Chapter 1: Introduction to HPE Aruba CX Switching and the ACSA Exam
Learning Objectives
Describe the HPE7-A01 exam format, blueprint, and passing score so you can plan a study schedule that matches how the exam actually weights its domains.
Identify the Aruba CX switch families (6000, 6100, 6200, 6300, 6400, 8000, 8100, 9300, 10000) and recognize which target use case each was engineered for.
Explain the AOS-CX operating system architecture, paying particular attention to the database-driven design that underpins the CLI, REST API, and Network Analytics Engine (NAE).
Recognize where the Aruba Certified Switching Associate (ACSA) credential fits within the broader HPE Aruba certification track and how it sets you up for ACP and ACE level work later.
Pre-Quiz: Exam Overview
1. The ACSA blueprint dedicates 70 percent of its weighting to "classic" Layer 2 and Layer 3 networking. Which combination of domains accounts for that 70 percent?
2. With approximately 60 questions and 90 minutes of testing time, what is the per-question pacing implied by the ACSA blueprint?
Roughly 30 seconds per questionRoughly 60 seconds per questionRoughly 90 seconds per questionRoughly 3 minutes per question
3. A candidate has 10 study hours per week for 6 weeks (60 total). Using a proportional allocation against the ACSA domain weights, which allocation is best for the Switching & VLANs domain?
~9 hours~12 hours~18 hours~30 hours
4. The book treats HPE7-A01 and HPE6-A86 as interchangeable codes. What is the underlying reason given?
Both exams cover identical AOS-CX-based ACSA content even though the catalog code has shifted.HPE retired HPE7-A01 and folded its scoring directly into HPE6-A86 results.Pearson VUE allows candidates to substitute one code for the other at the test center.Third-party vendors are permitted to relabel exam codes for marketing purposes.
HPE7-A01 Exam Overview
Key Points
HPE7-A01 and HPE6-A86 are treated as interchangeable codes for the same Aruba Certified Switching Associate (ACSA) credential.
Five weighted domains: Switching & VLANs (30%), Routing & OSPF (20%), Security & ACLs (20%), Aruba Central (15%), Monitoring & API (15%).
"Classic" L2/L3 = 70 percent of the exam; "modern" cloud + programmability = 30 percent.
HPE recommends the AOS-CX Switching Fundamentals course (Rev. 24.31) and 6-12 months of switching experience.
If you have arrived at this book hunting for the "HPE7-A01" code on the HPE certification site, you may already have noticed that the catalog is in flux. The most current associate-level switching exam in the HPE Aruba portfolio is the Aruba Certified Associate - Switching (ACA-Switching), currently coded HPE6-A86, and the underlying body of knowledge — AOS-CX fundamentals — is the same content that "HPE7-A01" maps to in legacy and third-party study material. Whether your voucher reads HPE7-A01 or HPE6-A86, the blueprint, the question style, and the recommended preparation path are the same. This book treats the two codes as interchangeable and uses ACSA (the credential name) as the canonical label.
Exam objectives and weighting
The ACSA blueprint is built around five weighted domains. Memorize these percentages early — they tell you exactly how many study hours each topic deserves.
Standard/extended ACLs, 802.1X, MAC authentication, port security, DHCP snooping, DAI, ClearPass integration
Aruba Central Management
15%
Cloud management, Zero-Touch Provisioning (ZTP), firmware/group configuration, AI Insights, reporting
Monitoring & API
15%
NAE, REST API automation, sFlow, port mirroring
A practical reading of the table: 70 percent of the exam is "classic" Layer 2 and Layer 3 networking expressed in AOS-CX terms (switching, routing, security). The remaining 30 percent is what makes AOS-CX modern — cloud management through Aruba Central and on-box programmability through NAE and REST.
Number of questions: approximately 60 multiple-choice items.
Duration:90 minutes (~90 seconds per question).
Passing score: approximately 66 percent.
Delivery: proctored at Pearson VUE; online proctoring also available in most regions.
Real-world analogy: Think of the 90-minute clock as a single highway commute. You want a steady cruising speed (~1 question / 90 s), pull over briefly for "construction zone" scenarios, and avoid camping on a single hard problem.
Recommended experience level
There are no formal prerequisites, but HPE strongly recommends the AOS-CX Switching Fundamentals course (Rev. 24.31). Successful candidates typically have:
6 to 12 months of switching experience (any vendor; concepts transfer).
Key Takeaway: The ACSA exam is a 60-question, 90-minute, ~66%-to-pass associate-level credential dominated by L2/L3 fundamentals (70%) but distinguished by 30% cloud + programmability content. Plan study time in proportion to the published weights.
