JNCIA-SEC Network Address Translation Practice Question
An administrator configures interface-based Source NAT on the outgoing external interface of a SRX Series device. However, internal hosts report being unable to reach external web servers. Upon checking the security flow session, the administrator notices that packets are egressing the interface with the actual internal private IP address rather than the interface IP. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The source NAT rule is missing the 'then source-nat interface' action statement.
Interface-based Source NAT requires the configuration under the security nat source rule-set to reference the correct 'from zone' and 'to zone', and the rule must contain 'then source-nat interface'. If the rule is missing or not applied to the traffic flow direction, translation will not occur.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The security policy is evaluating the post-translation source IP instead of the pre-translation IP.
Why it's wrong here
Security policies on Junos OS evaluate the pre-NAT source IP for source NAT rules.
- ✗
Proxy ARP must be manually enabled on the internal interface for interface-based NAT to function.
Why it's wrong here
Proxy ARP is typically required for static or destination NAT with external IP pools, not for interface-based source NAT.
- ✗
Interface-based Source NAT requires an explicit routing instance to bypass the master routing table.
Why it's wrong here
Interface-based NAT operates within the standard routing table without needing a separate routing instance.
- ✓
The source NAT rule is missing the 'then source-nat interface' action statement.
Why this is correct
Without the explicit 'then source-nat interface' action, the SRX Series device will not perform translation and will attempt to route the private IP out.
Visual reference
About these practice questions
This JNCIA-SEC question is part of Courseiva's 513-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Juniper Networks exam blueprint
This JNCIA-SEC practice question is part of Courseiva's free Juniper Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the JNCIA-SEC exam.