JN0-696 · Question #71
You are deploying AppFW in an SRX Series device and implemented the application signature shown below: junos:FACEBOOK-ACCESS Traffic is going through the correct policy zone and the license for…
The correct answer is B. You need to add junos:FACEBOOK-ACCESS to a black-list. AppFW works by creating an application rulebase. This works on a whitelist/blacklist approach. We either allow a few things with a default action of deny or deny a few things with a default action of permit.
Question
You are deploying AppFW in an SRX Series device and implemented the application signature shown below:
junos:FACEBOOK-ACCESS Traffic is going through the correct policy zone and the license for appid-sig is active. The signature package is current, and the application firewall is applied to the correct zone. However, you can still access FaceBook. What is the problem?
Options
- BYou need to add junos:FACEBOOK-ACCESS to a black-list.
- CThere is no available cache in the browser, therefore it is not hitting the firewall.
- DNew sessions are bypassing the policy rule.
How the community answered
(40 responses)- B75% (30)
- C8% (3)
- D18% (7)
Explanation
AppFW works by creating an application rulebase. This works on a whitelist/blacklist approach. We either allow a few things with a default action of deny or deny a few things with a default action of permit.
Topics
Community Discussion
No community discussion yet for this question.