HPE7-A02 · Question #81
A company has HPE Aruba Networking APs running AOS-10 and managed by HPE Aruba Networking Central. The company also has AOS-CX switches. The security team wants you to capture traffic from a…
The correct answer is B. Go to the client's AP in HPE Aruba Networking Central. Use the "Security" page to run a packet. Option B is correct because HPE Aruba Networking Central provides a built-in packet capture tool accessible from the AP's Security page, which lets you specify a target client, set a capture duration, and download the result as a PCAP file - exactly what the scenario requires…
Question
A company has HPE Aruba Networking APs running AOS-10 and managed by HPE Aruba Networking Central. The company also has AOS-CX switches. The security team wants you to capture traffic from a particular wireless client. You should capture this client's traffic over a 15- minute time period and then send the traffic to them in a PCAP file. What should you do?
Options
- AAccess the CLI for the client's AP. Set up a mirroring session between its radio and a management
- BGo to the client's AP in HPE Aruba Networking Central. Use the "Security" page to run a packet
- CGo to that client in HPE Aruba Networking Central. Use the "Live Events" page to run a packet
- DAccess the CLI for the client's AP's switch. Set up a mirroring session between the AP's port and a
How the community answered
(34 responses)- A15% (5)
- B76% (26)
- C6% (2)
- D3% (1)
Explanation
Option B is correct because HPE Aruba Networking Central provides a built-in packet capture tool accessible from the AP's Security page, which lets you specify a target client, set a capture duration, and download the result as a PCAP file - exactly what the scenario requires without any additional infrastructure.
Why the distractors fail:
- A is wrong because AOS-10 APs are cloud-managed thin/micro-APs; configuring a CLI mirroring session on the AP itself is not the intended workflow, and it wouldn't natively produce a downloadable PCAP.
- C is wrong because the client's Live Events page shows connection events and logs, not raw packet captures - it's a diagnostic timeline, not a traffic capture tool.
- D is wrong because setting up a mirror session on the AOS-CX switch captures traffic at the wired uplink level, requires a separate monitoring destination (another port or system), and does not natively output a PCAP file to hand to the security team.
Memory tip: Associate the word "Security" with "packet capture" - in Central, the AP's Security page is your go-to for capturing and exporting client traffic, because security investigations are exactly what that feature was built for.
Topics
Community Discussion
No community discussion yet for this question.