining the AD
D. there is a clock difference between ClearPass and AD servers
E. there is an IP communication issue

Answer: C


