nerdexam
Juniper

JN0-696 · Question #1

Click the Exhibit button. You are troubleshooting a communication problem between a trust zone and an untrust zone in the network, where PC-1 cannot ping PC-2. Referring to the exhibit, which…

The correct answer is A. Add a security policy to allow ICMP traffic from the untrust zone to the trust zone. B: This has already been done by permitting any source, any dest and any app. C: No address book is used in the policy, so no need for an address book entry. D: Add a security policy to allow ICMP from untrust to trust; this one is not valid, as session is initiated from trust…

Troubleshooting Firewall Filters

Question

Click the Exhibit button. You are troubleshooting a communication problem between a trust zone and an untrust zone in the network, where PC-1 cannot ping PC-2. Referring to the exhibit, which configuration change on SRX- 1 would resolve this problem?

Options

  • AAdd a security policy to allow ICMP traffic from the untrust zone to the trust zone.
  • BConfigure proxy-arp under the [edit security nat] hierarchy.
  • CAdd a security policy to allow ICMP traffic from the trust zone to the untrust zone.
  • DAdd an address book entry for address 70.1.1.2.

How the community answered

(45 responses)
  • A
    76% (34)
  • B
    9% (4)
  • C
    11% (5)
  • D
    4% (2)

Explanation

B: This has already been done by permitting any source, any dest and any app. C: No address book is used in the policy, so no need for an address book entry. D: Add a security policy to allow ICMP from untrust to trust; this one is not valid, as session is initiated from trust zone.

Topics

#security policy direction#ICMP permit#trust zone#untrust zone

Community Discussion

No community discussion yet for this question.

Full JN0-696 Practice