Courseiva
Network Address TranslationmediumMultiple ChoiceObjective-mapped

JNCIA-SEC Network Address Translation Practice Question

An administrator configures interface-based Source NAT on the outgoing external interface of a SRX Series device. However, internal hosts report being unable to reach external web servers. Upon checking the security flow session, the administrator notices that packets are egressing the interface with the actual internal private IP address rather than the interface IP. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The source NAT rule is missing the 'then source-nat interface' action statement.

Interface-based Source NAT requires the configuration under the security nat source rule-set to reference the correct 'from zone' and 'to zone', and the rule must contain 'then source-nat interface'. If the rule is missing or not applied to the traffic flow direction, translation will not occur.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The security policy is evaluating the post-translation source IP instead of the pre-translation IP.

    Why it's wrong here

    Security policies on Junos OS evaluate the pre-NAT source IP for source NAT rules.

  • Proxy ARP must be manually enabled on the internal interface for interface-based NAT to function.

    Why it's wrong here

    Proxy ARP is typically required for static or destination NAT with external IP pools, not for interface-based source NAT.

  • Interface-based Source NAT requires an explicit routing instance to bypass the master routing table.

    Why it's wrong here

    Interface-based NAT operates within the standard routing table without needing a separate routing instance.

  • The source NAT rule is missing the 'then source-nat interface' action statement.

    Why this is correct

    Without the explicit 'then source-nat interface' action, the SRX Series device will not perform translation and will attempt to route the private IP out.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This JNCIA-SEC question is part of Courseiva's 513-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Juniper Networks exam blueprint

This JNCIA-SEC practice question is part of Courseiva's free Juniper Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the JNCIA-SEC exam.