nerdexam
Juniper

JN0-336 · Question #8

When a security policy is deleted, which statement is correct about the default behavior of active sessions allowed by that policy?

The correct answer is B. The active sessions allowed by the policy will be marked as a legacy flow and will continue to be. When a security policy is deleted, the existing sessions that were previously allowed by that policy are not immediately dropped; instead, they are typically treated as legacy flows. This means they are allowed to continue until they naturally end or until the session timeout…

Security Zones, Policies, and Objects

Question

When a security policy is deleted, which statement is correct about the default behavior of active sessions allowed by that policy?

Options

  • AThe active sessions allowed by the policy will be dropped.
  • BThe active sessions allowed by the policy will be marked as a legacy flow and will continue to be
  • CThe active sessions allowed by the policy will be reevaluated by the cached
  • DThe active sessions allowed by the policy will continue

How the community answered

(42 responses)
  • A
    2% (1)
  • B
    93% (39)
  • D
    5% (2)

Explanation

When a security policy is deleted, the existing sessions that were previously allowed by that policy are not immediately dropped; instead, they are typically treated as legacy flows. This means they are allowed to continue until they naturally end or until the session timeout is reached. This behavior ensures that deleting a policy does not abruptly disrupt ongoing traffic flows that were previously authorized by that policy. This approach helps in avoiding unintended service disruptions, especially in production environments where active connections may be critical to operations.

Topics

#security policy#active sessions#legacy flow#policy deletion

Community Discussion

No community discussion yet for this question.

Full JN0-336 Practice