PrepAway - Latest Free Exam Questions & Answers

Which statement about the Cisco ASA 5585-X appliance is…

Which statement about the Cisco ASA 5585-X appliance is true?

PrepAway - Latest Free Exam Questions & Answers

A.
The IPS SSP must be installed in slot 0 (bottom slot) and the firewall/VPN SSP must be installed in slot 1 (top slot).

B.
The IPS SSP operates independently. The firewall/VPN SSP is not necessary to support the IPS SSP.

C.
The ASA 5585-X appliance supports three types of SSP (the firewall/VPN SSP, the IPS SSP, and the CSC SSP).

D.
The ASA 5585-X appliance with the firewall/VPN SSP-60 has a maximum firewall throughput of 10 Gb/s.

E.
All IPS traffic (except the IPS management interface traffic) must flow through the firewall/VPN SSP first before it can be redirected to the IPS SSP.

Explanation:
http://www.cisco.com/en/US/docs/security/asa/quick_start/ips/ips_qsg.pdf
The IPS module runs a separate application from the ASA. The IPS module might include an external management interface so you can connect to the IPS module
directly; if it does not have a management interface, you can connect to the IPS module through the ASA interface. Any other interfaces on the IPS module, if
available for your model, are used for ASA traffic only. Traffic goes through the firewall checks before being forwarded to the IPS module.


Leave a Reply