Juniper Networks Certified Associate Junos JNCIA Junos · Free Practice Question Medium
Question 13
Which of these is true about zone-based security policies? (Choose two)
-
A
Zone-based security policies must include a source address in the match criteria
-
B
Zone-based security policies must include user information in the match criteria
-
C
Zone-based security policies must include a URL category in the match criteria
-
D
Zone-based security policies must include a destination address in the match criteria
Reveal correct answers
Correct answers: A, D
Explanation
Each policy consists of:
1. A unique name for the policy.
2. A from-zone and a to-zone, for example: user@host# set security policies from-zone untrust to-zone untrust
3. A set of match criteria defining the conditions that must be satisfied to apply the policy rule. The match criteria are based on a source IP address, destination IP address, and applications. The user identity firewall provides greater granularity by including an additional tuple, source-identity, as part of the policy statement.
4. A set of actions to be performed in case of a match—permit, deny, or reject.
5. Accounting and auditing elements—counting, logging, or structured system logging.
Further reading - https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-policy-configuration.html
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
