nerdexam
Juniper

JN0-696 · Question #2

Click the Exhibit button. Referring to the exhibit, PC-1 is unable to ping Server-1. Traffic from PC- 1 to Server-1 arrives on interface fe-0/0/3 but return traffic from Server-1 to PC-1 should be…

The correct answer is C. Move both interface fe-0/0/2 and fe-0/0/3 to the same security zone. See the full explanation below for the reasoning.

Question

Click the Exhibit button. Referring to the exhibit, PC-1 is unable to ping Server-1. Traffic from PC- 1 to Server-1 arrives on interface fe-0/0/3 but return traffic from Server-1 to PC-1 should be sent out from interface fe- 0/0/2. What would you change on SRX-1 to resolve this problem?

Options

  • AConfigure a security policy to allow traffic from the DMZ zone to the untrust-1 zone.
  • BConfigure a security policy to allow traffic from the DMZ zone to the untrust-2 zone.
  • CMove both interface fe-0/0/2 and fe-0/0/3 to the same security zone.
  • DDisable TCP SYN check and TCP sequence check.

How the community answered

(27 responses)
  • A
    11% (3)
  • B
    4% (1)
  • C
    81% (22)
  • D
    4% (1)

Community Discussion

No community discussion yet for this question.

Full JN0-696 Practice