Post-Quiz: Exam Overview
1. The ACSA blueprint dedicates 70 percent of its weighting to "classic" Layer 2 and Layer 3 networking. Which combination of domains accounts for that 70 percent?
2. With approximately 60 questions and 90 minutes of testing time, what is the per-question pacing implied by the ACSA blueprint?
Roughly 30 seconds per questionRoughly 60 seconds per questionRoughly 90 seconds per questionRoughly 3 minutes per question
3. A candidate has 10 study hours per week for 6 weeks (60 total). Using a proportional allocation against the ACSA domain weights, which allocation is best for the Switching & VLANs domain?
~9 hours~12 hours~18 hours~30 hours
4. The book treats HPE7-A01 and HPE6-A86 as interchangeable codes. What is the underlying reason given?
Both exams cover identical AOS-CX-based ACSA content even though the catalog code has shifted.HPE retired HPE7-A01 and folded its scoring directly into HPE6-A86 results.Pearson VUE allows candidates to substitute one code for the other at the test center.Third-party vendors are permitted to relabel exam codes for marketing purposes.
Pre-Quiz: Switch Portfolio
1. A retail customer asks for two CX 6300s in each store closet. They want the simplest possible operations and accept a brief outage during firmware upgrades. Which redundancy technology fits best?
VSF (Virtual Switching Framework)VSX (Virtual Switching Extension)EVPN-VXLAN active/activeMC-LAG with separate control planes only
2. Which CX series is specifically distinguished by integrated Pensando DPUs that allow stateful firewalling and microsegmentation at line rate on the switch ASIC?
CX 6400CX 8325CX 9300CX 10000
3. An enterprise refresh requires a campus access switch that can power Wi-Fi 6/6E APs over 2.5G mGig downlinks with 25G uplinks back to aggregation. Which series best matches?
CX 6000CX 6100CX 6200CX 8400
4. A hospital insists on zero-maintenance-window firmware upgrades for its data-center core pair of CX 8325s. Which redundancy choice is necessary?
VSF, because it provides a single shared control plane.VSX, because each peer has an independent control plane and can be upgraded individually.A standalone pair without any redundancy protocol.An RSTP-only design relying solely on spanning tree.
Aruba CX Switch Portfolio
Key Points
The CX portfolio is intentionally tiered: 6000-class for access, 6300/6400/8100/8325/8360 for aggregation/core, 8400/9300/10000 for the data center.
The entire portfolio runs the same AOS-CX image — skills transfer 1:1 across price points.
VSF = single-control-plane stacking (up to 10 members), best for campus closets; commonly a 50G DAC ring on the 6300.
VSX = active-active dual-control-plane redundancy enabling non-disruptive upgrades; standard in 6400/8000-series.
The CX 10000 is the headline data-center product because of integrated Pensando DPUs for stateful services.
Animation: CX Portfolio Tiered by Network Role
Three tiers fade in left-to-right. Hover any chip for the model's role.
Figure 1.2: Aruba CX switch portfolio hierarchy by network tier
The 6000-class switches are the workhorses of the wiring closet. They terminate user devices — laptops, IP phones, wireless APs, IoT — and they dominate by sheer count in any campus deployment.
Series
Form factor
Typical port mix
Uplinks
Primary role
CX 6000
Fixed
12/24/48 × 1G with PoE options
1G/10G
Small office / branch access
CX 6100
Fixed
24/48 × 1G
4 × 10G SFP+
Cost-optimized campus access
CX 6200
Fixed
24/48 × 1G or 1G/2.5G mGig
4 × 10G or 25G
Modern campus access (Wi-Fi 6/6E APs)
The differentiator inside the 6000-class line is PoE budget and uplink speed. The 6200 handles Wi-Fi 6/6E access points that need 2.5G mGig downlinks and 25G uplinks back to aggregation.
Aggregation / Core (6300/6400/8100/8325/8360)
Two acronyms recur here:
VSF (Virtual Switching Framework): up to 10 fixed switches behave as a single logical switch with a single control plane. Most commonly deployed as a ring topology using 50G DAC cables on the 6300.
VSX (Virtual Switching Extension): active-active, dual-control-plane alternative for the 6300, 6400, and 8000-series. Each VSX peer keeps its own control plane and reboots independently — giving non-disruptive upgrades and fast failover.
Worked example — choosing between VSF and VSX. A retail customer with two CX 6300s per store who accepts a brief firmware-upgrade outage → VSF: simple, single management plane. A hospital with two CX 8325s in the DC core that refuses any maintenance window → VSX: independent control planes allow per-peer upgrades.
