Can you have two ASA 5520s running as Active/Active when you have a single ISP and one security context (duplicated across both boxes)?
Or in this scenario can you only use active/standby?
Yes. In Active/Standby failover, it is the entire chassis that fails over (including whatever SSM module is in the chassis). So the newly active ASA and it's SSM module will be the one processing the traffic.
This is why we have the failover requirement that both boxes must have the exact same hardware (SSM module included).
PS> If this solves your issue, please don't forget to check the box to let us know.
Unfortunately Active/Active requires multi-contexts. Additionally, the same context cannot be active on both units. (Ctx A will be active on unit 1, but standby on unit 2; Ctx B will be active on unit 2, but standby on unit 1).
Now, *if* you did configure only one context and also A/A, then it would be equivalent to active/standby (as that single context can only be active on a single box at a time).
Therefore, in the case you describe, I cannot see how A/A would work for you.