nerdexam
Juniper

JN0-633 · Question #152

Click the Exhibit button. [edit] user@host# run show log debug Feb3 22:04:31 22:04:31.824294:CID-0:RT:flow_first_policy_search: policy search from zone host-> zone attacker (Ox0,0xe4089404,0x17)…

The correct answer is A. The packet does not match any user-configured security policies. C. The log is showing the first path packet flow. See the full explanation below for the reasoning.

Question

Click the Exhibit button. [edit] user@host# run show log debug Feb3 22:04:31 22:04:31.824294:CID-0:RT:flow_first_policy_search: policy search from zone host-> zone attacker (Ox0,0xe4089404,0x17) Feb3 22:04:31 22:04:31.824297:CID-0:RT:Policy lkup: vsys 0 zone(9:host) -> zone(10:attacker) scope: 0 Feb3 22:04:31 22:04:31.824770:CID-0:RT:5.0.0.25/59028 -> 25.0.0.25/23 proto 6 Feb3 22:04:31 22:04:31.824778:CID-0:RT:Policy lkup: vsys 0 zone(5:Umkmowm) -> zone(5:Umkmowm) scope: 0 Feb3 22:04:31 22:04:31.824780:CID-0:RT:5.0.0.25/59028 -> 25.0.0.25/23 proto 6 Feb3 22:04:31 22:04:31.824783:CID-0:RT: app 10, timeout 1800s, curr ageout 20s Feb3 22:04:31 22:04:31.824785:CID-0:RT: permitted by policy default- policy-00(2) Feb3 22:04:31 22:04:31.824787:CID-0:RT: packet passed, Permitted by policy. Feb3 22:04:31 22:04:31.824790:CID-0:RT:flow_first_src_xlate:

nat_src_xlated: False, nat_src_xlate_failed; False Feb3 22:04:31 22:04:31.824834:CID-0:RT:flow_first_src_xlate: incoming src port is: 38118 Which two statements are true regarding the output shown in the exhibit? (Choose two.)

Options

  • AThe packet does not match any user-configured security policies.
  • BThe user has configured a security policy to allow the packet.
  • CThe log is showing the first path packet flow.
  • DThe log shows the reverse flow of the session.

How the community answered

(69 responses)
  • A
    77% (53)
  • B
    9% (6)
  • D
    14% (10)

Community Discussion

No community discussion yet for this question.

Full JN0-633 Practice