Data center (8400/9300/10000)
The CX 10000 is the headline product of the data-center line: integrated Pensando DPUs allow it to run stateful firewalling, microsegmentation, and telemetry directly on the switch ASIC, eliminating "service hairpin" trips to a centralized appliance.
Choosing the right platform — the exam-day decision tree
Terminating end-user devices? → 6100/6200 (or 6000 for branch).
Closet aggregation pair that should look like one switch? → 6300 + VSF.
Data-center core? → 8400 (legacy), 9300 (modern), or 10000 (DPU).
Key Takeaway: Memorize the tier each model belongs to and recognize VSF as the campus stacking story versus VSX as the active-active redundancy story.
Post-Quiz: Switch Portfolio
1. A retail customer asks for two CX 6300s in each store closet. They want the simplest possible operations and accept a brief outage during firmware upgrades. Which redundancy technology fits best?
VSF (Virtual Switching Framework)VSX (Virtual Switching Extension)EVPN-VXLAN active/activeMC-LAG with separate control planes only
2. Which CX series is specifically distinguished by integrated Pensando DPUs that allow stateful firewalling and microsegmentation at line rate on the switch ASIC?
CX 6400CX 8325CX 9300CX 10000
3. An enterprise refresh requires a campus access switch that can power Wi-Fi 6/6E APs over 2.5G mGig downlinks with 25G uplinks back to aggregation. Which series best matches?
CX 6000CX 6100CX 6200CX 8400
4. A hospital insists on zero-maintenance-window firmware upgrades for its data-center core pair of CX 8325s. Which redundancy choice is necessary?
VSF, because it provides a single shared control plane.VSX, because each peer has an independent control plane and can be upgraded individually.A standalone pair without any redundancy protocol.An RSTP-only design relying solely on spanning tree.
Pre-Quiz: AOS-CX Architecture
1. Which statement best characterizes AOS-CX in one sentence?
It is CLI-driven; the database is a read-only export of show-command output.It is database-driven; the CLI, REST API, and NAE are different "lenses" on the same underlying data.It is a SNMP-driven NOS that copies data between CLI and management plane on demand.It is an asynchronous file-based NOS that writes configuration directly into kernel memory.
2. Which scenario illustrates the operational benefit of AOS-CX modular daemon isolation?
A bug in OSPF crashes the OSPF daemon; the supervisor restarts it while the data plane keeps forwarding traffic.A bug in OSPF reboots the entire chassis to ensure consistency.A bug in OSPF triggers an automatic vendor support call, halting all daemons.A bug in OSPF corrupts LACP and STP state because they share kernel memory.
3. What is the role of the AOS-CX time-series database, in addition to the configuration/state database?
It stores binary firmware images for ISSU rollback.It records timestamped samples of operational state, enabling NAE to detect trends like "error rate climbing for 30 minutes."It buffers SNMP traps before the management plane forwards them.It caches REST API responses so the CLI does not need to recompute them.
4. An NAE on-box agent is fundamentally a Python script that does which of the following?
Replaces the CLI by translating user commands into syscalls.Subscribes to time-series metrics, evaluates a condition, and triggers an action when that condition fires.Acts as a firewall between management VRF and default VRF.Compiles the running configuration into a binary image for ZTP.
AOS-CX Architecture Fundamentals
Key Points
AOS-CX is database-driven, not CLI-driven. The CLI, REST API, NAE, and Aruba Central are all "lenses" on a centralized in-memory database.
An OVSDB-style configuration/state database + a time-series telemetry database sit at the core.
Modular Linux daemons (OSPF, LACP, STP, REST server) communicate exclusively via the database — giving process isolation, hot-patch/ISSU, and a single common image.
Every CLI-configurable element is reachable via REST URI (e.g., GET /rest/v10.13/system/vlans).
NAE = Network Analytics Engine — Python agents subscribe to metrics, evaluate conditions, and take action (log, webhook, CLI, ticket).
Hardware → daemons → database → consumers. Pulsing arrows show the database is the single source of truth.
