exam questions

Exam JN0-335 All Questions

View all questions & answers for the JN0-335 exam

Exam JN0-335 topic 1 question 8 discussion

Actual exam question from Juniper's JN0-335
Question #: 8
Topic #: 1
[All JN0-335 Questions]

Which two statements are correct about security policy changes when using the policy rematch feature? (Choose two.)

  • A. When a policy change includes changing the policy's action from permit to deny, all existing sessions are maintained.
  • B. When a policy change includes changing the policy's source or destination address match condition, all existing sessions are dropped.
  • C. When a policy change includes changing the policy's action from permit to deny, all existing sessions are dropped.
  • D. When a policy change includes changing the policy's source or destination address match condition, all existing sessions are reevaluated.
Show Suggested Answer Hide Answer
Suggested Answer: CD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Nikhil541993
1 week, 5 days ago
Selected Answer: BC
The correct answer is B & C. Here's why: B. When a policy change includes changing the policy's source or destination address match condition, all existing sessions are dropped. Correct – Changing the source or destination address affects how traffic is matched, so all existing sessions are dropped because they may no longer match the modified policy. C. When a policy change includes changing the policy's action from permit to deny, all existing sessions are dropped. Correct – If a policy action is changed from permit to deny, the existing sessions are immediately dropped because they are no longer allowed under the new rule. Why D is incorrect: D states that sessions are "reevaluated" when source or destination addresses are changed. However, in most firewalls with a policy rematch feature, such changes result in sessions being dropped, not just reevaluated. The system does not keep the session and just check it again—it removes it because the session may no longer be valid.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago