JNCIA-SEC Network Address Translation Practice Question
You are troubleshooting a Junos security deployment where Source NAT is configured with a pool. You observe that certain internal applications fail because the external receiving server expects the source port to remain identical to the internal client's ephemeral port (Port Preservation). Which feature or configuration setting should be applied to the source NAT pool to maintain source port numbers whenever possible?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure port preservation or persistent-nat on the source NAT pool to attempt retaining the original source port.
When port preservation is required so that the translated source port matches the original source port (if available), Junos supports port preservation options or persistent NAT settings on the source NAT pool.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable PAT globally so that source NAT operates exclusively as 1:1 without port translation.
Why it's wrong here
Disabling PAT when using a pool shared by multiple hosts causes address collision and session failure.
- ✗
Set the security policy action to 'port-preserve trust'.
Why it's wrong here
Security policies do not contain port preservation action keywords.
- ✗
Configure Static NAT instead of Source NAT for all clients requiring port preservation.
Why it's wrong here
Using static NAT for every internal client requires a 1:1 public IP ratio, which is impractical for large subnets.
- ✓
Configure port preservation or persistent-nat on the source NAT pool to attempt retaining the original source port.
Why this is correct
Port preservation / persistent-nat settings instruct the SRX to keep original source ports when allocating translation ports, provided they are not in conflict.
Visual reference
About these practice questions
This JNCIA-SEC question is part of Courseiva's 520-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Juniper Networks exam blueprint
This JNCIA-SEC practice question is part of Courseiva's free Juniper Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the JNCIA-SEC exam.