nerdexam
HP

HPE7-A02 · Question #115

HPE Aruba Networking Central displays a Gateway Threat Count alert in the alert list. How can you gather more information about what caused the alert to trigger?

The correct answer is C. Check the threat list for the gateway associated with the alert. Access threat details and download. Option C is correct because when a Gateway Threat Count alert fires, the natural investigative path is to examine the threat list directly associated with that gateway. HPE Aruba Networking Central's Security dashboard lets you drill into individual threats, view details such…

Troubleshooting and Monitoring Network Security

Question

HPE Aruba Networking Central displays a Gateway Threat Count alert in the alert list. How can you gather more information about what caused the alert to trigger?

Options

  • AUse HPE Aruba Networking Central tools to run a Network Check on the gateway with which the
  • BUse Live Monitoring on the gateway to download a packet capture of recent traffic flowing through
  • CCheck the threat list for the gateway associated with the alert. Access threat details and download
  • DCheck the gateway's Audit Trail in HPE Aruba Networking Central for more details about the

How the community answered

(50 responses)
  • A
    10% (5)
  • B
    4% (2)
  • C
    84% (42)
  • D
    2% (1)

Explanation

Option C is correct because when a Gateway Threat Count alert fires, the natural investigative path is to examine the threat list directly associated with that gateway. HPE Aruba Networking Central's Security dashboard lets you drill into individual threats, view details such as threat type, source/destination, and severity, and download a threat report - giving you the exact context needed to understand what triggered the alert.

Why the distractors are wrong:

  • A - Network Check is a connectivity/health diagnostic tool, not a security investigation tool; it won't surface threat details.
  • B - Live Monitoring packet captures show current traffic, but a past alert requires historical threat data, not a real-time capture.
  • D - The Audit Trail logs administrative actions (config changes, user logins), not security threat events; it tells you what admins did, not what threats occurred.

Memory tip: Match the tool to the data type - threats live in the threat list, admin actions live in the audit trail, and connectivity issues live in network checks. When the alert says "threat," go to the threat list.

Topics

#gateway threat detection#Aruba Central alerts#threat forensics#security investigation

Community Discussion

No community discussion yet for this question.

Full HPE7-A02 Practice