QuestionQ15
AnalyzeA hospital has an AOS-10 architecture managed by HPE Aruba Networking Central. The customer has deployed a pair of HPE Aruba Networking 9000 Series gateways with Security licenses at each clinic. The gateways implement IDS/IPS in IDS mode.
The Security Dashboard shows several recent events with the same signature, as shown below:

Refer to the scenario.
You have learned that nurse call stations are the source of the events. What can you conclude?
- A These devices are unlikely to use TOR legitimately, but malware often does. You and the security team should investigate these stations.
- B This event is a common false positive for clients using video streaming, but you should still investigate it further to comply with best practices.
- C The nurses are making their devices vulnerable by contacting unsafe websites. You should educate them about safe browsing practices.
- D The threat destination has an internal IP address, and it is likely a DNS server. You should verify that this server is patched and uncompromised.
Community Discussion