HPE7-A02 · Question #86
You have enabled "rogue AP containment" in the Wireless IPS settings for a company's HPE Aruba Networking APs. What form of containment does HPE Aruba Networking recommend?
The correct answer is A. Wireless deauthentication only. HPE Aruba Networking recommends wireless deauthentication only because it is the safest and most targeted containment method - it sends 802.11 deauthentication frames over the air to disconnect clients from the rogue AP without risking disruption to the legitimate wired…
Question
You have enabled "rogue AP containment" in the Wireless IPS settings for a company's HPE Aruba Networking APs. What form of containment does HPE Aruba Networking recommend?
Options
- AWireless deauthentication only
- BWireless tarpit and wired containment
- CWireless tarpit only
- DWired containment
How the community answered
(30 responses)- A87% (26)
- B7% (2)
- C3% (1)
- D3% (1)
Explanation
HPE Aruba Networking recommends wireless deauthentication only because it is the safest and most targeted containment method - it sends 802.11 deauthentication frames over the air to disconnect clients from the rogue AP without risking disruption to the legitimate wired infrastructure. Wired containment (D) is discouraged as the primary method because automatically shutting down switch ports can accidentally take down legitimate devices sharing the same segment, causing unintended outages. Wireless tarpit (C) and tarpit + wired containment (B) are more aggressive techniques that can interfere with nearby legitimate clients or cause broader network impact, making them higher-risk choices that Aruba does not recommend as the default. The "wireless deauthentication only" approach keeps containment entirely in the RF domain, minimizing collateral damage.
Memory tip: Think "air only, don't touch the wire" - Aruba keeps rogue AP containment wireless (deauth frames) to avoid the risk of accidentally disrupting legitimate wired infrastructure.
Topics
Community Discussion
No community discussion yet for this question.