Exam JN0-105 All QuestionsBrowse all questions from this exam
Question 11

Which two statements are correct about firewall filters? (Choose two.)

    Correct Answer: A, C

    In firewall filters, 'Discard' is the default action for packets that are not explicitly allowed to ensure security by blocking any unspecified traffic. Additionally, it is possible to have multiple firewall filters, which can be applied to different interfaces or directions to meet various traffic control requirements depending on the network's needs.

Discussion
thatstrawOptions: AC

The two correct statements about firewall filters are: A. "Discard" is the default action of packets that are not explicitly allowed. - If a packet does not match any term in a firewall filter, the default action is typically to discard the packet. This default behavior ensures that only explicitly permitted traffic is allowed through, enhancing security. C. There can be multiple firewall filters. - Multiple firewall filters can be created and applied to different interfaces or different directions (inbound or outbound) on a network device. Each filter can be tailored to specific traffic control needs.

topicsdisOptions: AC

A and C

ahmeedi251Options: AC

Discard is default action for firewall filter , accept is default action for Routing policy

5a1dde4Options: AC

A. Discard is default action for firewall filter C. There can be multiple firewall filters

Pedro2024Options: AC

A and C

ArshadAlamOptions: AC

A and C

b39dcd4Options: AC

Firewall systems, including those in Junos, allow the configuration of multiple firewall filters. This flexibility is necessary to apply different rulesets based on varying criteria such as incoming interface, source address, destination address, application, etc. In many firewall configurations, including Junos firewall filters, if a packet does not match any of the specified rules, the default action is typically to discard or drop the packet. This is known as an implicit deny or default deny posture, where security is prioritized by denying all traffic that isn't explicitly allowed by any rule.