700-270 · Question #60
How is traffic forwarded from the Cisco ASA to the FirePOWER services module for analysis?
The correct answer is B. A service policy redirects traffic from the Cisco ASA packet-processing path to the SFR. Option B is correct because the Cisco ASA FirePOWER Services Module (SFR) is an internal module that sits inside the ASA chassis - traffic does not reach it automatically. Instead, you use Cisco's Modular Policy Framework (MPF) to configure a service policy that matches desired t
Question
How is traffic forwarded from the Cisco ASA to the FirePOWER services module for analysis?
Options
- AThe SFR is transparent and automatically sees all traffic.
- BA service policy redirects traffic from the Cisco ASA packet-processing path to the SFR
- CThe SFR has a dedicated data interface
- DThe SFR is a standalone appliance that is inserted inline in the data path
How the community answered
(37 responses)- A5% (2)
- B92% (34)
- C3% (1)
Explanation
Option B is correct because the Cisco ASA FirePOWER Services Module (SFR) is an internal module that sits inside the ASA chassis - traffic does not reach it automatically. Instead, you use Cisco's Modular Policy Framework (MPF) to configure a service policy that matches desired traffic (via a class map) and applies an sfr action, explicitly redirecting those packets from the ASA's processing path to the SFR for deep inspection.
Why the distractors are wrong:
- A is wrong because the SFR has no passive "wire-tap" visibility; without a service policy, it sees nothing.
- C is wrong because the SFR is an internal module with no independent physical data interface connected to the network - it receives traffic only through the ASA's internal redirect mechanism.
- D describes a standalone FirePOWER appliance (NGIPS), not the SFR module. The SFR lives inside the ASA chassis, not inline in the external data path.
Memory tip: Use the acronym anchor - "Service policy Forwards to the sfR module." The letters S-F-R map to Service policy → FirePOWER Redirect, reminding you that explicit policy configuration is always the bridge between the ASA and its SFR module.
Topics
Community Discussion
No community discussion yet for this question.