nerdexam
HP

HPE6-A78 · Question #73

Your HPE Aruba Networking Mobility Master-based solution has detected a rogue AP. Among other information, the AOS Detected Radios page lists this information for the AP: SSID = PublicWiFi BSSID =…

The correct answer is B. The AP is probably connected to your LAN because it has a BSSID that is close to a MAC address. HPE Aruba Networking's Wireless Intrusion Prevention (WIP) system, part of the AOS-8 architecture (Mobility Master and Mobility Controllers), is designed to detect and classify rogue APs. The "AOS Detected Radios" page provides details about detected APs, including their SSID…

Monitoring and Troubleshooting Aruba Network Security

Question

Your HPE Aruba Networking Mobility Master-based solution has detected a rogue AP. Among other information, the AOS Detected Radios page lists this information for the AP:

SSID = PublicWiFi BSSID = a8:bd:27:12:34:56 Match method = Plus one Match method = Eth-Wired-Mac-Table The security team asks you to explain why this AP is classified as a rogue. What should you explain?

Options

  • AThe AP has been detected using multiple MAC addresses. This indicates that the AP is spoofing
  • BThe AP is probably connected to your LAN because it has a BSSID that is close to a MAC address
  • CThe AP is an AP that belongs to your solution. However, the AOS has detected that it is behaving
  • DThe AP has a BSSID that is close to your authorized APs' BSSIDs. This indicates that the AP

How the community answered

(35 responses)
  • A
    14% (5)
  • B
    49% (17)
  • C
    29% (10)
  • D
    9% (3)

Explanation

HPE Aruba Networking's Wireless Intrusion Prevention (WIP) system, part of the AOS-8 architecture (Mobility Master and Mobility Controllers), is designed to detect and classify rogue APs. The "AOS Detected Radios" page provides details about detected APs, including their SSID, BSSID, and match methods used to classify them. In this case, the AP is classified as a rogue with the following match methods: Plus one: This indicates that the BSSID of the detected AP is numerically close (e.g., differs by one in the last octet) to the MAC address of a known device in the network. Eth-Wired-Mac- Table: This indicates that the AP's MAC address (or a closely related MAC address) was found in the wired network's MAC address table, suggesting that the AP is connected to the LAN. These match methods suggest that the AP is likely connected to the company's wired LAN (via the Eth-Wired-Mac-Table match) and has a BSSID that is close to a known device's MAC address (Plus one match). Since this AP is not part of the company's authorized AP list (it's broadcasting "PublicWiFi," which may not be a corporate SSID), it is classified as a suspected rogue. This scenario is common when an unauthorized AP is plugged into the corporate LAN, posing a security risk.

Topics

#rogue AP detection#Plus One method#wired MAC table#BSSID analysis

Community Discussion

No community discussion yet for this question.

Full HPE6-A78 Practice