Intra-zone traffic: On SRX devices, traffic between interfaces in the same security zone is allowed without requiring a security policy (Option C is correct). Policies are only evaluated for inter-zone traffic.
Junos-host functional zone: This zone is a predefined functional zone that allows administrators to apply policies controlling access to the SRX firewall itself, such as SSH, HTTP, or SNMP traffic (Option D is correct).
Null zone: This zone is a predefined discard zone. Interfaces placed in the null zone drop all traffic. It does not allow policy logging of dropped control plane traffic (Option A is incorrect).
Management functional zone: This is used to define management interfaces, not the “functional zone” as stated in Option B (incorrect wording).
Correct Statements: C and D
[Reference: Juniper Networks – Security Zones and Functional Zones, Junos OS Security Fundamentals., ]
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit