JNCIA-SEC Content Security Practice Question
An administrator configures Content Filtering to block executable files (.exe). Users report that they can still download archives containing executable files inside them (.zip). What is the recommended way to prevent users from bypassing file extension blocks using compressed archives?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add archive file extensions (such as .zip and .rar) to the content filtering block list.
To prevent users from bypassing file extension blocks using archives, content filtering or antivirus profiles should be configured to block archive types (.zip, .rar) or block password-protected/unscannable archives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Convert the security policy from stateless to stateful inspection.
Why it's wrong here
SRX security policies are stateful by default.
- ✗
Enable BGP routing route-reflection for HTTP traffic.
Why it's wrong here
BGP routing is unrelated to content filtering.
- ✓
Add archive file extensions (such as .zip and .rar) to the content filtering block list.
Why this is correct
Blocking archive file extensions prevents users from circumventing executable blocks using archive containers.
- ✗
Disable HTTP proxy caching on the client browsers.
Why it's wrong here
Browser caching does not affect firewall file extension inspection.
About these practice questions
Courseiva writes every JNCIA-SEC question from scratch — 513 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Juniper Networks exam blueprint
This JNCIA-SEC practice question is part of Courseiva's free Juniper Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the JNCIA-SEC exam.