A university wants to deploy ClearPass with the Guest module. The university has two types that need to use web login authentication. The first type of users are students whose accounts are in an Active Directory server. The second type of
users are friends of students who need to self-register to access the network.
How should the service be set up in the Policy Manager for this network?
A. Guest User Repository and Active Directory server both as authentication sources
B. Active Directory server as the authentication source, and Guest User Repository as the authorization source
C. Guest User Repository as the authentication source, and Guest User Repository and Active Directory server as authorization sources
D. Either the Guest User Repository or Active Directory server should be the single authentication source
E. Guest User Repository as the authentication source and the Active Directory server as the authorization source
Refer to the exhibit.

Based on the guest Self-Registration with Sponsor Approval workflow shown, at which stage is an email request sent to the sponsor?
A. after `Guest Role (7)'
B. after `Login Message page (5)'
C. after `Submit form (3)'
D. after `Automated NAS login (6)'
E. after `Redirects (1)'
Refer to the exhibit.

A user logged in to the Self-Service Portal as shown. What do the traffic received and sent statistics present?
A. These show the total amount of traffic the guest transmitted, as seen through RADIUS CoA packets from the NAD to ClearPass.
B. These show the total amount of traffic the NAD transmitted to ClearPass, as seen through RADIUS accounting messages from the NAD to ClearPass.
C. These show the total amount of traffic the guest transmitted after account expiration, as seen through RADIUS accounting messages sent from the NAD to ClearPass.
D. These show the total amount of traffic the guest transmitted, as seen through RADIUS CoA packets from the client to ClearPass.
E. These show the total amount of traffic the guest transmitted, as seen through RADIUS accounting messages sent from the NAD to ClearPass.
A customer with an Aruba Controller wants it to work with ClearPass Guest. How should the customer configure ClearPass as an authentication server in the controller so that guests are able to authenticate successfully?
A. Add ClearPass as a RADIUS CoA server.
B. Add ClearPass as a RADIUS authentication server.
C. Add ClearPass as a TACACS+ authentication server.
D. Add ClearPass as an HTTPS authentication server.
ClearPass and a wired switch are configured for 802.1x authentication with RADIUS CoA (RFC 3576) on UDP port 3799. This port has been blocked by a firewall between the wired switch and ClearPass. What will be the outcome of this state?
A. RADIUS Authentications will fail because the wired switch will not be able to reach the ClearPass server.
B. During RADIUS Authentication, certificate exchange between the wired switch and ClearPass will fail.
C. RADIUS Authentications will timeout because the wired switch will not be able to reach the ClearPass server.
D. RADIUS Authentication will succeed, but Post-Authentication Disconnect-Requests from ClearPass to the wired switch will not be delivered.
E. RADIUS Authentication will succeed, but RADIUS Access-Accept messages from ClearPass to the wired switch for Change of Role will not be delivered.
An Android device goes through the single-SSID Onboarding process and successfully connects using EAP-TLS to the secure network. What is the order in which services are triggered?
A. Onboard Authorization, Onboard Provisioning, Onboard Authorization
B. Onboard Provisioning, Onboard Pre-Auth, Onboard Authorization, Onboard Provisioning
C. Onboard Provisioning, Onboard Authorization, Onboard Pre-Auth
D. Onboard Provisioning, Onboard Authorization, Onboard Provisioning
E. Onboard Provisioning, Onboard Pre-Auth, Onboard Authorization
Which device type supports Exchange ActiveSync configuration with Onboard?
A. Linux laptop
B. Mac OS X device
C. Apple iOS device
D. Windows laptop
E. Android device
Refer to the exhibit.

Based on the configuration for the client's certificate private key as shown, which statements accurately describe the settings? (Select two.)
A. The private key is stored in the ClearPass server.
B. The private key is stored in the user device.
C. The private key for TLS client certificates is not created.
D. More bits in the private key will increase security.
E. More bits in the private key will reduce security.
Refer to the exhibit.

An administrator configured a service and tested authentication, but was unable to complete authentication successfully. The administrator performs a Search using insight and the information displays as shown. What is a possible reason for the ErrorCode `Failed to classify request to service' shown?
A. The user failed authentication due to an incorrect password.
B. ClearPass could not match the authentication request to a service, but the user passed authentication.
C. ClearPass service authentication sources were not configured correctly.
D. The NAD did not send the authentication request.
E. ClearPass service rules were not configured correctly.
Refer to the exhibit.

Based on the Policy configuration shown, which VLAN will be assigned when a user with ClearPass role Engineer authenticates to the network successfully on Saturday using connection protocol WEBAUTH?
A. Full Access VLAN
B. Employee VLAN
C. Internet VLAN
D. Deny Access