nerdexam
HP

HPE7-A02 · Question #64

A company has HPE Aruba Networking gateways that implement gateway IDS/IPS. Admins sometimes check the Security Dashboard, but they want a faster way to discover if a gateway starts detecting…

The correct answer is C. Set up email notifications using HPE Aruba Networking Central's global alert settings. HPE Aruba Networking Central's global alert settings support email notifications triggered by security events, including when gateway IDS/IPS detects threats - making C the right fit for "faster discovery" without requiring admins to manually check dashboards. Why the…

Troubleshooting and Monitoring Network Security

Question

A company has HPE Aruba Networking gateways that implement gateway IDS/IPS. Admins sometimes check the Security Dashboard, but they want a faster way to discover if a gateway starts detecting threats in traffic. What should they do?

Options

  • ASet up Webhooks that are attached to the HPE Aruba Networking Central Threat Dashboard.
  • BUse Syslog to integrate the gateways with HPE Aruba Networking ClearPass Policy Manager
  • CSet up email notifications using HPE Aruba Networking Central's global alert settings.
  • DIntegrate HPE Aruba Networking ClearPass Device Insight (CPDI) with Central and schedule

How the community answered

(45 responses)
  • B
    2% (1)
  • C
    96% (43)
  • D
    2% (1)

Explanation

HPE Aruba Networking Central's global alert settings support email notifications triggered by security events, including when gateway IDS/IPS detects threats - making C the right fit for "faster discovery" without requiring admins to manually check dashboards.

Why the distractors are wrong:

  • A (Webhooks on the Threat Dashboard): Central's Threat Dashboard does not support webhook attachments as an alerting mechanism; webhooks in Central are used for other integrations, not dashboard-level threat triggers.
  • B (Syslog to ClearPass Policy Manager): Syslog integration with CPPM is used for policy enforcement and authentication context, not for generating proactive threat alerts to admins.
  • D (ClearPass Device Insight integration + schedule): CPDI focuses on device profiling and visibility, not on IDS/IPS threat alerting; scheduling a report still requires manual review rather than immediate notification.

Memory tip: Think "faster = automatic push notification." Email alerts push information to admins the moment a threat is detected, whereas dashboards, syslog forwarding to CPPM, and CPDI reports all require someone to pull or check - Central's global alert settings are the only option here that proactively notifies.

Topics

#IDS/IPS#threat alerts#Aruba Central#email notifications

Community Discussion

No community discussion yet for this question.

Full HPE7-A02 Practice