HPE7-A02 · Question #65
A company has Aruba APs that are controlled by Central and that implement WIDS. When you check WIDS events, you see a "detect valid SSID misuse" event. What can you interpret from this event, and…
The correct answer is C. Hackers are likely trying to pose as authorized APs. You should use the detecting radio. A "detect valid SSID misuse" event means WIDS has spotted an AP broadcasting one of your company's legitimate SSIDs but that AP is not in your authorized AP list - a classic evil twin / rogue AP attack. Hackers do this to lure employees into connecting to their malicious AP…
Question
A company has Aruba APs that are controlled by Central and that implement WIDS. When you check WIDS events, you see a "detect valid SSID misuse" event. What can you interpret from this event, and what steps should you take?
Options
- AClients are failing to authenticate to corporate SSIDs. You should first check for misconfigured
- BAdmins have likely misconfigured SSID security settings on some of the company's APs. You
- CHackers are likely trying to pose as authorized APs. You should use the detecting radio
- DThis event might be a threat but is almost always a false positive. You should wait to see the event
How the community answered
(47 responses)- A2% (1)
- B13% (6)
- C81% (38)
- D4% (2)
Explanation
A "detect valid SSID misuse" event means WIDS has spotted an AP broadcasting one of your company's legitimate SSIDs but that AP is not in your authorized AP list - a classic evil twin / rogue AP attack. Hackers do this to lure employees into connecting to their malicious AP instead of a real corporate one, enabling credential theft or man-in-the-middle interception. The correct response is to use the detecting radio (the Aruba AP that flagged the event) to physically locate the rogue device and take it offline.
Why the distractors are wrong:
- A - Authentication failures produce auth-failure events, not SSID misuse events; this option confuses the symptom.
- B - A misconfigured company AP would still appear in your authorized AP list; SSID misuse events are triggered by external/unknown radios using your SSID.
- D - Unlike some WIDS events that are noisy/false-positive-prone, "valid SSID misuse" is a precise match against your known SSID list and warrants immediate investigation, not passive waiting.
Memory tip: Break down the event name - "valid SSID" means someone is using your real SSID, and "misuse" means an unauthorized party is doing it. Anytime something valid is being misused, think impersonation attack → rogue AP → locate and contain.
Topics
Community Discussion
No community discussion yet for this question.