nerdexam
HP

HPE7-A08 · Question #107

In a WLAN network with a tunneled SSID, you see the following events in HPE Aruba Networking Central: The customer asks you to investigate log messages. What should you tell them?

The correct answer is D. This is normal, expected behavior. No further actions are needed. Option D is correct because in a tunneled SSID deployment (where client traffic is encapsulated and forwarded through a GRE tunnel to a gateway), the log messages visible in Aruba Central are a normal artifact of the tunneling process itself - events like station…

Manage and Monitor HPE Aruba Networking CX Switches

Question

In a WLAN network with a tunneled SSID, you see the following events in HPE Aruba Networking Central:

The customer asks you to investigate log messages. What should you tell them?

Exhibit

HPE7-A08 question #107 exhibit

Options

  • AThis indicates a security issue. The client with a MAC address ending with 37:18:0d is performing
  • BThere is a roaming issue. Enable Fast Roaming 802.11r and OKC to resolve the issue
  • CThis indicates a client WLAN driver issue for the client with a MAC address ending with 37:18:0d.
  • DThis is normal, expected behavior. No further actions are needed

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    13% (3)
  • C
    4% (1)
  • D
    78% (18)

Explanation

Option D is correct because in a tunneled SSID deployment (where client traffic is encapsulated and forwarded through a GRE tunnel to a gateway), the log messages visible in Aruba Central are a normal artifact of the tunneling process itself - events like station deletion/re-addition, deauthentication, or re-association are expected as the tunnel is established and maintained.

Option A is wrong because the log events are not indicators of a malicious activity; they are infrastructure-driven events tied to how tunnel mode handles client sessions, not client-initiated attacks. Option B is wrong because the logs do not reflect a roaming failure - 802.11r/OKC addresses fast BSS transitions, which is a separate concern unrelated to tunneled SSID session events. Option C is wrong because the behavior is driven by the AP/gateway interaction in tunnel mode, not by a defect in the specific client's wireless driver.

Memory tip: Associate "Tunneled SSID = traffic engineering overhead" - the tunnel creates extra control-plane chatter (deauths, re-associations, station state changes) that looks alarming but is by design. On the exam, if a question pairs "tunneled SSID" with "unusual log messages," your first instinct should be: is this just the tunnel doing its job?

Topics

#WLAN logs#tunneled SSID#Central monitoring#roaming events

Community Discussion

No community discussion yet for this question.

Full HPE7-A08 Practice