HPE Aruba Certified Mobility Professional (ACMP) — Question 76
An AOS-Switch enforces 802.1X. It receives an Access-Accept with this HPE VSA from its Radius server:
Attribute Name and ID = HPE-User-Role (25) Value = contractor
The switch then rejects the client. What is one requirement for the switch to accept the message and authorize the client?
Answer options
- A. The initial user role must be set to the factory default permit any role.
- B. User role authorization must be enabled globally on the switch.
- C. An aaa authentication local user group must have the contractor name.
- D. The RADIUS server settings must permit dynamic authorization.
Correct answer: D
Explanation
The correct answer is D because for the switch to accept the Access-Accept message and authorize the client, dynamic authorization must be enabled on the RADIUS server. The other options, while they may relate to user roles or configurations, do not directly address the requirement for dynamic authorization from the RADIUS server.