Our current setup using ASA and Firepower
 
Inside : 20.20.20.0/24
Outside : x.x.x.x
 
My access control policy is such that it inspects 'Inside' to 'Outside', where 'Inside' is Firewall trusted interface, and 'Outside' is Outside interface.
 
I understand all packets outbound are inspected, but what if I have an FTP server on the inside that is accessible from internet? How can I inspect this inbound traffic knowing the FTP allows data copy from internet.