Which two statements are true about the procedures the Junos security device uses when handling traffic destined for the device itself? (Choose two.)
A.
If the received packet is addressed to the ingress interface, then the device first performs a security policy evaluation for the junos-host zone.
B.
If the received packet is addressed to the ingress interface, then the device first examines the host -inbound-traffic configuration for the ingress interface and zone.
C.
If the received packet is destined for an interface other than the ingress interface, then the device performs a security policy evaluation based on the ingress and egress zone.
D.
If the received packet is destined for an interface other than the ingress interface, then the device performs a security policy evaluation for the junos-host zone.
B. If the received packet is addressed to the ingress interface, then the device first examines the host-inbound-traffic configuration for the ingress interface and zone.
Correct — This is the proper process. When the packet is for the SRX itself, it checks whether the service (e.g., SSH, HTTPS, etc.) is permitted under the host-inbound-traffic configuration.
C. If the received packet is destined for an interface other than the ingress interface, then the device performs a security policy evaluation based on the ingress and egress zone.
Correct — This describes transit traffic, where packets pass through the SRX. In this case, the device performs a security policy lookup between ingress and egress zones.
A,B be are oposit, and first hostinbound is checked.
C - non-inbound interface means that traffic must go through 2 zones (and then policies), next is host inbound and at the end junos host.
upvoted 2 times
...
This section is not available anymore. Please use the main Exam Page.JN0-637 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
e359166
3 weeks agoinmymind84
7 months, 3 weeks ago