Hi egawd,
I agree. Because in the flow the SRX does not have any action defined under NAT. It either translates if the traffic matches a rule or it doesnt. The Allow/Deny action comes under the policy. So irrespective of whether you NAT or not the traffic should be denied by your global policy. Let me lab this up.
Regards,
Anand