Trouble Spots
The challenges presented by the Cisco Deploying ASA Firewall Solutions exam consist of exam simulations and answer deducing. Regarding exam simulations, the challenge and tradeoff here is time as the activities/objectives can prove time consuming. The key is success here is hands-on experience with both CLI and ASDM related configuration. Answer deducing should not be new to Cisco exam takers, as it is quite common to experience questions in which you are able to eliminate some answer choices, but not all. The answer choices typically come down to two or three options. The key here is to possess the resolve to deduce the most adequate answer given specific details by reviewing the helpful resources that follow this document, in addition to any training courses, and further reference materials used.
Detailed challenges include ASA architecture, including the following:
- Understanding how the ASA processes traffic, i.e., does NAT happen before crypto, etc.
- ASDM configuration
- Understanding the types of SSM modules suited for the ASA platform and how they interoperate/communicate with the ASA platform for data traffic and management
- Access controls leveraging AAA protocol(s) and concepts