JNCIA-SEC Junos OS Security Objects Practice Question
You want to configure a security zone to automatically reject new TCP connections with a TCP RST packet when the zone's transit sessions exceed capacity or policies deny them. Where is this behavior configured?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Under the security policy action keyword 'reject' rather than 'deny'.
Session drop behavior, such as sending TCP resets on rejection, is configured under security options or policy actions, but default session limits and rejection behaviors are managed within security options. Wait, session rejection action ('reject' vs 'deny') is specified directly within the security policy. Let's check session table limits: session limits can be set under [edit security max-sessions].
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Under the security policy action keyword 'reject' rather than 'deny'.
Why this is correct
Using 'reject' as a security policy action causes the SRX to send a TCP RST for TCP traffic or an ICMP unreachable for UDP traffic when blocked.
- ✗
Under the security zone options by enabling 'tcp-reset-on-drop'.
Why it's wrong here
Security zone options do not have a 'tcp-reset-on-drop' knob; policy actions dictate deny vs reject.
- ✗
Under the SCREEN options profile by enabling 'tcp-rst-reply'.
Why it's wrong here
SCREEN options detect attacks, they do not configure policy rejection behavior.
- ✗
Under the global system services configuration.
Why it's wrong here
System services do not govern transit policy rejection behavior.
Visual reference
About these practice questions
Courseiva writes every JNCIA-SEC question from scratch — 513 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Juniper Networks exam blueprint
This JNCIA-SEC practice question is part of Courseiva's free Juniper Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the JNCIA-SEC exam.