SRX devices operate on adefault deny-all policyif no explicit match is found:
If a packet does not match any configuredzone-basedorglobalpolicy, it is implicitly denied.
The traffic is discarded silently by the default security policy (Option A).
Option B:No predefined “safe zone” exists.
Option C:Logging occurs only if explicitly configured; default deny does not automatically log traffic.
Option D:Incorrect, since the firewall defaults to deny, not permit.
Correct Behavior:Traffic is discarded by the default security policy.
[Reference:Juniper Networks –Security Policy Evaluation and Default Deny Behavior, Junos OS Security Fundamentals., , ]
Submit