300-710 · Question #298
A network administrator reviews the attack risk report and notices several low-impact attacks. What does this type of attack indicate?
The correct answer is B. The host is not vulnerable to those attacks.. A low-impact attack in a risk report indicates that the targeted host is not vulnerable to the specific attack, meaning the attack attempt was unsuccessful or benign.
Question
A network administrator reviews the attack risk report and notices several low-impact attacks. What does this type of attack indicate?
Options
- AAll attacks are listed as low until manually recategorized.
- BThe host is not vulnerable to those attacks.
- CThe host is not within the administrator's environment.
- DThe attacks are not dangerous to the network.
How the community answered
(68 responses)- A1% (1)
- B90% (61)
- C3% (2)
- D6% (4)
Why each option
A low-impact attack in a risk report indicates that the targeted host is not vulnerable to the specific attack, meaning the attack attempt was unsuccessful or benign.
Attack categorizations are usually based on predefined rules, vulnerability assessments, and contextual information, not defaulting to low until manual recategorization.
When an attack is classified as low-impact, it typically signifies that the security posture of the host, such as patching or configuration, prevented the attack from successfully exploiting a vulnerability, or the attack itself was not relevant to that host.
The physical location or administrative scope of a host does not directly determine the impact classification of an attack against it.
While 'low-impact' suggests less danger, the specific technical reason for this classification is that the host is not susceptible to the particular attack detected.
Concept tested: Interpreting attack risk reports
Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/intrusion_policies_and_rules.html
Topics
Community Discussion
No community discussion yet for this question.