nerdexam
Cisco

300-710 · Question #298

A network administrator reviews the attack risk report and notices several low-impact attacks. What does this type of attack indicate?

The correct answer is B. The host is not vulnerable to those attacks.. A low-impact attack in a risk report indicates that the targeted host is not vulnerable to the specific attack, meaning the attack attempt was unsuccessful or benign.

Management and Troubleshooting

Question

A network administrator reviews the attack risk report and notices several low-impact attacks. What does this type of attack indicate?

Options

  • AAll attacks are listed as low until manually recategorized.
  • BThe host is not vulnerable to those attacks.
  • CThe host is not within the administrator's environment.
  • DThe attacks are not dangerous to the network.

How the community answered

(68 responses)
  • A
    1% (1)
  • B
    90% (61)
  • C
    3% (2)
  • D
    6% (4)

Why each option

A low-impact attack in a risk report indicates that the targeted host is not vulnerable to the specific attack, meaning the attack attempt was unsuccessful or benign.

AAll attacks are listed as low until manually recategorized.

Attack categorizations are usually based on predefined rules, vulnerability assessments, and contextual information, not defaulting to low until manual recategorization.

BThe host is not vulnerable to those attacks.Correct

When an attack is classified as low-impact, it typically signifies that the security posture of the host, such as patching or configuration, prevented the attack from successfully exploiting a vulnerability, or the attack itself was not relevant to that host.

CThe host is not within the administrator's environment.

The physical location or administrative scope of a host does not directly determine the impact classification of an attack against it.

DThe attacks are not dangerous to the network.

While 'low-impact' suggests less danger, the specific technical reason for this classification is that the host is not susceptible to the particular attack detected.

Concept tested: Interpreting attack risk reports

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/intrusion_policies_and_rules.html

Topics

#Attack reporting#Vulnerability status#Security risk interpretation

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice