Configure the Solution
HPE6-A85 · 64 questions
- Biomedical engineering just racked a new HPE Aruba AOS-CX switch for a new orthopedic ward, and it has not yet been assigned a management IP address. Which method lets a technician log in to configure the switch for the first time?
- A network technician is provisioning access ports for a new medical-surgical ward. Each patient-room wall jack should carry only the traffic for the ward's clinical workstation VLAN. What is the correct AOS-CX port mode for these jacks?
- An access switch on the cardiology ward has a single uplink cable to the distribution switch, which must carry traffic for the clinical VLAN, the guest Wi-Fi VLAN, and the biomedical device VLAN simultaneously. How should this uplink port be configured?
- On a trunk link between the radiology-ward access switch and the aggregation switch, frames arrive on the link without an 802.1Q tag. Which VLAN does the receiving AOS-CX switch place these untagged frames into?
- A technician is bundling two physical links between the outpatient annex aggregation switch and the core switch into a single logical interface for extra bandwidth and resiliency. Which technology accomplishes this on AOS-CX?
- A technician is forming a link aggregation group between an access switch and the aggregation switch and wants both ends to actively negotiate the bundle rather than assume it is already formed. Which LACP configuration achieves this?
- A rogue consumer switch gets plugged into a nurse-station wall jack, and its bridging behavior starts destabilizing the ward's access-layer spanning tree topology. Which AOS-CX access-port feature is designed to prevent exactly this kind of problem?
- Two access switches on the same ward are both eligible to become the spanning tree root bridge. A technician wants the more powerful aggregation-facing switch, not either access switch, to remain root. What is the most direct way to ensure this?
- An outpatient annex is being built with two AOS-CX aggregation switches configured as a VSX pair to avoid a single point of failure. In normal, healthy operation, how do the two VSX switches behave from the perspective of connected devices?
- In a VSX pair deployed at the hospital's core-aggregation layer, the two switches use a dedicated link between them to synchronize MAC/ARP tables and coordinate forwarding state. What is this link called?
- The biomedical engineering lab wants to manage two physical AOS-CX switches as a single logical device with one management IP and one configuration file, primarily to simplify day-to-day administration rather than to maximize inter-building resiliency. Which technology best fits this goal?
- The lead network engineer must choose between VSF and VSX for a new pair of access switches serving a maternity ward, where the priority is keeping both switches' management and control planes fully independent so a software fault on one switch cannot affect the other. Which choice fits, and why?
- A new wireless infusion-pump monitoring hub in the ICU draws more power than a typical IP phone. Before plugging it into an AOS-CX access port, what should the technician confirm about that port's PoE configuration?
- An access switch in the emergency department is close to its total PoE power budget. A technician needs to guarantee that nurse-call station ports keep receiving power even if adding new devices pushes the switch over budget. What AOS-CX PoE feature addresses this?
- A new pediatric wing needs devices on the clinical VLAN to communicate with devices on the guest Wi-Fi VLAN without a separate router, using the AOS-CX aggregation switch that already carries both VLANs. What should be configured on that aggregation switch to enable inter-VLAN routing?
- The outpatient annex's aggregation switch has a directly connected route to its local VLANs but needs a path to reach the hospital's main data center subnet, which is not directly connected. No dynamic routing protocol has been deployed yet. What is the simplest way to provide that reachability?
- The hospital IT team wants newly racked AOS-CX switches at a future clinic expansion site to automatically discover their configuration profile from Aruba Central as soon as they receive DHCP and internet reachability, without a technician manually logging into each one. What onboarding approach does this describe?
- During initial provisioning of a new ward's access switches, the network team wants administrative access to each switch to be isolated from the clinical and guest data traffic those switches carry. What design choice accomplishes this?
- A nurse-station wall jack needs to support both a desk phone and a PC daisy-chained through the phone, with the phone's voice traffic separated from the PC's data traffic on the same cable. What AOS-CX access-port configuration supports this?
- A newly configured LAG between an access switch and the aggregation switch is not passing any traffic. One switch has both member ports set to LACP active mode, and the other switch has both member ports administratively set to access mode with LACP disabled. What is the most likely cause of the failure?
- A VSX pair at the aggregation layer serves as the default gateway for several ward VLANs. The hospital wants both switches to share a single virtual gateway IP and MAC address per VLAN, so an end device only needs one gateway configured regardless of which physical switch actually forwards its traffic. Which VSX feature provides this?
- After deploying VLANs, trunk uplinks, and a LAG for a newly built ward, the technician wants to validate the configuration before declaring the rollout complete. Which check most directly confirms the deployment is working as intended?
