The active intrusion policies will depend on traffic and host information collected and analysed by the FTD device. Also, the Firepower recommendations are not automatically taken into use, you need to run the recommendations again and confirm the usage of the recommendations. So, if there are new policies added in an update, and you run the Firepower recommendations, any newly added or disabled rules will depend on collected and analysed host and traffic information. So you might have more more active policies than you did before, but it could also be possible that you will have fewer active policies if there have been significant changes to the hosts in the network.
--
Please remember to select a correct answer and rate helpful posts