Which statement about the Cisco ASA 5585-X appliance is true?
A.
The IPS SSP must be installed in slot 0 (bottom slot) and the firewall/VPN SSP must be
installed in slot 1 (top slot).
B.
The IPS SSP operates independently. The firewall/VPN SSP is not necessary to support the
IPS SSP.
C.
The ASA 5585-X appliance supports three types of SSP (the firewall/VPN SSP, the IPS SSP,
and the CSC SSP).
D.
The ASA 5585-X appliance with the firewall/VPN SSP-60 has a maximum firewall throughput of
10 Gb/s.
E.
All IPS traffic (except the IPS management interface traffic) must flow through the firewall/VPN
SSP first before it can be redirected to the IPS SSP.
Explanation:
http://www.cisco.com/en/US/docs/security/asa/quick_start/ips/ips_qsg.pdf
The IPS module runs a separate application from the ASA. The IPS module might include an
external management interface so you can connect to the IPS module directly; if it does not have a
management interface, you can connect to the IPS module through the ASA interface. Any other
interfaces on the IPS module, if available for your model, are used for ASA traffic only.
Traffic goes through the firewall checks before being forwarded to the IPS module.