Refer to the exhibit.

AOS-Switches will enforce 802.1X authentication on edge ports. The company has two RADIUS servers, which are meant to provide redundancy and load sharing of requests. The exhibit shows the planned RADIUS settings to deploy to the switches.
What should customers understand about this plan?
A. AOS switches do not support two RADIUS servers for redundancy, instead, a secondary authentication method is required.
B. Dynamic authentication is only permitted on one of the RADIUS servers and must be removed from the other.
C. Each RADIUS server must use a unique port number for the authentication and dynamic authorization port.
D. Each AOS-Switch will send all RADIUS requests to the first server on the list unless that server becomes unreachable.
Refer to the exhibits. Exhibit 1.

Exhibit 2.

The company wants to minimize congestion on Link 1.
Which spanning tree implementation meets this goal?
A. Instance 1 = VLANs 4-5 Instance 2 = VLANs 6-7 Switch 2 instance 1 priority = 0 Switch 2 instance 2 priority = 1 Switch 3 instance 1 priority = 1 Switch 3 instance 2 priority = 0
B. Instance 1 = VLANs 4,6 Instance 2 = VLANs 5,7 Switch 2 instance 1 priority = 0 Switch 2 instance 2 priority = 1 Switch 3 instance 1 priority = 1 Switch 3 instance 2 priority = 0
C. Instance 1 = VLANs 4,6 Instance 2 = VLANs 5,7 Switch 2 instance 1 priority = 0 Switch 2 instance 2 priority = 1 Switch 3 instance 1 priority = 0 Switch 3 instance 2 priority = 1
D. Instance 1 = VLANs 4-5 Instance 2 = VLANs 6-7 Switch 2 instance 1 priority = 0 Switch 2 instance 2 priority = 1 Switch 3 instance 1 priority = 0 Switch 3 instance 2 priority = 1
An AOS-Switch needs to be configured to support tunneled node in role-based mode. The Mobility Controller administrators tell the switch administrators that the AOS-Switch will integrate with a cluster of Mobility Controllers. The cluster virtual IP address is 10.1.1.10.
How should switch administrator integrate the AOS-Switch with the cluster?
A. Double-check the settings with the Mobility Controller administrators because the planned configuration is incomplete with the switch settings.
B. Configure the virtual IP address as the tunneled-node-server address, tunneled node will work, but the clustering features will not provide redundancy.
C. Configure the virtual IP address as the tunneled-node-server address. The switch will automatically learn controller IP addresses to which to tunnel various traffic.
D. Configure the virtual IP address for the primary tunneled-node-server and an actual controller IP address for the backup tunneled-node-server in order to receive redundancy.
Refer to the exhibit.

The exhibit shows configurations for interface 5 and VLAN 20. Note that DHCP snooping and ARP protection are also enabled.
A network administrator finds that interface 5 on an AOS-Switch is disabled. The administrator re-enables the interface, but it shuts down again.
What should the administrator investigate?
A. a device that sends too much unicast traffic
B. rogue DHCP server
C. a loop on the interface
D. a device that sends unauthorized ARP messages
A company has AOS-switches, Aruba ClearPass, and Aruba AirWave. A network administrator needs to find the source of a performance issue that often occurs at the start of the day and early in the afternoon.
Which action is likely to give the administrator the most useful information for the investigation?
A. Access the Network Device view on ClearPass.
B. Use the configuration audit tool on AirWave.
C. View the current running config on each switch.
D. View usage patterns on the switches on AirWave.
An AOS-Switch needs to use captive portal to integrate with an Aruba ClearPass Guest solution. The solution should allow guests to connect their own devices to the network, be redirected to a portal, log in, and be granted access transparently.
What is one setting administrators should configure for this solution?
A. ClearPass should be defined as the enhanced Web Auth (EWA) server.
B. RADIUS MAC-Auth should be enabled on the guest ports.
C. Web-Auth should be enabled on the guest ports.
D. BYOD redirect should be enabled globally.
Refer to the exhibit.

Switch-1 and Switch-2 connect on interface A23. The switches experience a connectivity issue. The network administrator sees that both switches show this interface as up. The administrator sees the output shows in the exhibit on Switch-1.
What is a typical issue that could cause this output?
A. a hardware issue, such as a broken cable
B. asymmetric routing introduced by a routing configuration error
C. an issue with queuing, caused by mismatched QoS settings
D. mismatched IP addresses on the VLAN for the link
AOS-Switches authenticate guests to ClearPass with captive portal. When guests first connect their device to the network, they are redirected to a captive portal in which they log in. ClearPass then stores the guest MAC addresses, and the guests are permitted access. Due to a conflict, the network administrator needs to change the dynamic authorization port, port 3799 on Aruba ClearPass.
If the administrator forgets to also change the port on one of the AOS-Switches, what will be one symptom?
A. Some guests receive full access to the network when they first connect instead of being redirected to the portal page
B. When some guests successfully authenticate in the captive portal, they are redirected back to the portal page
C. Guests are redirected to the system listening on port 3799
D. Some guests are unable to reach the captive portal page. Instead, they receive no access at all
How far do OSPF link state updates (LSUs) for Type 1 (Router) and Type 2 (Network) LSAs propagate?
A. to every OSPF router in the local area
B. to every OSPF router in all areas
C. to every OSPF router in the local area and the backbone
D. to every OSPF router in the network to which the LSU applies
Refer to the exhibit.

Endpoints in VLAN 2 connect directly to this switch. These devices should only be able to send DHCP, DNS, HTTP, and HTTPS traffic. However, they are able to send any traffic. Based on the exhibit, what is the issue?
A. The switch does not have an IP address on VLAN 2.
B. The ACL lacks a deny ip any any statement at the end.
C. The ACL is applied in the wrong direction.
D. The name of the ACL applied to VLAN 2 is incorrect.