Courseiva
Junos OS Security ObjectshardMultiple ChoiceObjective-mapped

JNCIA-SEC Junos OS Security Objects Practice Question

You are troubleshooting an issue where TFTP file transfers are failing across an SRX device. Traffic is permitted by security policies. What is the most likely cause of this behavior?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The TFTP ALG is disabled or missing, preventing dynamic data port opening.

TFTP relies on UDP port 69 for initial control, but dynamically negotiates a new port for data transfer. The TFTP ALG must be active to handle this port translation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The TCP proxy is disabled in the security zone.

    Why it's wrong here

    TFTP is a UDP-based protocol, not TCP proxy-dependent.

  • The TFTP ALG is disabled or missing, preventing dynamic data port opening.

    Why this is correct

    TFTP requires an ALG to open dynamic pinholes for the data transfer phase.

  • Address books are blocking high-numbered UDP ephemeral ports.

    Why it's wrong here

    Address books filter by IP address/subnet, not by ephemeral port numbers.

  • Screen options are misinterpreting TFTP data packets as a UDP flood attack.

    Why it's wrong here

    While possible if thresholds are low, ALG failure is the classic root cause for TFTP transfer failures.

About these practice questions

Courseiva writes every JNCIA-SEC question from scratch — 513 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Juniper Networks exam blueprint

This JNCIA-SEC practice question is part of Courseiva's free Juniper Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the JNCIA-SEC exam.