JN0-696 · Question #1
Click the Exhibit button. You are troubleshooting a communication problem between a trust zone and an untrust zone in the network, where PC-1 cannot ping PC-2. Referring to the exhibit, which…
The correct answer is A. Add a security policy to allow ICMP traffic from the untrust zone to the trust zone. B: This has already been done by permitting any source, any dest and any app. C: No address book is used in the policy, so no need for an address book entry. D: Add a security policy to allow ICMP from untrust to trust; this one is not valid, as session is initiated from trust…
Question
Click the Exhibit button. You are troubleshooting a communication problem between a trust zone and an untrust zone in the network, where PC-1 cannot ping PC-2. Referring to the exhibit, which configuration change on SRX- 1 would resolve this problem?
Options
- AAdd a security policy to allow ICMP traffic from the untrust zone to the trust zone.
- BConfigure proxy-arp under the [edit security nat] hierarchy.
- CAdd a security policy to allow ICMP traffic from the trust zone to the untrust zone.
- DAdd an address book entry for address 70.1.1.2.
How the community answered
(45 responses)- A76% (34)
- B9% (4)
- C11% (5)
- D4% (2)
Explanation
B: This has already been done by permitting any source, any dest and any app. C: No address book is used in the policy, so no need for an address book entry. D: Add a security policy to allow ICMP from untrust to trust; this one is not valid, as session is initiated from trust zone.
Topics
Community Discussion
No community discussion yet for this question.