HPE7-A02 · Question #115
HPE Aruba Networking Central displays a Gateway Threat Count alert in the alert list. How can you gather more information about what caused the alert to trigger?
The correct answer is C. Check the threat list for the gateway associated with the alert. Access threat details and download. Option C is correct because when a Gateway Threat Count alert fires, the natural investigative path is to examine the threat list directly associated with that gateway. HPE Aruba Networking Central's Security dashboard lets you drill into individual threats, view details such…
Question
HPE Aruba Networking Central displays a Gateway Threat Count alert in the alert list. How can you gather more information about what caused the alert to trigger?
Options
- AUse HPE Aruba Networking Central tools to run a Network Check on the gateway with which the
- BUse Live Monitoring on the gateway to download a packet capture of recent traffic flowing through
- CCheck the threat list for the gateway associated with the alert. Access threat details and download
- DCheck the gateway's Audit Trail in HPE Aruba Networking Central for more details about the
How the community answered
(50 responses)- A10% (5)
- B4% (2)
- C84% (42)
- D2% (1)
Explanation
Option C is correct because when a Gateway Threat Count alert fires, the natural investigative path is to examine the threat list directly associated with that gateway. HPE Aruba Networking Central's Security dashboard lets you drill into individual threats, view details such as threat type, source/destination, and severity, and download a threat report - giving you the exact context needed to understand what triggered the alert.
Why the distractors are wrong:
- A - Network Check is a connectivity/health diagnostic tool, not a security investigation tool; it won't surface threat details.
- B - Live Monitoring packet captures show current traffic, but a past alert requires historical threat data, not a real-time capture.
- D - The Audit Trail logs administrative actions (config changes, user logins), not security threat events; it tells you what admins did, not what threats occurred.
Memory tip: Match the tool to the data type - threats live in the threat list, admin actions live in the audit trail, and connectivity issues live in network checks. When the alert says "threat," go to the threat list.
Topics
Community Discussion
No community discussion yet for this question.