nerdexam
HP

HPE6-A78 · Question #146

You have detected a Rogue AP using the Security Dashboard. Which two actions should you take in responding to this event? (Select two)

The correct answer is C. You should receive permission before containing an AP, as this action could have legal D. For forensic purposes, you should copy out logs with relevant information, such as the time mat. When responding to the detection of a Rogue AP, it's important to consider legal implications and to gather forensic evidence: You should receive permission before containing an AP (Option C), as containing it could disrupt service and may have legal implications, especially if…

Protect and Defend

Question

You have detected a Rogue AP using the Security Dashboard. Which two actions should you take in responding to this event? (Select two)

Options

  • AThere is no need to locale the AP If you manually contain it.
  • BThis is a serious security event, so you should always contain the AP immediately regardless of
  • CYou should receive permission before containing an AP, as this action could have legal
  • DFor forensic purposes, you should copy out logs with relevant information, such as the time mat
  • EThere is no need to locate the AP If the Aruba solution is properly configured to automatically

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    8% (2)
  • C
    76% (19)
  • E
    12% (3)

Explanation

When responding to the detection of a Rogue AP, it's important to consider legal implications and to gather forensic evidence: You should receive permission before containing an AP (Option C), as containing it could disrupt service and may have legal implications, especially if the AP is on a network that the organization For forensic purposes, it is essential to document the event by copying out logs with relevant information, such as the time the AP was detected and the AP's MAC address (Option D). This information could be crucial if legal action is taken or if a detailed analysis of the security breach Automatically containing an AP without consideration for the context (Options A and E) can be problematic, as it might inadvertently interfere with neighboring networks and cause legal issues. Immediate containment without consideration of company policy (Option B) could also violate established incident response procedures.

Topics

#rogue AP#containment#incident response#forensic logging

Community Discussion

No community discussion yet for this question.

Full HPE6-A78 Practice