Courseiva
Srx Series Service GatewayshardMultiple ChoiceObjective-mapped

JNCIA-SEC Srx Series Service Gateways Practice Question

An administrator configures NAT on an SRX Series gateway and encounters an issue where overlapping IP spaces require destination NAT and source NAT (twice NAT) simultaneously. In what order are NAT rules evaluated in the SRX packet flow?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Destination NAT is evaluated before routing and security policy lookup, while Source NAT is evaluated later in the flow pipeline

Destination NAT is evaluated first on incoming packets before routing lookup, while source NAT is evaluated later in the packet flow outbound.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Both NAT types are evaluated simultaneously in a single processing step.

    Why it's wrong here

    They occur at different stages of the SRX packet flow pipeline.

  • NAT rules are only evaluated after session termination.

    Why it's wrong here

    NAT must be evaluated when establishing the session.

  • Source NAT is evaluated before Destination NAT

    Why it's wrong here

    Destination NAT happens prior to routing and security policy lookups, whereas source NAT happens later.

  • Destination NAT is evaluated before routing and security policy lookup, while Source NAT is evaluated later in the flow pipeline

    Why this is correct

    Destination NAT modifies the destination IP before the routing lookup, and source NAT is applied on egress/session creation.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every JNCIA-SEC question from scratch — 513 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Juniper Networks exam blueprint

This JNCIA-SEC practice question is part of Courseiva's free Juniper Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the JNCIA-SEC exam.