Courseiva
Content SecuritymediumMultiple ChoiceObjective-mapped

JNCIA-SEC Content Security Practice Question

You are troubleshooting a web filtering policy on an SRX Series firewall configured for Integrated Web Filtering. Users report that a specific educational website is being blocked under the 'Finance' category. Where should you configure a custom exemption or local override to permit access to this specific URL without changing the global category assignment?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure a custom URL category and assign a permit action within the UTM policy profile.

Custom local overrides for web filtering URLs on SRX devices are configured under the [edit security UTM custom-objects url-pattern] and referenced in the custom-url-category.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Modify the Junos global bypass list under [edit system services web-management].

    Why it's wrong here

    This path refers to device management web access, not traffic filtering.

  • Add the URL to the application firewall (AppID) custom application definition.

    Why it's wrong here

    AppID is separate from UTM web filtering overrides.

  • Configure a security policy source NAT rule to bypass the UTM profile for that specific IP.

    Why it's wrong here

    Source NAT alters packet headers and does not exempt traffic from UTM inspection profiles.

  • Configure a custom URL category and assign a permit action within the UTM policy profile.

    Why this is correct

    Creating a custom URL category with a permit action allows administrators to override cloud-based category blocking for specific URLs.

About these practice questions

Courseiva writes every JNCIA-SEC question from scratch — 520 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Juniper Networks exam blueprint

This JNCIA-SEC practice question is part of Courseiva's free Juniper Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the JNCIA-SEC exam.