QuestionQ15

Analyze

A hospital has an AOS-10 architecture managed by HPE Aruba Networking Central. The customer has deployed a pair of HPE Aruba Networking 9000 Series gateways with Security licenses at each clinic. The gateways implement IDS/IPS in IDS mode.

The Security Dashboard shows several recent events with the same signature, as shown below:

Question Image

Refer to the scenario.

You have learned that nurse call stations are the source of the events. What can you conclude?

  • A These devices are unlikely to use TOR legitimately, but malware often does. You and the security team should investigate these stations.
  • B This event is a common false positive for clients using video streaming, but you should still investigate it further to comply with best practices.
  • C The nurses are making their devices vulnerable by contacting unsafe websites. You should educate them about safe browsing practices.
  • D The threat destination has an internal IP address, and it is likely a DNS server. You should verify that this server is patched and uncompromised.
Explanation

Repeated DNS queries associated with Tor hidden services from nurse call stations are anomalous and warrant investigation, because those devices are not expected to require Tor while malware can use Tor communications to obscure activity. Aruba IDS monitors and alerts on identified malicious activity rather than taking action on the traffic.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!