700-270 · Question #4
When deploying the Cisco ASA with FirePOWER services module, which two functions are performed by the Cisco ASA? (Choose two.)
The correct answer is B. NAT C. TCP intercept. In the ASA + FirePOWER architecture, the ASA handles traditional network-layer functions while the FirePOWER module handles advanced threat and application intelligence. NAT (B) is a core ASA function - it translates addresses before or after traffic is inspected. TCP intercept (
Question
When deploying the Cisco ASA with FirePOWER services module, which two functions are performed by the Cisco ASA? (Choose two.)
Options
- Afile disposition checks
- BNAT
- CTCP intercept
- Dfile capturing
- Eapplication visibility and control
How the community answered
(51 responses)- A4% (2)
- B90% (46)
- D2% (1)
- E4% (2)
Explanation
In the ASA + FirePOWER architecture, the ASA handles traditional network-layer functions while the FirePOWER module handles advanced threat and application intelligence. NAT (B) is a core ASA function - it translates addresses before or after traffic is inspected. TCP intercept (C) is also native to the ASA, protecting servers from SYN flood attacks by proxying the TCP handshake.
Why the distractors are wrong:
- A (file disposition checks) and D (file capturing) are performed by the FirePOWER module leveraging Cisco AMP (Advanced Malware Protection), not the ASA itself.
- E (application visibility and control / AVC) is also a FirePOWER capability - the ASA has no deep packet inspection engine to classify applications at Layer 7.
Memory tip: Think of the ASA as the "network plumber" (NAT, TCP, VPN, ACLs) and FirePOWER as the "security analyst" (apps, files, threats). If the feature requires looking inside traffic to understand content or behavior, it belongs to FirePOWER - not the ASA.
Topics
Community Discussion
No community discussion yet for this question.