If you remember only one thing from this chapter, make it this: AOS-CX is database-driven, not CLI-driven. Every switch capability — VLANs, OSPF neighbors, interface counters, even the running configuration — lives as rows and columns in a centralized in-memory database. The CLI, REST API, and NAE Python agents are simply different "lenses" on the same underlying data.
flowchart TD
subgraph CONSUMERS["Management & Automation Consumers"]
CLI["CLI (interactive)"]
REST["REST API (automation)"]
NAE["NAE (on-box Python)"]
CENTRAL["Aruba Central (cloud)"]
end
subgraph DB["Centralized Database Layer"]
CFGDB["OVSDB-style Config & State DB"]
TSDB["Time-Series Telemetry DB"]
end
subgraph DAEMONS["Modular Linux Daemons"]
OSPF["OSPF"]
LACP["LACP"]
STP["STP"]
REST_D["REST Server"]
end
HW["Hardened Linux Kernel + Switch ASIC"]
CLI --> CFGDB
REST --> CFGDB
NAE --> TSDB
CENTRAL --> CFGDB
CFGDB <--> OSPF
CFGDB <--> LACP
CFGDB <--> STP
CFGDB <--> REST_D
OSPF --> HW
LACP --> HW
STP --> HW
HW --> TSDB
Time-series database (OVSDB-based)
AOS-CX uses an OVSDB-style centralized configuration and state database combined with a time-series database for telemetry. Two databases work together:
The configuration/state database holds the current declared configuration plus live operational state (interface up/down, neighbor adjacencies, MAC table).
The time-series database records timestamped samples — interface counters every 5 seconds, CPU every 10 seconds, queue depth every second. This is what lets NAE detect "error rate has been climbing for the last 30 minutes."
Real-world analogy: Think of a hospital. The configuration/state database is the patient's current chart — name, room, current medications. The time-series database is the bedside monitor — heart rate every second, oxygen saturation every five seconds. Doctors (CLI), automation (REST), and on-call alerts (NAE) all read the same charts and monitors.
Modular daemons and process isolation
Process isolation. A bug in OSPF cannot corrupt LACP state and cannot crash the switch.
Hot-patch and ISSU. Daemons are independent, enabling in-service software upgrades on supported platforms.
Common image across the portfolio. The same AOS-CX binary set runs from 6100 to 10000.
Worked example — daemon isolation in action. A malformed OSPF Type 5 LSA triggers a regression. On a legacy monolithic NOS the entire control plane could panic. On AOS-CX the OSPF daemon crashes, the supervisor restarts it within seconds, the time-series store flags the event, an NAE agent emails the on-call engineer — and traffic keeps forwarding in hardware because the data plane was never affected.
REST API and Python on-box scripting
Interface
Best for
Typical user
CLI
Interactive troubleshooting, ad-hoc changes
Network engineer at a console
REST API
Bulk automation, ITSM/IaC integration
DevOps / NetOps automation
NAE (on-box Python)
Closed-loop monitoring and remediation
Network reliability engineer
Aruba Central
Multi-site fleet management, ZTP
NOC, managed-service provider
NAE overview
An NAE agent is a Python script that:
Subscribes to the time-series database for one or more metrics.
Evaluates a condition every sampling period (e.g., "error rate > 1% for 60 seconds").
When the condition fires, takes action — log, webhook, CLI command, or ticket.
Real-world analogy: NAE is the on-call doctor who lives inside the hospital instead of being paged from home. The data never leaves the building, the response is measured in seconds, and only true anomalies escalate to humans.
Key Takeaway: AOS-CX is built around a centralized OVSDB-style database plus a time-series telemetry store. Modular daemons read/write through the database; the REST API and NAE expose the same data programmatically; the entire CX portfolio runs the same image.
Post-Quiz: AOS-CX Architecture
1. Which statement best characterizes AOS-CX in one sentence?
It is CLI-driven; the database is a read-only export of show-command output.It is database-driven; the CLI, REST API, and NAE are different "lenses" on the same underlying data.It is a SNMP-driven NOS that copies data between CLI and management plane on demand.It is an asynchronous file-based NOS that writes configuration directly into kernel memory.
2. Which scenario illustrates the operational benefit of AOS-CX modular daemon isolation?
A bug in OSPF crashes the OSPF daemon; the supervisor restarts it while the data plane keeps forwarding traffic.A bug in OSPF reboots the entire chassis to ensure consistency.A bug in OSPF triggers an automatic vendor support call, halting all daemons.A bug in OSPF corrupts LACP and STP state because they share kernel memory.
3. What is the role of the AOS-CX time-series database, in addition to the configuration/state database?
It stores binary firmware images for ISSU rollback.It records timestamped samples of operational state, enabling NAE to detect trends like "error rate climbing for 30 minutes."It buffers SNMP traps before the management plane forwards them.It caches REST API responses so the CLI does not need to recompute them.