- A hospital's IT team unboxes a brand-new access point for the new clinic wing and connects it to a switch port on the network with internet reachability, without ever touching its CLI. The AP is expected to reach out on its own, discover it belongs to the hospital's Aruba Central account, and pull down its configuration automatically. What onboarding mechanism makes this possible?
- Network staff are creating a new WLAN for nurse-station laptops in a newly opened ward. The design calls for that traffic to land on its own dedicated clinical VLAN rather than mixing with guest or biomedical device traffic. Which setting on the WLAN profile accomplishes this?
- The hospital's guest and patient WLAN needs all of its traffic sent back to a central point where it can be firewalled and monitored before reaching the internet, rather than exiting directly at each access point. Which wireless forwarding mode should this WLAN be configured to use?
- A wireless design document for the new imaging wing specifies that APs near the MRI and CT suites must use only non-overlapping 5GHz channels from a defined list, avoiding auto-channel selection, because of known RF sensitivity around the imaging equipment. When configuring those APs, what is the correct way to honor this requirement?
- A network engineer wants a new SSID for tablet carts to broadcast only from the access points inside the new pediatric clinic wing, and not from any other AP on the hospital campus. Rather than configuring each AP individually, what is the most efficient way to scope this?
- The hospital wants visiting family members to get free internet access from the lobby and waiting areas, but wants those visitors to first agree to an acceptable-use policy before their device is allowed online. Which wireless feature is designed for exactly this workflow?
- A large hospital network runs its access points as Central-managed rather than tied to an on-site hardware controller. When network staff need to update a WLAN's settings for a whole clinic building at once, where is that change made?
- Biomedical engineering wants the WLAN used by networked infusion pumps to not appear in a casual Wi-Fi scan on a visitor's phone, to reduce the chance of someone accidentally trying to join it. Which WLAN setting addresses this specific concern?
- During AP provisioning for the new clinic wing, the network team wants each AP to receive its management IP address, subnet mask, and gateway automatically rather than typing these in on every device. Which provisioning approach fits this need?
- The RF design for the imaging suite calls for a dedicated WLAN that only operates in 5GHz, avoiding the more congested and interference-prone 2.4GHz band that several biomedical devices already use nearby. How should this WLAN be configured to meet that requirement?
- A hospital's wireless team needs to roll out an identical RF power and channel-width setting across all forty access points in the main tower in one change, without editing each AP separately. Which existing construct makes this a single action instead of forty?
- The outpatient annex across the road connects back to the main hospital campus over a modest point-to-point wireless link. The design wants staff clinical traffic tunneled back to the main campus for policy enforcement, while general internet-bound guest traffic at the annex exits locally to avoid straining that link. Which forwarding approach matches this?
- A hospital wants patient and visitor devices on the guest WLAN kept completely separate at the network layer from the WLAN used by clinical staff laptops, even though both networks are broadcast from the very same access points. What WLAN configuration choice enforces this separation?
- An IT technician plugs in a factory-default AP for the new surgical wing, but after several minutes it still has not appeared in Aruba Central's device list, even though the AP has a link light and appears to have network connectivity. What is the most likely explanation, assuming the AP was already added to the hospital's Central inventory?
- A small break-room WLAN for staff on the new ward is being set up quickly, without integrating it into the hospital's central authentication system yet. The requirement for now is simply that a single shared secret controls who can join. Which WLAN key setting fits this interim need?
- A wireless survey of the busy nurse-station area, dense with access points close together, shows unusually high co-channel interference degrading performance. The design calls for reducing the RF footprint per AP without shutting any radios off. Which radio setting adjustment addresses this?
- An AP that was originally provisioned for the general medical ward is physically relocated to the new pediatric wing, and its AP group membership is changed to match. What is the expected effect of that group change on the AP's wireless behavior?
- Hospital administration wants visitors on the guest WLAN to be able to reach the hospital's own patient-information website even before they accept the captive portal's terms, while everything else stays blocked until acceptance. Which captive portal concept enables this exception?
- At the outpatient annex, most client traffic (browsing local file shares, printing to a local printer) stays within the annex itself, and only a small portion needs to reach the main hospital campus. The design wants that local traffic switched right at the AP instead of adding unnecessary load to the point-to-point link back to campus. Which forwarding mode best fits the majority of this traffic?
- After validating a new guest WLAN's captive portal on a single test AP, the network team is ready to roll it out to every AP group across the hospital campus that should offer guest access. Using the Central-managed model, what is the correct way to deploy this at scale?
