nerdexam
Juniper

JN0-336 · Question #69

When a security policy is modified, which statement is correct about the default behavior for active sessions allowed by that policy?

The correct answer is D. The active sessions allowed by the policy will continue unchanged. When you modify a security policy on the SRX Series device, the default behavior is that the existing sessions that match the policy will continue unchanged. This means that the policy modification will only affect new sessions that are initiated after the change. However, you…

Security Zones, Policies, and Objects

Question

When a security policy is modified, which statement is correct about the default behavior for active sessions allowed by that policy?

Options

  • AThe active sessions allowed by the policy will be dropped.
  • BOnly policy changes that involve modification of the action field will cause the active sessions affected
  • COnly policy changes that involve modification of the application will cause the active sessions affected
  • DThe active sessions allowed by the policy will continue unchanged.

How the community answered

(43 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    5% (2)
  • D
    91% (39)

Explanation

When you modify a security policy on the SRX Series device, the default behavior is that the existing sessions that match the policy will continue unchanged. This means that the policy modification will only affect new sessions that are initiated after the change. However, you can change this behavior by using the clear-policy-session command, which will clear all the sessions that match the modified policy and force them to re-evaluate the new policy. Reference: = JNCIS-SEC Certification, Open Learning - Security, Specialist (JNCIS-SEC), Security Policies (Advanced)

Topics

#security policy#active sessions#policy modification#session continuity

Community Discussion

No community discussion yet for this question.

Full JN0-336 Practice