HPE7-A06 HPE Campus Access Switching Expert Written Exam Topics and Questions
These HPE Campus Access Switching Expert Written Exam (HPE7-A06) exam topics are organized according to official exam domains to help candidates quickly verify coverage and focus on assessment rather than theory. Each domain is paired with topic-wise HPE7-A06 sample questions that reflect how objectives are tested in the actual exam. This structure enables efficient review, targeted self-assessment, and rapid identification of weak areas when preparing for the HPE Campus Access Switching Expert Written Exam certification exam.
Let's Practice Free HPE7-A06 Questions Aligned with Official Exam Topics
The exam opens with network stack fundamentals, the bedrock protocols and models that underpin every campus deployment. At 4 percent this is the lightest topic by weight, but the scenario-led format means you need diagnostic skill under pressure. Expect to trace packet flow, interpret error messages, and isolate whether a fault sits at Layer 2, Layer 3, or somewhere in the control plane. How Network Stack is tested Items present a customer complaint or an incomplete troubleshooting log, then ask...
The exam opens with network stack fundamentals, the bedrock protocols and models that underpin every campus deployment. At 4 percent this is the lightest topic by weight, but the scenario-led format means you need diagnostic skill under pressure. Expect to trace packet flow, interpret error messages, and isolate whether a fault sits at Layer 2, Layer 3, or somewhere in the control plane.
How Network Stack is tested
Items present a customer complaint or an incomplete troubleshooting log, then ask you to identify the layer at fault or the next diagnostic step. You are assessed on whether you can move methodically through encapsulation, recognize where protocol negotiation breaks, and distinguish a misconfigured gateway from a routing black hole. The trap is jumping to a fix before confirming the symptom's true location. Candidates lose marks when they pick a Layer 3 remedy for what turns out to be a spanning-tree block, or when they miss clues in output that point to MTU mismatch rather than reachability. Four percent means roughly three or four items, so every miss is expensive. Read the exhibit completely, compare expected behavior against observed state, and confirm the layer before choosing your action.
The practice test lets you see how scenario exhibits are formatted and how much log detail the items include. Because the topic is narrow, working a full bank confirms you can handle every common stack diagnostic pattern without second-guessing under time pressure.
The question below asks you to interpret output and pinpoint where in the stack the fault originates.
Connectivity moves from theory to implementation. You design configurations that meet stated customer requirements, apply advanced architectures, identify weak points in a proposed design, and troubleshoot deployment failures. Nine percent means this topic appears more than twice as often as the stack fundamentals that preceded it, so gaps here cost you quickly. β Configuration and architecture You translate a requirements document into working syntax, choosing the right feature set for link aggregation, uplink redundancy, and inter-VLAN routing. The exam expects...
Connectivity moves from theory to implementation. You design configurations that meet stated customer requirements, apply advanced architectures, identify weak points in a proposed design, and troubleshoot deployment failures. Nine percent means this topic appears more than twice as often as the stack fundamentals that preceded it, so gaps here cost you quickly.
β Configuration and architecture
You translate a requirements document into working syntax, choosing the right feature set for link aggregation, uplink redundancy, and inter-VLAN routing. The exam expects you to recognize when a customer needs stacked switches versus standalone units with VSF, and when to apply dynamic rather than static methods. Advanced architectures include spine-and-leaf topologies for the campus core, collapsed distribution designs, and multi-chassis approaches that blend physical and logical redundancy. You also decide where to place Layer 3 boundaries so that failure domains stay small and traffic flows efficiently. The challenge is matching the architecture to the scale and fault-tolerance goals without over-engineering or leaving single points of failure.
β Design critique and deployment troubleshooting
Items show a topology or a configuration snippet and ask what will break first. You identify missing redundancy, bandwidth bottlenecks, or loops that spanning-tree cannot resolve. Deployment troubleshooting covers the gap between a working lab config and a production rollout that fails because of firmware mismatches, incompatible transceivers, or cabling errors. You interpret pre-deployment checks, compare planned versus discovered neighbors, and decide whether the fault lies in physical connectivity, auto-negotiation, or a provisioning mistake. Candidates trip when they assume the design is sound and focus only on syntax, or when they overlook that a valid configuration can still create a non-functional network if the architecture itself has a flaw.
