What Do Low-Impact Attacks in the Firepower Risk Report Indicate?
A network administrator reviews the attack risk report and notices several low-impact attacks. What does this type of attack indicate?
Community Votes
50% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests how Firepower derives an event's impact level — the trap is picking the vague 'attacks are not dangerous' wording instead of the host-vulnerability cause that FMC actually computes.
In Cisco Secure Firewall Management Center, an intrusion event's impact level is calculated from the rule's impact flag plus the target host's known vulnerability in the network map. This guide explains why several low-impact attacks in the attack risk report indicate the targeted hosts are not vulnerable to those attacks (B), not simply that the traffic is harmless.
Most candidates pick D because 'low impact' reads like 'not dangerous', but FMC's impact level is host-relative: it is downgraded when the network map shows the target lacks the vulnerable OS, service, or port the rule targets, which is exactly what option B states.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Secure Firewall Management Center does not judge an intrusion event in isolation: each event's impact level (0–4) is derived from the rule's impact flag combined with what the network map knows about the target host's operating system, open services, and vulnerabilities. When a signature fires but the discovered target is missing the vulnerable service or OS the rule expects, FMC downgrades the event to a low impact level instead of a high one. A cluster of low-impact attacks in the attack risk report is therefore FMC telling you that the targeted hosts are not vulnerable to those attacks (B), even though the signature matched. Option D reduces the finding to a generic threat opinion and ignores the host-relative mechanism FMC actually uses.Why the Other Options Are Wrong
A is wrong because there is no manual recategorization step: impact levels are computed automatically from the impact flag and the network map, not parked at 'low' until an administrator changes them. C is wrong because hosts outside the monitored environment surface as unknown impact rather than low impact — FMC needs a host record before it can downgrade or upgrade anything. D is wrong because 'the attacks are not dangerous to the network' is a vague restatement of the term low impact and never explains the cause; FMC's impact level is relative to a specific target host, so the precise reading is host vulnerability, not general network danger.Community Comment Notes
The community is split almost evenly here, which is exactly why the underlying mechanism decides the question. One voter chose B and pointed at Cisco's "Impact Levels" table in the FMC configuration guide, which ties impact to the target's vulnerability. Another commenter argued "since it doesn't specifically say anything about hosts" the answer is more likely D — but the impact level is inherently host-relative, so the absence of a named host in the stem is not evidence against B. A third reader simply agreed the scenario looks straightforward, and the takeaway is that the risk report's low-impact label is a vulnerability verdict, not a general danger verdict.Official Reference
Exam Strategy
For any Firepower impact or risk question, translate the wording into FMC's formula: rule impact flag plus target host vulnerability from the network map. Eliminate options that merely restate 'low' as 'not dangerous', and pick the option that names the host's vulnerability state.
Frequently Asked Questions
Why do low-impact attacks still show up in the Firepower attack risk report?
FMC logs every triggered intrusion rule, then downgrades the impact level when the network map shows the target host lacks the vulnerable OS, service, or port the rule targets.
Does a low impact level in FMC mean the attack is completely harmless?
No. It means FMC sees no vulnerable target for that signature; if discovery later reveals the host as vulnerable, the impact level can change.