HPE7-A07 Sample Questions & Answers
Wireless rollout with access points and gateways ties with campus infrastructure using VSX, OSPF, and BGP, plus centralized or distributed overlays through VXLAN and EVPN, for the heaviest weighting, alongside authentication, QoS tuning, and management tools.
Launch the full HPE7-A07 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Campus Network Infrastructure · BGP Route Filtering
A network administrator is configuring a BGP peering between an Aruba CX switch at the campus edge and an ISP router. The administrator needs to prevent routes learned from other internal BGP peers from being advertised to the ISP. Which BGP attribute or mechanism should be used in an outbound route map to achieve this?
Show answer & explanation
Correct answer: B
Routes originated locally within the BGP process on the Aruba CX switch will have an empty AS-Path. Routes learned from other internal BGP (iBGP) peers or external BGP (eBGP) peers will have one or more AS numbers in the path. To advertise only locally originated routes, the administrator should create a route map that permits routes matching an empty AS-Path (often represented by the regex
^$) and denies all others. MED and Local Preference are used for influencing inbound traffic, and weight is for local path selection. - Question 2Beginner
Network Resiliency and Redundancy · VSX Architecture
A large retail company is migrating its campus core from a traditional Layer 2 design to a more resilient architecture using two Aruba CX 8400 switches. The primary goals are to provide active-active forwarding for all VLANs, eliminate STP, and ensure sub-second failover. Which ArubaOS-CX technology is specifically designed to meet all these requirements?
Show answer & explanation
Correct answer: B
Virtual Switching Extension (VSX) is Aruba's virtualization technology that allows two supported switches to appear as a single logical device to the rest of the network. It provides active-active forwarding paths, enabling the use of all available bandwidth and eliminating the need for Spanning Tree Protocol (STP) between the core and access layers through multi-chassis link aggregation (MC-LAG). VSX is designed for high availability with sub-second failover. VRF is for network segmentation, VRRP is for active-standby gateway redundancy, and VSF is a stacking technology for different switch models.
- Question 3Intermediate
Management, Monitoring, and Troubleshooting · AirWave Configuration Compliance
While configuring an Aruba wireless network using AirWave, a network engineer needs to ensure that all configuration changes are validated against a set of corporate security standards before being pushed to devices. For example, no AP group should be allowed to use WPA2-Personal (PSK). Which AirWave feature should be used to enforce this policy?
Show answer & explanation
Correct answer: C
AirWave's Configuration Audit and Compliance feature is specifically designed for this purpose. It allows administrators to define a 'golden' or desired configuration template and then audit devices against it. The compliance engine can flag any deviations, such as the use of a forbidden authentication method like PSK, and can be configured to automatically remediate the configuration. Triggers and Alerts are for monitoring device status, VisualRF is for location and heatmaps, and RAPIDS is for rogue AP detection.
- Question 4Advanced
Network Overlays and Segmentation · EVPN Route Types
A solutions architect is designing a campus network using a distributed overlay with EVPN-VXLAN. The design includes multiple VNIs that need to communicate with each other. Which EVPN route type is responsible for advertising the IP prefixes that enable inter-VNI (Layer 3) routing?
Show answer & explanation
Correct answer: D
The EVPN Type 5 route, or IP Prefix Route, is specifically used to advertise IP prefixes (routes) between different VNIs, enabling Layer 3 routing across the fabric. Type 2 routes advertise MAC and IP addresses of hosts within a single VNI for Layer 2 forwarding. Type 3 routes are used for BUM traffic handling. Type 1 routes are for auto-discovery and multihoming. Therefore, Type 5 is the correct answer for inter-VNI routing.
- Question 5IntermediateSelect 3
Management, Monitoring, and Troubleshooting · Wireless Client Troubleshooting
A technician is using the Aruba Central dashboard to troubleshoot a connectivity issue for a specific wireless client. The client is connected but reports extremely slow speeds. The technician navigates to the client details page. Which THREE of the following metrics are most critical to examine first to diagnose a potential RF-related performance problem? (Select THREE)
Show answer & explanation
Correct answers: A, C, E
When diagnosing RF performance issues, SNR, PHY Rate, and Retransmission Rate are the most critical metrics. A low SNR indicates a poor quality signal. A low PHY (data) rate indicates the client and AP have negotiated a slow connection speed, often due to poor signal. A high Retransmission Rate (Retries) indicates that frames are being corrupted in transit, usually due to interference or weak signal, which severely impacts throughput. Association Time and IP address are relevant for connectivity but not primary indicators of RF performance.