How Connectivity is tested
Expect a mix of design-review items that present a topology and ask what is missing or misconfigured, and build-from-requirements items that give you a customer brief and ask which configuration satisfies it. The weight means six to eight items, so you will see several variants. The exam tests whether you can read a requirement that says "no single device failure may partition the network" and translate that into the correct stacking or VSF setup, then verify it against a diagram. You also face troubleshooting scenarios in which a deployment went live but users cannot reach a gateway, and you must decide if the problem is physical layer, VLAN assignment, or routing. The trap is choosing a fix that works in isolation but does not fit the stated constraints, such as enabling a protocol the customer explicitly ruled out. Another common error is missing that two valid design choices were offered but only one meets the scale or redundancy target. Read every requirement twice and confirm your answer satisfies all of them.
A full question bank gives you enough design-review and build-from-requirements items to learn which constraints appear repeatedly and which architecture keywords signal a particular solution. The PDF format lets you compare your reasoning against the correct topology before the exam clock starts.
The scenario that follows hands you a set of customer requirements and asks which configuration meets them without introducing new risk.
Resiliency and virtualization sit between connectivity and switching, focused entirely on keeping the network alive when hardware fails. Eight percent of the exam tests your ability to design and troubleshoot mechanisms that deliver redundancy, fault tolerance, and seamless failover. The coverage is narrow but deep: you need to know not just which protocol to enable, but also where it breaks and how to prove it will behave correctly under failure. How Network Resiliency and virtualization is tested Items present a...
Resiliency and virtualization sit between connectivity and switching, focused entirely on keeping the network alive when hardware fails. Eight percent of the exam tests your ability to design and troubleshoot mechanisms that deliver redundancy, fault tolerance, and seamless failover. The coverage is narrow but deep: you need to know not just which protocol to enable, but also where it breaks and how to prove it will behave correctly under failure.
How Network Resiliency and virtualization is tested
Items present a topology with redundant links or devices and ask what happens when a specific component fails, or they show a configuration and ask why failover did not occur. You must recognize whether Virtual Switching Framework, link aggregation, or a first-hop redundancy protocol is the right answer, and whether the timers, priorities, and preemption settings will produce the desired behavior. The exam also tests virtualization in the form of virtual chassis and distributed switching, where multiple physical devices present as one logical unit. You trace control-plane state across member switches and decide whether a failure will trigger a re-election, a topology change, or silent packet loss. Candidates lose marks when they assume redundancy is automatic, when in fact it requires correct configuration of tracking, priorities, and hello intervals. Another trap is choosing a solution that provides failover but introduces a loop or fails to meet a convergence-time requirement. Eight percent means five to seven items, so every missed failover scenario or misconfigured priority hurts. Verify that your answer not only keeps traffic flowing but does so within the customer's recovery-time objective.
Resiliency questions often include topology diagrams and failure scenarios that are hard to visualize from memory. The practice test shows you how these items are drawn and lets you confirm you can trace failover paths before sitting the real exam.
The item below presents a redundant topology and asks what happens when a particular device or link goes down.
Switching is the heaviest topic on the exam. Nineteen percent means one item in five comes from this domain, so weak areas here guarantee a failing score. You implement, troubleshoot, and fix Layer 2 and Layer 3 switching, including VLAN segmentation, broadcast-domain control, and the technologies that interconnect them. The scope runs from basic port assignment through inter-VLAN routing, trunking, and the edge cases that cause silent failures in production. How Switching is tested Items give you a switching configuration...
Switching is the heaviest topic on the exam. Nineteen percent means one item in five comes from this domain, so weak areas here guarantee a failing score. You implement, troubleshoot, and fix Layer 2 and Layer 3 switching, including VLAN segmentation, broadcast-domain control, and the technologies that interconnect them. The scope runs from basic port assignment through inter-VLAN routing, trunking, and the edge cases that cause silent failures in production.
