350-701 · Question #87
Which option is the main function of Cisco Firepower impact flags?
The correct answer is C. They correlate data about intrusions and vulnerability. Cisco Firepower impact flags are a core feature designed to correlate intrusion events with known vulnerabilities on specific assets, providing a prioritized view of threats. This correlation helps administrators focus on the most critical security incidents that pose an actual…
Question
Which option is the main function of Cisco Firepower impact flags?
Options
- AThey alert administrators when critical events occur.
- BThey highlight known and suspected malicious IP addresses in reports.
- CThey correlate data about intrusions and vulnerability.
- DThey identify data that the ASA sends to the Firepower module.
How the community answered
(18 responses)- A6% (1)
- B6% (1)
- C89% (16)
Why each option
Cisco Firepower impact flags are a core feature designed to correlate intrusion events with known vulnerabilities on specific assets, providing a prioritized view of threats. This correlation helps administrators focus on the most critical security incidents that pose an actual risk to their network.
While impact flags contribute to understanding critical events, their main function is correlation and prioritization, not just generating alerts.
Highlighting malicious IP addresses is a function of threat intelligence and reputation services, not the primary function of impact flags, which specifically deal with intrusion/vulnerability correlation.
Cisco Firepower impact flags serve the main function of correlating intrusion events with discovered vulnerabilities on network assets. By matching intrusion attempts to specific vulnerabilities present on the target, they help prioritize security events and provide context on which attacks are most likely to succeed and cause actual impact.
Impact flags do not identify data sent from the ASA to the Firepower module; they are an analysis feature within the Firepower management center for threat intelligence.
Concept tested: Cisco Firepower impact flags functionality
Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/intrusion_events_and_rule_management.html
Topics
Community Discussion
No community discussion yet for this question.