Cisco ASA SAL Integration Prerequisites

Configure secure network management of perimeter security and infrastructure devices such as SNMPv3, NetConf, RestConf, APIs, secure syslog, and NTP with authentication
Answer Correct answer: C — Onboard Cisco ASA device to CDO is needed.

An engineer needs to configure cloud logging on Cisco ASA with SAL integration. Which parameter must be considered for this configuration?

  1. Events can be viewed only from one regional cloud.
  2. All CSM versions are supported.
  3. Onboard Cisco ASA device to CDO is needed. Correct Answer
  4. Required storage size can be allocated dynamically.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the prerequisite steps for enabling SAL, specifically the dependency on CDO onboarding rather than just network connectivity or version compatibility.

Configuring Security Analytics and Logging (SAL) on Cisco ASA requires the device to be onboarded to Cisco Defense Orchestrator (CDO). This process establishes the necessary management plane for cloud logging integration.

Many candidates choose Option A, assuming regional restrictions are the primary configuration hurdle, but the fundamental requirement is establishing the device identity in CDO first.

Community Discussion (3 comments)

Arian5431 👍 1
C correct Answer
luismg 👍 2 Selected: C
The answer is C https://docs.defenseorchestrator.com/c_implementing-cisco-security-analytics-and-logging-saas-for-asa-devices.html Be sure to review "Before you Begin" above to make sure your environment is properly configured. Onboard ASA Device to CDO using username and password. Send ASA Syslog Events to the Cisco Cloud. Configuring NSEL for ASA Devices Using a CDO Macro. Confirm events are visible in CDO. From the navigation bar, select Monitoring > Event Logging. Click the Live tab to view live events. If you have a Firewall Analytics and Monitoring or Total Network Analytics and Monitoring license, continue with the next section, Analyzing Events with Cisco Secure Cloud Analytics.
dya11 👍 2
Seems to be A: Determine which regional cloud you will send events to. "Events cannot be viewed from or moved between different regional clouds." https://www.cisco.com/c/en/us/td/docs/security/asa/special/sal-saas/cisco-asa-and-cisco-security-analytics-and-logging-asdm-integration-guide.html

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct answer is C because Cisco Security Analytics and Logging (SAL) relies on a centralized management hierarchy. Before any syslog events can be sent to the cloud, the ASA must be onboarded to Cisco Defense Orchestrator (CDO). The official documentation states that you must "Onboard ASA Device to CDO" as a preliminary step to configure the connection parameters.

Why the Other Options Are Wrong

Option A is incorrect because while regional constraints exist, they are not the primary configuration parameter for establishing the link; the device must simply be assigned to a region during onboarding. Option B is false because specific ASA IOS-XE versions and FTD versions are required, not all CSM versions. Option D is misleading as storage is managed by the service provider, not dynamically allocated by the engineer at the device level.

Community Comment Notes

Community feedback strongly supports C, with users citing the 'Before you Begin' section of the implementation guide which explicitly lists onboarding to CDO as the first mandatory step. One user noted, "Be sure to review 'Before you Begin' above to make sure your environment is properly configured," reinforcing that technical configuration follows administrative onboarding.

Official Reference

Exam Strategy

Always check for management plane prerequisites before diving into data plane configurations. For cloud-integrated security services like SAL, identify if onboarding to a central orchestrator (like CDO) is required.

Frequently Asked Questions

Why is onboarding to CDO required for SAL?

CDO acts as the central management plane that authenticates the ASA and configures the secure tunnel to the SAL cloud.

Can I send logs without CDO onboarding?

No, the ASA must be registered and managed via CDO to establish the authorized connection for Security Analytics and Logging.

Related Analysis

← Back to 350-701 Study Guide