How Switching is tested
Items give you a switching configuration or a topology and ask why traffic is not forwarding, why broadcasts are leaking between segments, or which change will restore connectivity. You must interpret VLAN databases, recognize when a trunk is pruning the wrong VLANs, and decide whether a Layer 3 interface or a switched virtual interface is the correct solution for inter-VLAN routing. The exam also tests broadcast-domain design: you calculate how many hosts can coexist in a segment before performance degrades, and you decide where to split domains to contain failures. Interconnection technologies include trunking protocols, native VLAN handling, and the interaction between access ports and voice VLANs. Candidates lose marks when they assume all ports default to the same VLAN, when they forget that a missing route to a VLAN interface stops inter-VLAN traffic even if Layer 2 is perfect, or when they overlook that a trunk carrying all VLANs can still fail to forward because the far-end switch has not created the VLAN locally. Nineteen percent means fourteen to sixteen items, the largest block in the exam. Every broadcast-domain boundary and every trunk configuration is in scope, so you cannot afford to skip sub-topics.
Switching spans the widest range of scenarios, from simple VLAN mismatches to multi-layer routing interactions. A full bank lets you see every common failure mode and confirms you can distinguish a trunking problem from a routing problem under exam conditions.
The question that follows tests whether you can trace a switching fault through VLANs, trunks, and Layer 3 interfaces to find the break.
WLAN brings radio-frequency design and wireless-specific troubleshooting into the campus. Nine percent of the exam focuses on RF attributes, wireless functions, configuration from customer requirements, and Layer 2 behavior that differs from wired switching. You need to know how signal strength, channel width, and roaming thresholds affect performance, and how broadcast domains and inter-VLAN traffic behave when the access layer is an access point rather than a switch port. β RF design and wireless functions You design coverage by selecting...
WLAN brings radio-frequency design and wireless-specific troubleshooting into the campus. Nine percent of the exam focuses on RF attributes, wireless functions, configuration from customer requirements, and Layer 2 behavior that differs from wired switching. You need to know how signal strength, channel width, and roaming thresholds affect performance, and how broadcast domains and inter-VLAN traffic behave when the access layer is an access point rather than a switch port.
β RF design and wireless functions
You design coverage by selecting channel plans, transmit power, and cell overlap that balance capacity against interference. The exam tests your understanding of signal-to-noise ratio, co-channel contention, and the impact of adjacent-channel interference when channels are too close. You also troubleshoot roaming failures, where a client sticks to a distant AP or drops during handoff because thresholds are misconfigured. Wireless functions include band steering, load balancing, and airtime fairness, each of which changes how clients associate and how traffic is distributed. The challenge is recognizing when poor performance is a coverage gap, when it is interference, and when it is a client behavior that no RF change will fix.
β Configuration and Layer 2 behavior
Building a configuration from customer requirements means translating a brief that specifies SSIDs, VLANs, authentication methods, and QoS into controller or access-point syntax. You decide whether to tunnel traffic back to a controller or switch it locally, and you configure the VLAN mappings so that wireless users land in the correct broadcast domain. Layer 2 troubleshooting covers VLAN assignment per SSID, trunk configuration between AP and switch, and broadcast-domain isolation when guest and corporate traffic share the same physical infrastructure. Candidates lose marks when they assume wireless VLANs behave exactly like wired VLANs, forgetting that a single AP can inject multiple VLANs onto one uplink and that a misconfigured trunk will black-hole an entire SSID.
How WLAN is tested
Expect RF-design items that show a floor plan and ask where to place APs or which channel plan avoids overlap, and troubleshooting items that present client-association logs or controller output and ask why connectivity failed. You must interpret signal levels, identify sources of interference, and decide whether a roaming problem is due to threshold settings or insufficient cell overlap. Configuration items give you a requirements list and ask which SSID, VLAN, and security combination satisfies it. Layer 2 items test whether you can trace a VLAN from SSID through controller or AP to the wired switch, and whether you recognize when a trunk is pruning the VLAN the SSID needs. Nine percent means six to eight items, so you will face both design and troubleshooting. The trap is treating WLAN as an afterthought because you have strong wired-switching skills; the RF and roaming logic is entirely different and requires separate preparation.
Wireless scenarios mix RF analysis with VLAN and authentication dependencies, so a single weak area can cascade into multiple misses. The practice test shows you how controller output is formatted and which metrics matter most when diagnosing a wireless fault.
The scenario below combines RF attributes and VLAN assignment, asking you to identify why clients cannot associate or why traffic is not reaching the wired network.
