Juniper
JN0-332 · Question #313
Following a recent security audit, you find that users are able to ping between the untrust zone and the trust zone, which is contrary to your organization's current security policy. On examination…
The correct answer is A. The default policy has been modified to permit all traffic. C. A firewall filter has been configured that places traffic into packet mode. See the full explanation below for the reasoning.
Question
Following a recent security audit, you find that users are able to ping between the untrust zone and the trust zone, which is contrary to your organization's current security policy. On examination of the current security policies, you find no policies that would allow these connections. What are two reasons why users would be able to ping between these zones? (Choose two.)
Options
- AThe default policy has been modified to permit all traffic.
- BThere is a hidden policy that permits all traffic from untrust to trust.
- CA firewall filter has been configured that places traffic into packet mode.
- DICMP traffic is not subject to policy inspection.
How the community answered
(52 responses)- A71% (37)
- B10% (5)
- D19% (10)
Community Discussion
No community discussion yet for this question.