HPE7-A02 · Question #12
Admins have recently turned on Wireless IDS/IPS infrastructure detection at the high level on HPE Aruba Networking APs. When you check WIDS events, you see several RTS rate and CTS rate anomalies…
The correct answer is B. These neighboring APs might be hackers trying to launch a DoS, but are more likely operating. When Wireless IDS/IPS infrastructure detection reports RTS (Request to Send) and CTS (Clear to Send) rate anomalies triggered by neighboring APs, it is often an indication of unusual, but not necessarily malicious, behavior. These anomalies can be caused by neighboring APs…
Question
Admins have recently turned on Wireless IDS/IPS infrastructure detection at the high level on HPE Aruba Networking APs. When you check WIDS events, you see several RTS rate and CTS rate anomalies, which were triggered by neighboring APs. What can you interpret from this event?
Options
- AThese neighboring APs are likely to be wireless clients that are inappropriately bridging their wired
- BThese neighboring APs might be hackers trying to launch a DoS, but are more likely operating
- CThese neighboring APs are actually rogue APs, and you should enable wireless tarpit containment
- DThese neighboring APs are actually rogue APs, and you should enable wireless de-authentication
How the community answered
(27 responses)- A26% (7)
- B56% (15)
- C15% (4)
- D4% (1)
Explanation
When Wireless IDS/IPS infrastructure detection reports RTS (Request to Send) and CTS (Clear to Send) rate anomalies triggered by neighboring APs, it is often an indication of unusual, but not necessarily malicious, behavior. These anomalies can be caused by neighboring APs operating normally but under specific conditions that trigger the alerts. Before assuming a security threat, it is recommended to tune the event thresholds to better match the environment and reduce false positives. This approach helps to distinguish between normal operations and potential DoS
Topics
Community Discussion
No community discussion yet for this question.