Routing is the second-heaviest topic. Sixteen percent means it appears nearly as often as switching, and the focus is on designing and troubleshooting routing topologies and functions in a campus environment. You work with dynamic protocols, redistribution, route summarization, and the interaction between routing and the Layer 2 infrastructure beneath it. Mistakes here compound quickly because a routing fault can black-hole entire subnets. How Routing is tested Items present a topology with multiple routers or Layer 3 switches and ask...
Routing is the second-heaviest topic. Sixteen percent means it appears nearly as often as switching, and the focus is on designing and troubleshooting routing topologies and functions in a campus environment. You work with dynamic protocols, redistribution, route summarization, and the interaction between routing and the Layer 2 infrastructure beneath it. Mistakes here compound quickly because a routing fault can black-hole entire subnets.
How Routing is tested
Items present a topology with multiple routers or Layer 3 switches and ask why a prefix is missing from the routing table, why traffic is taking a suboptimal path, or which configuration change will restore reachability. You must interpret routing-protocol behavior, recognize when a route is being filtered by a policy or suppressed by summarization, and decide whether the fault is in neighbor adjacency, route advertisement, or next-hop reachability. The exam also tests redistribution between protocols, where a metric mismatch or a missing route-map causes silent loss. You trace traffic from source to destination, checking each hop's forwarding table and confirming that return traffic can follow the reverse path. Candidates lose marks when they assume a route will appear automatically, when they overlook that a working adjacency does not guarantee the route will be installed if a better path exists, or when they forget that a reachable next hop at Layer 3 requires a valid ARP entry and a working Layer 2 path. Sixteen percent means eleven to thirteen items, a substantial portion of the exam. Every routing-protocol feature and every redistribution edge case is fair game, so you cannot rely on rote memory of show commands. You need to understand why the protocol made the decision it did and what configuration change will alter it.
Routing topologies involve multiple devices and overlapping address spaces, so visualizing the fault path from a text description is hard. The PDF bank gives you annotated topologies and lets you compare your trace against the correct next-hop sequence before the timer runs out.
The question that follows asks you to diagnose why a route is missing or why traffic is not following the expected path through a multi-router campus.
Security covers the design and troubleshooting of access control, encryption, and policy enforcement across wired and wireless campus networks. Ten percent of the exam tests your ability to implement security concepts, diagnose wired 802.1X with EAP-TLS, and build or troubleshoot Group-Based Policy. The scope is broad, running from port security and ACLs through certificate-based authentication and dynamic segmentation. β Access control and 802.1X You design configurations that restrict which devices can connect, using port security, MAC authentication, and 802.1X. The...
Security covers the design and troubleshooting of access control, encryption, and policy enforcement across wired and wireless campus networks. Ten percent of the exam tests your ability to implement security concepts, diagnose wired 802.1X with EAP-TLS, and build or troubleshoot Group-Based Policy. The scope is broad, running from port security and ACLs through certificate-based authentication and dynamic segmentation.
β Access control and 802.1X
You design configurations that restrict which devices can connect, using port security, MAC authentication, and 802.1X. The exam focuses heavily on EAP-TLS, the certificate-based method that enterprises deploy for high-assurance environments. You troubleshoot why a supplicant fails to authenticate, tracing the exchange between client, switch, and RADIUS server to find whether the break is in certificate validation, VLAN assignment, or RADIUS reachability. You also interpret packet captures or debug logs that show TLS handshake failures, expired certificates, or trust-chain mismatches. Candidates lose marks when they assume 802.1X is working because the port shows authorized, when in fact the client landed in a guest VLAN due to a failed certificate check, or when they overlook that the switch needs both a server certificate for its own identity and a CA certificate to validate the client.
β Group-Based Policy and segmentation
Group-Based Policy uses tags to enforce access rules without tying them to VLANs or IP addresses. You build configurations that assign tags based on user identity or device type, then apply policies that permit or deny traffic between groups. The exam tests whether you can troubleshoot why a tag is not being applied, why a policy is not triggering, or why traffic is allowed when it should be blocked. You trace tag propagation across switches and confirm that every hop understands the policy. Segmentation also includes traditional ACLs and private VLANs, which isolate hosts within the same broadcast domain. The challenge is recognizing when a security failure is due to a missing tag, a misconfigured ACL, or a VLAN assignment that bypasses the policy entirely.
