HPE7-A02 · Question #130
HPE Aruba Networking Central displays an alert about an Infrastructure Attack that was detected. You go to the Security > RAPIDS events and see that the attack was "Detect adhoc using Valid SSID."…
The correct answer is C. Use HPE Aruba Networking Central floorplans or the detecting AP identities to locate the general. When RAPIDS flags "Detect adhoc using Valid SSID," it means a device is broadcasting a peer-to-peer ad-hoc network mimicking your legitimate SSID - a classic rogue network setup. Option C is correct because the immediate, actionable response is physical location: HPE Aruba…
Question
HPE Aruba Networking Central displays an alert about an Infrastructure Attack that was detected. You go to the Security > RAPIDS events and see that the attack was "Detect adhoc using Valid SSID." What is one possible next step?
Options
- AMake sure that you have tuned the threshold for that check as false positives are common for it.
- BMake sure that clients have updated drivers, as faulty drivers are a common explanation for this
- CUse HPE Aruba Networking Central floorplans or the detecting AP identities to locate the general
- DLook for the IP address associated with the offender and then check for that IP address among
How the community answered
(29 responses)- A7% (2)
- B3% (1)
- C83% (24)
- D7% (2)
Explanation
When RAPIDS flags "Detect adhoc using Valid SSID," it means a device is broadcasting a peer-to-peer ad-hoc network mimicking your legitimate SSID - a classic rogue network setup. Option C is correct because the immediate, actionable response is physical location: HPE Aruba Central's floorplans combined with the list of APs that detected the signal let you triangulate where the offending device is so you can investigate or remove it.
A is wrong because this is not a known high-false-positive check - an ad-hoc device using your exact SSID is a genuine security concern that warrants investigation, not threshold tuning. B is wrong because client driver issues don't cause a separate device to broadcast an ad-hoc network; drivers affect how clients behave, not how rogue devices appear. D is wrong because an ad-hoc rogue device likely has no IP on your managed network, making an IP-based search unreliable and indirect compared to RF-based location.
Memory tip: Think "detect → locate → eliminate." RAPIDS detects the threat; your next move is always to locate it physically using the detecting AP identities and floorplans before you can eliminate it.
Topics
Community Discussion
No community discussion yet for this question.