Valid JN0-335 Dumps shared by ExamDiscuss.com for Helping Passing JN0-335 Exam! ExamDiscuss.com now offer the newest JN0-335 exam dumps, the ExamDiscuss.com JN0-335 exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com JN0-335 dumps with Test Engine here:
You are deploying a new SRX Series device and you need to log denied traffic. In this scenario, which two policy parameters are required to accomplish this task? (Choose two.)
Correct Answer: A,C
Explanation To log denied traffic, you need to configure a security policy with the action of deny and the option of log session-init. The deny action blocks the traffic that matches the policy criteria, and the log session-init option generates a log entry when the session is denied. The session-close option is not required, as it only logs the end of a session. The count option is not required, as it only increments a counter for the policy. References: [SRX] How to log traffic that is denied by default system security policy1 [SRX] How to log traffic for the default deny policy2 How to log traffic dropped by Juniper SRX firewalls3