Hi,
As soon as a packet enters the SRX, the first thing which gets checked is the filter, the security policy comes after checking a few other things :-
http://kb.juniper.net/InfoCenter/index?page=content&id=kb16110&smlogin=true&actp=search
It is always best to drop unnecessary packets on the filter itself rather than dropping them after a few more checks and thus consuming more resources on the SRX.
Firewall filters are the most effective way to ward off attacks with the use of minimal resources on the SRX.
Regards,
Sahil Sharma
---------------------------------------------------
Please mark my solution as accepted if it helped, Kudos are appreciated as well.