ASA Security Levels Enabling Exceptions to Default Behavior
By default, ASA security levels are employed to control the flow of traffic between DMZ, INSIDE, and OUTSIDE interfaces. But in order to allow some of the traffic to flow as desired, it is necessary to employ exceptions to the default behavior.
Those exceptions are configured using Access lists which permit traffic only to specific P addresses and ports needed by services intended to be publicly accessible. This approach minimizes exposure by keeping unnecessary services hidden from external access.
Links
https://networklessons.com/cisco/asa-firewall/cisco-asa-security-levels
https://networklessons.com/cisco/asa-firewall/cisco-asa-access-list