JNCIA-SEC Security Policies Practice Question
An administrator implements AppID within the unified security policy framework on an SRX Series device to identify and control specific cloud-based applications. The initial policy uses a broad match for 'junos-ssl' at the transport layer, while a subsequent policy specifies 'junos-facebook' using AppID. How does the SRX policy engine evaluate and re-evaluate traffic when application identification takes multiple packets to determine?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The SRX evaluates the initial packets against transport-layer criteria, and once AppID identifies the specific application, it re-evaluates the session against application-specific policies.
When AppID is enabled, the SRX initially matches the transport layer policy. Once the application is identified mid-stream, the security engine re-evaluates the session against policies with specific application signatures and can take action (such as closing or shifting the session).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The session is terminated immediately upon initial packet inspection because the AppID cannot be determined instantly.
Why it's wrong here
Sessions are allowed to pass initial packets while AppID inspects payload signatures.
- ✗
AppID policies are evaluated before any transport layer policies, regardless of rule ordering.
Why it's wrong here
Policies are evaluated in the order they are configured; AppID does not bypass the top-down rule order.
- ✓
The SRX evaluates the initial packets against transport-layer criteria, and once AppID identifies the specific application, it re-evaluates the session against application-specific policies.
Why this is correct
Mid-stream re-evaluation is a core mechanism of the Junos AppID engine.
- ✗
Application identification only occurs for the return traffic stream.
Why it's wrong here
AppID inspects both directions of the traffic flow to determine signatures.
About these practice questions
This JNCIA-SEC question is part of Courseiva's 520-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Juniper Networks exam blueprint
This JNCIA-SEC practice question is part of Courseiva's free Juniper Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the JNCIA-SEC exam.