4. An NAE on-box agent is fundamentally a Python script that does which of the following?
Replaces the CLI by translating user commands into syscalls.Subscribes to time-series metrics, evaluates a condition, and triggers an action when that condition fires.Acts as a firewall between management VRF and default VRF.Compiles the running configuration into a binary image for ZTP.
Pre-Quiz: Certification Pathway
1. Which sequence describes the HPE Aruba switching certification ladder from entry to expert?
2. A network technician earns ACSA in year 1 and ACP-Switching in year 2. Under HPE's traditional recertification model, what happens to her ACSA credential?
It expires immediately because earning ACP supersedes ACSA.It is automatically extended because passing a higher-level exam in the same track renews the lower one.She must re-take ACSA every 12 months regardless of higher exams.It can only be renewed by passing a delta refresh exam.
3. Why does the ACSA blueprint include ClearPass topics under Security & ACLs even though ClearPass is part of a different track?
ClearPass is the only authentication system AOS-CX can use.RADIUS/802.1X with ClearPass is so common in enterprise switching that pure-switching engineers need basic ClearPass literacy.HPE bundles ClearPass licenses with every CX switch, requiring exam coverage.ClearPass and AOS-CX share the same OVSDB schema.
4. Roughly how often have HPE certifications historically required recertification?
Every 12 monthsEvery 2 yearsEvery 3 yearsLifetime — no recertification required
ClearPass appears in the ACSA blueprint under Security & ACLs (RADIUS / 802.1X with ClearPass).
Aruba Central is the unified cloud-management plane for all tracks.
AI Insights in Central is increasingly cross-track — campus, mobility, and security signals together.
Recertification policies
HPE certifications have historically followed a three-year recertification cycle. Retain a credential by:
Re-passing the same exam, or
Passing a higher-level exam in the same track (earning ACP-Switching automatically renews ACSA), or
Passing a delta/refresh exam if HPE publishes one.
Worked example — career trajectory. A network technician earns ACSA in year 1. In year 2 she leads a 6300/6400 deployment and earns ACP-Switching. ACP-Switching automatically extends her ACSA. By year 4 her exposure to multicast and VSX prepares her to attempt ACE-Switching — and she never has to "re-take" ACSA because each upward step renews it.
Key Takeaway: ACSA is the entry point of a four-tier ladder. Each level cumulatively assumes the one below, skills transfer across tracks via Aruba Central, and you can renew ACSA simply by climbing one rung higher within the recertification window.
Post-Quiz: Certification Pathway
1. Which sequence describes the HPE Aruba switching certification ladder from entry to expert?
2. A network technician earns ACSA in year 1 and ACP-Switching in year 2. Under HPE's traditional recertification model, what happens to her ACSA credential?
It expires immediately because earning ACP supersedes ACSA.It is automatically extended because passing a higher-level exam in the same track renews the lower one.She must re-take ACSA every 12 months regardless of higher exams.It can only be renewed by passing a delta refresh exam.
3. Why does the ACSA blueprint include ClearPass topics under Security & ACLs even though ClearPass is part of a different track?
ClearPass is the only authentication system AOS-CX can use.RADIUS/802.1X with ClearPass is so common in enterprise switching that pure-switching engineers need basic ClearPass literacy.HPE bundles ClearPass licenses with every CX switch, requiring exam coverage.ClearPass and AOS-CX share the same OVSDB schema.
4. Roughly how often have HPE certifications historically required recertification?
Every 12 monthsEvery 2 yearsEvery 3 yearsLifetime — no recertification required
Chapter Summary
This chapter framed the three things you need before opening Chapter 2: the exam, the hardware, and the operating system. The ACSA exam (HPE7-A01 / HPE6-A86) is a 60-question, 90-minute, ~66%-to-pass associate-level credential weighted 30/20/20/15/15 across Switching & VLANs, Routing & OSPF, Security & ACLs, Aruba Central, and Monitoring & API.
The Aruba CX hardware portfolio is intentionally tiered. The 6000/6100/6200 land in the wiring closet; the 6300/6400/8100/8325/8360 occupy aggregation and campus core; the 8400/9300/10000 anchor data-center cores, with the 10000 distinguished by integrated Pensando DPUs. VSF delivers campus stacking, while VSX provides active-active redundancy with non-disruptive upgrades. All platforms run the same AOS-CX image.
That operating system is database-driven from the ground up. An OVSDB-style central database plus a time-series telemetry store sit at the core; modular Linux daemons, the REST API, NAE Python agents, and Aruba Central are all "lenses" on that same data. Finally, ACSA is one rung on a four-tier ladder; passing it begins the ACSA → ACSP → ACSE journey, with skills that transfer across wireless and security tracks.