Courseiva
Network Address TranslationhardMultiple ChoiceObjective-mapped

JNCIA-SEC Network Address Translation Practice Question

You are troubleshooting a scenario where an SRX device is performing Static NAT. An internal server initiates outbound connections to the internet. When external recipients examine the packets, they see the correct static NAT public IP as the source. However, when the external recipients reply, the packets are dropped by the SRX. Traceoptions reveal 'No session found for packet'. What is the cause of this session lookup failure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The return traffic security policy or session state lookup failed because the incoming return packet did not match the expected session parameters or was blocked by a policy.

When an internal server initiates an outbound connection under static NAT, the SRX creates a session table entry. If return traffic arrives with destination IP matching the static public IP, but the source port or IP does not match the expected state (or if security policies drop it), the session lookup fails.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The return traffic security policy or session state lookup failed because the incoming return packet did not match the expected session parameters or was blocked by a policy.

    Why this is correct

    Session lookup failures for return traffic typically point to security policy blocking or state mismatch.

  • The routing table lacks a default route for static NAT reply packets.

    Why it's wrong here

    If routing lacked a default route, the error would state 'No route found' rather than 'No session found'.

  • Static NAT requires explicit source NAT pool definitions for all outbound connections.

    Why it's wrong here

    Static NAT provides bidirectional translation automatically without needing separate source NAT pools.

  • Proxy ARP is not enabled for the internal server's private IP address.

    Why it's wrong here

    Proxy ARP is for external interfaces responding to upstream routers, not return session state lookups.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 513 original JNCIA-SEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Juniper Networks exam blueprint

This JNCIA-SEC practice question is part of Courseiva's free Juniper Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the JNCIA-SEC exam.