How Security is tested
Items present authentication logs, packet captures, or policy configurations and ask why a device was denied, why traffic is leaking between segments, or which setting will enforce the customer's access rules. You must interpret RADIUS attributes, certificate errors, and policy-match conditions under time pressure. The wired 802.1X scenarios are detailed: you see supplicant state, switch port status, and server logs, and you decide whether the fault is certificate expiry, a missing CA, or a RADIUS shared-secret mismatch. Group-Based Policy items test tag assignment and policy evaluation, asking you to trace why a tag is missing or why a deny rule is not taking effect. Ten percent means seven to nine items, and the troubleshooting depth is high. Candidates lose marks when they stop at "authentication failed" without checking whether the failure is in the certificate, the RADIUS response, or a downstream VLAN assignment, or when they assume a policy is active when it is actually being overridden by a higher-precedence rule.
Security troubleshooting relies on interpreting logs and packet captures that vary by vendor and feature. The practice test exposes you to the output formats the exam uses, so you recognize a certificate validation error or a tag mismatch without wasting minutes decoding syntax.
The item below presents an authentication failure or a policy violation and asks you to identify the root cause from logs or configuration snippets.
Authentication and authorization focus on AAA configurations and ClearPass integration. Nine percent of the exam tests your ability to design AAA setups that meet customer requirements and to troubleshoot why authentication is failing or why a user is landing in the wrong role. ClearPass adds policy-based profiling and posture checking, so you also trace how device attributes and health status translate into network access decisions. β AAA design and troubleshooting You build configurations that send authentication requests to the correct...
Authentication and authorization focus on AAA configurations and ClearPass integration. Nine percent of the exam tests your ability to design AAA setups that meet customer requirements and to troubleshoot why authentication is failing or why a user is landing in the wrong role. ClearPass adds policy-based profiling and posture checking, so you also trace how device attributes and health status translate into network access decisions.
β AAA design and troubleshooting
You build configurations that send authentication requests to the correct RADIUS or TACACS+ server, apply fallback methods when the primary server is unreachable, and assign users to roles or VLANs based on server responses. The exam tests whether you can interpret AAA method lists, recognize when a local fallback is being used instead of the intended server, and decide whether a failure is due to server unreachability, a shared-secret mismatch, or a missing attribute in the RADIUS response. You also troubleshoot authorization, where a user authenticates successfully but receives the wrong permissions because the role mapping is misconfigured or the server returned an attribute the switch does not recognize. Candidates lose marks when they assume authentication and authorization are the same process, or when they overlook that a working RADIUS exchange does not guarantee the user will land in the intended VLAN if the attribute name or value is wrong.
β ClearPass integration
ClearPass provides dynamic policy enforcement by profiling devices, checking posture, and returning access decisions to the switch or controller. You create and analyze integrations that use device fingerprints, health checks, and user identity to assign network privileges. The exam tests whether you can trace a ClearPass policy evaluation, identify why a device was profiled incorrectly, and decide whether a posture failure is due to missing endpoint software or a misconfigured health rule. You also confirm that the switch or controller is correctly consuming the ClearPass response, because a valid policy decision can still fail if the network device does not understand the returned role or VLAN. The challenge is that ClearPass decisions depend on multiple inputs, so a single misconfigured attribute or a missing endpoint agent can cascade into an access denial that looks like a network fault.
How Authentication/Authorization is tested
Items present AAA configurations, server logs, or ClearPass policy outputs and ask why a user was denied, why they landed in the wrong VLAN, or which configuration change will enforce the desired access control. You must interpret RADIUS attributes, method-list processing, and role-mapping tables under time pressure. ClearPass items show profiling results or posture-check outcomes and ask why a device was classified incorrectly or why a compliant endpoint was still denied. You trace the flow from authentication attempt through server decision to final VLAN or role assignment, checking each step for mismatches. Nine percent means six to eight items, and the troubleshooting is multi-layered because a failure can occur at the supplicant, the network device, the AAA server, or in the policy logic that ties them together. The trap is stopping at the first error message without confirming whether the error is the root cause or a symptom of a configuration mismatch further upstream.
AAA and ClearPass scenarios involve server logs, attribute dictionaries, and role mappings that are difficult to memorize. A full question bank lets you see how these elements combine in a failure scenario and confirms you can trace the decision path before the exam clock pressures you into guessing.
The scenario that follows asks you to diagnose an authentication or authorization failure by interpreting AAA or ClearPass output and identifying the misconfiguration.
