Referring to the exhibit, which statement is correct?
A.
policy3 will be shadowed because it matches the same application as policy1.
B.
None of the policies will be shadowed.
C.
policy1 will be shadowed because it matches the same application as policy3.
D.
policy2 will be shadowed because it matches the same application as policy1.
The Answer Is:
A
This question includes an explanation.
Explanation:
Juniper SRX evaluatessecurity policies in order, top to bottom. The first matching policy determines the action, and no further policies are evaluated. This behavior can lead toshadowed policiesif later policies match the same conditions as earlier ones.
From the exhibit:
Policy1:Matches application junos-http and permits traffic.
Policy2:Matches application junos-https and permits traffic.
Policy3:Matches application junos-http again, but denies traffic.
Sincepolicy1already matches all HTTP traffic and permits it, traffic never reachespolicy3. This makespolicy3 shadowedbecause it has the same match condition as policy1 but is evaluated later in the list.
Other options:
Policy1 is not shadowed because it is evaluated first.
Policy2 is independent (application = HTTPS) and therefore unaffected.
Only policy3 is shadowed by policy1.
Correct Statement:Policy3 will be shadowed because it matches the same application as policy1.
[Reference:Juniper Networks –Security Policy Evaluation Order and Shadowed Policies, Junos OS Security Fundamentals.]
JN0-232 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 60% Discount on All Products,
Use Coupon: "8w52ceb345"