PrepAway - Latest Free Exam Questions & Answers

What are two reasons for this problem?

A local user complains that they cannot connect to an FTP server on the DMZ network. You
investigate and confirm that the security policy allows FTP traffic from the trust zone to the
DMZ zone. What are two reasons for this problem? (Choose two.)

PrepAway - Latest Free Exam Questions & Answers

A.
The FTP ALG is disabled.

B.
No security policy exists for traffic from the DMZ zone to the trust zone.

C.
The FTP server has no route back to the local network.

D.
No route is configured to the DMZ network.

6 Comments on “What are two reasons for this problem?

  1. Tom Brady says:

    I cannot figure out what the author is trying to see if we know. The FTP ALG being disabled would not stop you from “connect”ing, the ALG would prevent the data portion of the FTP from connecting. The question does not say “file transfers fail”, it says you cannot connect to the FTP server.

    If it did say file transfers are failing, then A + B would be plausible because you can make active FTP work with ALG disabled by allowing traffic in the reverse direction albeit the security implications.

    For this reason A + B is tempting despite the fact the control connection would actually “connect” which makes A wrong outright imo.

    However to answer the question most accurately based on the selections given, certainly the FTP server not having it’s default route, and the SRX not having a route to the FTP server assuming it’s not directly connected would break the connection.

    In situations like this I go with what I feel is the best answer and not bet against the authors competence. So I’d go with C,D




    0



    0

Leave a Reply