Troubleshooting is a capstone topic that pulls together every domain you have covered. Ten percent of the exam presents advanced, multi-layer faults and asks you to perform end-to-end diagnosis and remediation. You cannot rely on a single show command or a memorized fix; you must trace the fault through physical, data-link, network, and policy layers, then choose the action that restores service without creating new problems. How Troubleshooting is tested Items give you a symptom, such as intermittent connectivity, failed...
Troubleshooting is a capstone topic that pulls together every domain you have covered. Ten percent of the exam presents advanced, multi-layer faults and asks you to perform end-to-end diagnosis and remediation. You cannot rely on a single show command or a memorized fix; you must trace the fault through physical, data-link, network, and policy layers, then choose the action that restores service without creating new problems.
How Troubleshooting is tested
Items give you a symptom, such as intermittent connectivity, failed voice calls, or slow application performance, along with partial diagnostic output. You decide which additional commands to run, interpret the results, and select the remediation that addresses the root cause. The exam tests whether you can distinguish correlation from causation: a flapping link and a routing flap may occur at the same time, but fixing the link may not stop the flap if a protocol timer is misconfigured. You also face scenarios in which multiple faults coexist, and you must prioritize which to fix first to restore service fastest. Advanced troubleshooting includes reading packet captures, comparing running config against intended state, and recognizing when a vendor bug or hardware fault is the true cause. Candidates lose marks when they jump to a fix that resolves the symptom but leaves the root cause active, when they choose a disruptive remediation that could be avoided with a targeted change, or when they misread the output and blame the wrong layer. Ten percent means seven to nine items, and every item is scenario-heavy. You will not see simple "Which command shows X?" questions here; every item requires you to synthesize information and decide on a course of action.
Advanced troubleshooting items present multi-page exhibits and require you to correlate evidence across layers. The practice test trains you to extract the relevant facts quickly and to recognize which diagnostic path the exam expects, so you do not burn minutes exploring dead ends under time pressure.
The question below hands you a complex fault scenario and asks you to identify the root cause and the correct remediation from the evidence provided.
Performance Optimization closes the exam with a focus on diagnosing and fixing throughput, latency, and utilization problems. Six percent tests your ability to analyze performance issues and apply remediations that improve service quality without destabilizing the network. You interpret traffic patterns, identify bottlenecks, and decide whether the fix is QoS, link aggregation, or a topology change. How Performance Optimization is tested Items present utilization graphs, latency measurements, or application-performance complaints and ask what is causing the degradation and which change...
Performance Optimization closes the exam with a focus on diagnosing and fixing throughput, latency, and utilization problems. Six percent tests your ability to analyze performance issues and apply remediations that improve service quality without destabilizing the network. You interpret traffic patterns, identify bottlenecks, and decide whether the fix is QoS, link aggregation, or a topology change.
How Performance Optimization is tested
Items present utilization graphs, latency measurements, or application-performance complaints and ask what is causing the degradation and which change will resolve it. You must recognize when high CPU is due to control-plane traffic that should be rate-limited, when packet loss is due to buffer exhaustion that QoS can mitigate, and when slow throughput is due to a half-duplex mismatch or a single overloaded link that needs aggregation. The exam also tests whether you understand the trade-offs: enabling aggressive QoS can starve best-effort traffic, and adding links without proper load-balancing configuration can leave the new capacity unused. You interpret show commands that display queue depths, drop counters, and forwarding rates, then decide which knob to turn. Candidates lose marks when they assume more bandwidth always solves the problem, when they overlook that a misconfigured QoS policy can make performance worse, or when they choose a fix that helps one application but breaks another. Six percent means four to five items, the smallest block after Network Stack. Every item is remediation-focused, so you need to know not just what is wrong but also which configuration change is safe to apply in production.
Performance issues are hard to reproduce in a lab, so seeing a variety of utilization and latency scenarios in a question bank builds pattern recognition you cannot get from reading alone. The practice test confirms you can interpret the graphs and counters the exam uses to describe a bottleneck.
The final question asks you to analyze performance data and select the remediation that improves throughput or latency without introducing new risk.
Ready to Start Practicing?
Access all questions and start your exam preparation journey
Upgrade to Full HPE7-A06 Exam Questions π