HPE7-A02 · Question #114
A company has AOS-CX switches at the access layer, managed by HPE Aruba Networking Central. You have identified suspicious activity on a wired client. You want to analyze the client's traffic with…
The correct answer is D. Set up a mirror session on the client's switch; set the client port as the source and your station IP. Option D correctly describes a remote traffic mirroring session, which is the standard, purpose-built mechanism for this use case. AOS-CX switches support mirror sessions where you define a source port (the client's switch port) and a remote destination IP (your management…
Question
A company has AOS-CX switches at the access layer, managed by HPE Aruba Networking Central. You have identified suspicious activity on a wired client. You want to analyze the client's traffic with Wireshark, which you have on your management station. What should you do?
Options
- AAccess the client's switch's CLI from your management station. Access the switch shell and run a
- BGo to the client's switch in HPE Aruba Networking Central. Use the "Security" page to run a packet
- CSet up a policy that implements a captive portal redirect to your management station. Apply that
- DSet up a mirror session on the client's switch; set the client port as the source and your station IP
How the community answered
(49 responses)- A4% (2)
- B16% (8)
- C8% (4)
- D71% (35)
Explanation
Option D correctly describes a remote traffic mirroring session, which is the standard, purpose-built mechanism for this use case. AOS-CX switches support mirror sessions where you define a source port (the client's switch port) and a remote destination IP (your management station). The switch encapsulates and forwards a copy of all the client's traffic to your station, where Wireshark captures it passively - no interruption to the client's connectivity.
Why the distractors fail:
- A is cut off in the question, but the approach of using the switch shell for packet capture doesn't deliver traffic to your Wireshark instance in a usable way - it's an indirect, unsupported workflow on AOS-CX.
- B is a fabricated feature; HPE Aruba Central has no "Security" page that runs a remote packet capture and streams it to your local Wireshark. Central's diagnostic tools don't work that way.
- C describes a captive portal, which is an authentication/redirect mechanism for onboarding users - it has nothing to do with copying traffic for analysis and would disrupt the client rather than silently observe them.
Memory tip: Think of it as holding up a mirror to the port - the client sees no change, but you get a perfect reflection of everything passing through. Whenever the exam asks about capturing wired traffic with Wireshark, the answer is always a mirror/SPAN session with your station as the destination.
Topics
Community Discussion
No community discussion yet for this question.