Courseiva
Security PolicieshardMultiple ChoiceObjective-mapped

JNCIA-SEC Security Policies Practice Question

An administrator implements AppID within the unified security policy framework on an SRX Series device to identify and control specific cloud-based applications. The initial policy uses a broad match for 'junos-ssl' at the transport layer, while a subsequent policy specifies 'junos-facebook' using AppID. How does the SRX policy engine evaluate and re-evaluate traffic when application identification takes multiple packets to determine?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The SRX evaluates the initial packets against transport-layer criteria, and once AppID identifies the specific application, it re-evaluates the session against application-specific policies.

When AppID is enabled, the SRX initially matches the transport layer policy. Once the application is identified mid-stream, the security engine re-evaluates the session against policies with specific application signatures and can take action (such as closing or shifting the session).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The session is terminated immediately upon initial packet inspection because the AppID cannot be determined instantly.

    Why it's wrong here

    Sessions are allowed to pass initial packets while AppID inspects payload signatures.

  • AppID policies are evaluated before any transport layer policies, regardless of rule ordering.

    Why it's wrong here

    Policies are evaluated in the order they are configured; AppID does not bypass the top-down rule order.

  • The SRX evaluates the initial packets against transport-layer criteria, and once AppID identifies the specific application, it re-evaluates the session against application-specific policies.

    Why this is correct

    Mid-stream re-evaluation is a core mechanism of the Junos AppID engine.

  • Application identification only occurs for the return traffic stream.

    Why it's wrong here

    AppID inspects both directions of the traffic flow to determine signatures.

About these practice questions

This JNCIA-SEC question is part of Courseiva's 520-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Juniper Networks exam blueprint

This JNCIA-SEC practice question is part of Courseiva's free Juniper Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the JNCIA-SEC exam.