nerdexam
HP

HPE7-A02 · Question #114

A company has AOS-CX switches at the access layer, managed by HPE Aruba Networking Central. You have identified suspicious activity on a wired client. You want to analyze the client's traffic with…

The correct answer is D. Set up a mirror session on the client's switch; set the client port as the source and your station IP. Option D correctly describes a remote traffic mirroring session, which is the standard, purpose-built mechanism for this use case. AOS-CX switches support mirror sessions where you define a source port (the client's switch port) and a remote destination IP (your management…

Troubleshooting and Monitoring Network Security

Question

A company has AOS-CX switches at the access layer, managed by HPE Aruba Networking Central. You have identified suspicious activity on a wired client. You want to analyze the client's traffic with Wireshark, which you have on your management station. What should you do?

Options

  • AAccess the client's switch's CLI from your management station. Access the switch shell and run a
  • BGo to the client's switch in HPE Aruba Networking Central. Use the "Security" page to run a packet
  • CSet up a policy that implements a captive portal redirect to your management station. Apply that
  • DSet up a mirror session on the client's switch; set the client port as the source and your station IP

How the community answered

(49 responses)
  • A
    4% (2)
  • B
    16% (8)
  • C
    8% (4)
  • D
    71% (35)

Explanation

Option D correctly describes a remote traffic mirroring session, which is the standard, purpose-built mechanism for this use case. AOS-CX switches support mirror sessions where you define a source port (the client's switch port) and a remote destination IP (your management station). The switch encapsulates and forwards a copy of all the client's traffic to your station, where Wireshark captures it passively - no interruption to the client's connectivity.

Why the distractors fail:

  • A is cut off in the question, but the approach of using the switch shell for packet capture doesn't deliver traffic to your Wireshark instance in a usable way - it's an indirect, unsupported workflow on AOS-CX.
  • B is a fabricated feature; HPE Aruba Central has no "Security" page that runs a remote packet capture and streams it to your local Wireshark. Central's diagnostic tools don't work that way.
  • C describes a captive portal, which is an authentication/redirect mechanism for onboarding users - it has nothing to do with copying traffic for analysis and would disrupt the client rather than silently observe them.

Memory tip: Think of it as holding up a mirror to the port - the client sees no change, but you get a perfect reflection of everything passing through. Whenever the exam asks about capturing wired traffic with Wireshark, the answer is always a mirror/SPAN session with your station as the destination.

Topics

#packet capture#mirror session#Wireshark#traffic analysis

Community Discussion

No community discussion yet for this question.

Full HPE7-A02 Practice