- The guest WLAN in the hospital's main lobby is seeing a handful of visitors monopolizing available bandwidth with large downloads, slowing the network for other waiting-room guests. The design wants a fair, per-client cap on guest bandwidth usage. Which WLAN-level setting addresses this?
- A hospital wants staff laptops joining the clinical Wi-Fi to prove their identity with domain credentials before they get any network access, rather than just knowing a shared passphrase. Which authentication approach is designed for this kind of per-user identity check at association time?
- An infusion pump on the med-surg ward has no way to run an 802.1X supplicant, but it still needs to authenticate onto the wired network port it's plugged into. Which authentication method is intended for exactly this kind of client?
- Instead of storing every staff member's credentials locally on each switch and controller across the hospital campus, the network team wants one central system that all access devices check against for both wired and wireless logins. What role does that central system play?
- After a nurse successfully authenticates on the hospital's staff SSID, the access point needs to decide which role to place her session in so the right VLAN and firewall policy apply. Where does that role decision typically come from?
- The hospital's radiology wing has a mix of staff workstations that can run 802.1X and older imaging viewers that cannot. The deployment technician wants 802.1X attempted first on every port, with devices that don't respond falling back to a hardware-address check instead of being denied outright. What is this fallback behavior called?
- Biomedical devices roam between wards on the hospital campus, but the security team wants their traffic to always be tunneled back to the same central policy enforcement point no matter which access point or wiring closet they associate through, rather than being switched locally at each edge. Which concept describes this approach?
- After pushing the access-layer configuration for a newly built pediatrics ward, the technician wants to confirm that a staff nurse's laptop actually lands in the correct VLAN once it authenticates, rather than assuming the configuration behaved as intended. What is the most direct way to confirm this?
- A single hospital SSID is used by both staff and visiting family members, but each group needs to reach very different resources once connected: staff need clinical systems, and visitors need only internet access. Which approach lets one SSID serve both groups with different network access?
- During a scheduled maintenance window, the hospital's RADIUS server briefly becomes unreachable, and staff laptops attempting 802.1X authentication start failing to connect to the clinical SSID. What does this outage most directly demonstrate about the deployment's authentication design?
- A biomedical device on the new oncology ward authenticates successfully and receives an IP address in its assigned VLAN, but the technician still hasn't finished validating the deployment. What additional check is needed to confirm the deployment is actually working as intended?
- A security-minded technician points out that MAC authentication, used for the ward's older nurse-call panels, verifies a hardware address rather than a real credential. What is the practical risk this introduces compared to 802.1X?
- A new technician is learning 802.1X and hears the terms supplicant, authenticator, and authentication server for the first time while shadowing a rollout on the surgical wing. Which pairing correctly matches each role to what it does?
- A newly opened cardiology ward has three kinds of clients landing on the same access ports: staff laptops, a vital-signs monitor, and a printer. The design calls for each to receive a different role automatically, without a technician manually assigning anything port by port. What makes this automatic differentiation possible?
- A staff member on the newly onboarded transplant ward can associate to the clinical SSID and authenticates successfully, but reports being unable to reach the electronic health records system that every other staff member on that SSID can reach. Association and authentication both look fine in the logs. What should the technician check next?
- The network team is frustrated that every ward's access switches need the exact same set of VLANs configured before a roaming infusion pump can keep the same policy as it moves from cardiology to oncology. Which approach removes the need to replicate that VLAN everywhere the device might roam?
- A network engineer wants to stop a rogue or misconfigured DHCP server plugged into an access port from handing out incorrect IP addresses to nurse-station devices on a ward switch. Which switch feature should be enabled to block DHCP server responses coming from untrusted ports?
- When RADIUS accepts a staff member's login on the maternity ward's SSID, it can include additional information alongside the plain accept, such as which role or VLAN that session should receive. What is this additional information called?
- After onboarding a new ward's nurse-call system, which uses MAC authentication because it can't run a supplicant, the technician wants to confirm the deployment actually worked. What should be verified specifically for this device?
- Family members visiting a patient on the surgical ward connect to the hospital's guest Wi-Fi and are presented with a login page before they can browse the internet, but they should never be able to reach the clinical systems staff use on a different SSID. What ensures this separation for the guest connection?
- A hospital's network security team wants to control not only which administrators can log in to the core switches, but also which specific configuration commands each administrator is permitted to run once logged in. Which AAA protocol is built to authorize individual commands like this?
- Before signing off on a newly built neurology ward and handing it over to clinical staff, the deployment technician wants a complete checklist confirming the access-layer rollout actually works end to end. Which sequence best captures a full post-deployment validation?