- Question 6Intermediate
Performance Optimization and QoS · QoS Policy Application
An engineer is configuring QoS on an Aruba CX switch to prioritize VoIP traffic from IP phones. The VoIP traffic is marked with DSCP EF (46). The engineer creates a QoS policy with a class for this traffic and assigns it to a high-priority queue. To which interface type must this policy be applied to affect traffic originating from the IP phones?
Show answer & explanation
Correct answer: B
QoS policies that classify and queue traffic are applied to interfaces where contention (congestion) can occur. To prioritize traffic as it enters the network from the source (the IP phone), the policy must be applied on the physical switch port in the inbound direction. This allows the switch to immediately classify the traffic based on its DSCP marking and place it into the appropriate priority queue before it is switched or routed. Applying it outbound on an SVI or uplink would only affect traffic after it has already traversed part of the switch.
- Question 7Intermediate
Security · Role-Based Access Control (RBAC)
A systems administrator is configuring role-based access for managing Aruba CX switches. The goal is to create a 'monitoring' role that allows users to execute all
showcommands but denies any configuration changes. The administrator plans to use the commandaaa authorization commands local. Which configuration snippet correctly defines this role?Show answer & explanation
Correct answer: D
ArubaOS-CX roles use a sequence of permit/deny rules, similar to an ACL. To allow all
showcommands but nothing else, the correct approach is to create a rule that explicitly permits any command starting with 'show' (show .*) and then a subsequent, broader rule that denies all other commands (.*). This creates a secure, least-privilege role. Simply permitting 'show' or denying 'configure' would not be specific enough and could have unintended consequences due to implicit rules. - Question 8Intermediate
Wireless Networks and WLAN · High-Density Wi-Fi Optimization
A deployment engineer is setting up a high-density Wi-Fi network in an auditorium using Aruba AP-555s. To optimize performance and minimize co-channel interference, the engineer wants to disable lower data rates for the 5GHz band. What is the primary reason for taking this action in a high-density environment?
Show answer & explanation
Correct answer: C
In high-density environments, airtime is the most precious resource. Clients communicating at low data rates consume a disproportionately large amount of airtime to transmit the same amount of data as a fast client. Disabling lower data rates forces clients to connect at higher speeds, which reduces their airtime consumption. A secondary effect is that it effectively shrinks the usable cell size, as clients with weak signals (who would use low rates) can no longer associate, which helps reduce co-channel interference.
- Question 9Beginner
Campus Network Infrastructure · OSPF Route Summarization
A network architect is designing a multi-area OSPF deployment for a large campus. To improve stability and reduce the size of the routing tables on switches in non-backbone areas, the architect decides to implement route summarization. Where in the OSPF hierarchy must this summarization be configured?
Show answer & explanation
Correct answer: C
In OSPF, inter-area route summarization is performed on the Area Border Routers (ABRs). An ABR connects one or more non-backbone areas to the backbone (Area 0). By configuring summarization on the ABR, it advertises a single summary route (Type 3 LSA) into the backbone area instead of multiple specific routes from its attached area. This reduces the LSDB size and routing table complexity in other areas. ASBRs summarize external routes, not internal inter-area routes.
- Question 10Advanced
Network Overlays and Segmentation · EVPN-VXLAN Design and Segmentation
Case Study: Global Logistics Inc. (GLI)
Company Background: GLI is a large logistics company with a central headquarters and numerous distribution centers. They are undertaking a major network modernization project for their HQ campus. The existing network is a traditional 3-tier architecture with a large Layer 2 domain at the access layer, which has caused instability due to spanning-tree issues.
Current Situation: The network team has decided to implement an EVPN-VXLAN fabric to create a more scalable and resilient network. The design uses Aruba CX switches in a spine-leaf topology. A key requirement is to provide secure segmentation between different corporate departments (e.g., Finance, HR, Operations) and also to accommodate a large, transient guest network.
Requirements:
- The solution must provide Layer 2 and Layer 3 segmentation across the fabric.
- Inter-departmental routing must be handled efficiently within the fabric.
- The guest network must be completely isolated from all corporate resources and only have access to the internet.
- The solution should use a standards-based control plane for scalability.
Which combination of technologies provides the most effective solution to meet all of GLI's requirements?
Show answer & explanation
Correct answer: C
This is the most comprehensive and modern solution. BGP EVPN provides the standards-based, scalable control plane. Using separate VNIs provides Layer 2 segmentation. Mapping these VNIs to different VRFs provides robust Layer 3 isolation. A 'Corporate' VRF can contain routing information for all internal departments, allowing inter-VNI routing, while a separate 'Guest' VRF ensures the guest network is completely isolated with its own routing table, which can be configured with only a default route to the internet. This design meets all requirements natively within the fabric.
Ready for the real thing?
The full HPE7-A07 simulator has every exam-style question, timed mode, and instant scoring.