nerdexam
Cisco

700-270 · Question #60

How is traffic forwarded from the Cisco ASA to the FirePOWER services module for analysis?

The correct answer is B. A service policy redirects traffic from the Cisco ASA packet-processing path to the SFR. Option B is correct because the Cisco ASA FirePOWER Services Module (SFR) is an internal module that sits inside the ASA chassis - traffic does not reach it automatically. Instead, you use Cisco's Modular Policy Framework (MPF) to configure a service policy that matches desired t

Understanding Next-Generation Firewall Technology and Concepts

Question

How is traffic forwarded from the Cisco ASA to the FirePOWER services module for analysis?

Options

  • AThe SFR is transparent and automatically sees all traffic.
  • BA service policy redirects traffic from the Cisco ASA packet-processing path to the SFR
  • CThe SFR has a dedicated data interface
  • DThe SFR is a standalone appliance that is inserted inline in the data path

How the community answered

(37 responses)
  • A
    5% (2)
  • B
    92% (34)
  • C
    3% (1)

Explanation

Option B is correct because the Cisco ASA FirePOWER Services Module (SFR) is an internal module that sits inside the ASA chassis - traffic does not reach it automatically. Instead, you use Cisco's Modular Policy Framework (MPF) to configure a service policy that matches desired traffic (via a class map) and applies an sfr action, explicitly redirecting those packets from the ASA's processing path to the SFR for deep inspection.

Why the distractors are wrong:

  • A is wrong because the SFR has no passive "wire-tap" visibility; without a service policy, it sees nothing.
  • C is wrong because the SFR is an internal module with no independent physical data interface connected to the network - it receives traffic only through the ASA's internal redirect mechanism.
  • D describes a standalone FirePOWER appliance (NGIPS), not the SFR module. The SFR lives inside the ASA chassis, not inline in the external data path.

Memory tip: Use the acronym anchor - "Service policy Forwards to the sfR module." The letters S-F-R map to Service policy → FirePOWER Redirect, reminding you that explicit policy configuration is always the bridge between the ASA and its SFR module.

Topics

#ASA-SFR Architecture#Service Policies#FirePOWER Integration#Traffic Forwarding

Community Discussion

No community discussion yet for this question.

Full 700-270 Practice