Agentforce-Specialist Practice Test

Salesforce Spring 25 Release
204 Questions



An admin has created a WLAN that uses the settings shown in the exhibits (and has not otherwise adjusted the settings in the AAA profile) A client connects to the WLAN Under which circumstances will a client receive the default role assignment?

A. The client has attempted 802 1X authentication, but the MC could not contact the authentication server

B. The client has attempted 802 1X authentication, but failed to maintain a reliable connection, leading to a timeout error

C. The client has passed 802 1X authentication, and the value in the Aruba-User-Role VSA matches a role on the MC

D. The client has passed 802 1X authentication and the authentication server did not send an Aruba-User-Role VSA

D.   The client has passed 802 1X authentication and the authentication server did not send an Aruba-User-Role VSA

Explanation:

From the configuration shown in the exhibit:

The WLAN is using WPA3-Enterprise with 802.1X authentication.
The authentication server is set to ClearPass.
Server-derived roles are unchecked, meaning the controller will not use roles sent by the RADIUS server unless that option is explicitly enabled.
A default role is set to myrole.

πŸ” When is the default role assigned?

In Aruba Mobility Controllers, the default role is assigned to a client after successful authentication if:

1. Server-derived roles are disabled (as in this case), or
2. The authentication server (e.g., ClearPass) does not send the Aruba-User-Role VSA, or
3. The role sent by the server doesn't match any existing role on the controller (and server-derived roles are enabled)

In this scenario:

The client successfully authenticates
No role is assigned via VSA (or VSA usage is disabled)
Therefore, the controller assigns the default role: myrole

❌ Why the other options are incorrect:

A. Client attempted 802.1X but auth server unreachable
➀ In this case, authentication fails, so no role is assigned β€” client won’t be connected.

B. Client attempted 802.1X but connection timed out
➀ Again, failed authentication means no role assignment.

C. Client passed 802.1X and VSA matches a role
➀ In this case, the server-derived role would be used β€” not the default.

However, server-derived roles are disabled here, so this path wouldn't occur.

Agentforce-Specialist Practice-Test - Home Previous
Page 24 out of 204 Pages