Ch10: Implementing Secure WLANs Flashcards
Match the AAA service (Authentication, Authorization, and Accounting) to an appropriate description.
A. Control authenticated user capabilities
B. Track user activity
C. Permit or deny access based on credentials and/or certificates
In Figure 10-56, which device would be the authenticator?
A. Endpoint
B. Switch
C. Authentication server
D. AD/LDAP/CA server”
Which of the options below accurately compares 802.1X authentication vs. captive portal authentication? (Select three.)
A. They both occur at layer 3 of the OSI model.
B. 802.1X authentication is typically used for corporate employee access.
C. Captive portal authentication is often used for guest access.
D .802.1X authentication requires clients to authenticate to a authentication server as soon as the endpoint connects.
During 802.1X client authentication, which devices can perform the authenticator role? (Select two.)
A. Supplicant
B. AP
C. Switch
D. Authentication server
E. RADIUS
There are a few popular Extensible Authentication Protocols (EAP). Match the advantage or disadvantage with the appropriate EAP method (EAP-TLS, PEAP, and EAP-TEAP).
A. Very strong security, mitigates risk of password authentication.
B. Easier to implement than some other methods, but slightly weaker security.
C. May have relatively limited support as compared to other methods.
D. Enables chaining of machine and user authentication with tokens.
E. Requires the overhead of managing CA services, certificate distribution and management
Your colleague is asking about the role-based ArubaOS Firewall. Which statements below can you leverage to improve their understanding? (Select three.)
A. It can enforce different rules based on user identity and assigned role but increases the reliance on VLANs and subnets for security.
B. A role is a group of settings that controls client traffic.
C. A role can include rules that leverage Deep Packet Inspection (DPI) and Web Content Classification (WebCC).
D. It can leverage roles derived from a authentication server.