ACE 100% Pass Guaranteed Download Aviatrix Certification Exam PDF Q&A [Q28-Q53]

Share

ACE 100% Pass Guaranteed Download Aviatrix Certification Exam PDF Q&A

ACE Practice Test Dumps with 100% Passing Guarantee

NEW QUESTION # 28
When an interface is in Tap mode and a policy action is set to block, the interface will send a TCP reset.

  • A. True
  • B. False

Answer: B


NEW QUESTION # 29
All of the interfaces on a Palo Alto Networks device must be of the same interface type.

  • A. True
  • B. False

Answer: B


NEW QUESTION # 30
As ofPAN-OS 8.0, when configuring a Decryption Policy Rule, which of the following is NOT an available option as matching criteria in the rule?

  • A. Source User
  • B. URL Category
  • C. Source Zone
  • D. Service
  • E. Application

Answer: E


NEW QUESTION # 31
Match the terminology to the appropriate Public Cloud provider.

Answer:

Explanation:


NEW QUESTION # 32
An Outbound SSL forward-proxy decryption rule cannot be created using which type of zone?

  • A. L2
  • B. Tap
  • C. Virtual Wire
  • D. L3

Answer: C


NEW QUESTION # 33
When AWS Direct Connect, Azure ExpressRoute, Google Interconnect and OCI FastConnect are encrypted without using Aviatrix High Performance Encryption, the effective throughput is reduced to____. SELECT THE CORRECT ANSWER

  • A. 10.25 Gbps
  • B. 5.25 Gbps
  • C. 525 Mbps
  • D. 1.25 Gbps

Answer: D

Explanation:
To encrypt this connection, users have the option to create an IPSec Tunnel which limits the throughput to only 1.25Gbps. Standard IPSec encryption in the cloud, or from your data center to the cloud, is limited by a single core processing to 1.25 Gbps.
High Performance Encryption with InsaneMode - Aviatrix Insane mode is integrated into the Transit Network solution to provide 10Gbps performance between on-prem and Transit VPC with encryption. For VPC to VPC, Insane mode can achieve 25 - 30Gbps.


NEW QUESTION # 34
Private, Public, Transit VIFs (Virtual interfaces) are terms related to which...
SELECT THE CORRECT ANSWER

  • A. AWS Transit Gateway
  • B. AWS Virtual Private Gateway (VGW)
  • C. AWS DirectConnect
  • D. Azure ExpressRoute

Answer: C

Explanation:
(AWS Direct Connect virtual interfaces)
You must create one of the following virtual interfaces to begin using your AWS Direct Connect connection.
* Private virtual interface: A private virtual interface should be used to access an Amazon VPC using private IP addresses.
* Public virtual interface: A public virtual interface can access all AWS public services using public IP addresses.
* Transit virtual interface: A transit virtual interface should be used to access one or more Amazon VPC
* Transit Gateways associated with Direct Connect gateways. You can use transit virtual interfaces with 1/2/5/10 Gbps AWS Direct Connect connections. For information about Direct Connect gateway configurations, see Direct Connect gateways.


NEW QUESTION # 35
In order for a customer to leverage Aviatrix Firenet to orchestrate the deployment and insertion of NGFWs, customers must leverage Aviatrix gateways in the spokes VPC/VNETs in order to program the necessary routing to insert the firewall into the traffic flow?

  • A. True
  • B. False

Answer: B

Explanation:
FireNet is a solution for integrating firewalls in the AWS TGW deployment.
* Aoer create Firewall Domain we have to launch Aviatrix FireNet Gateway.
This step leverages the Transit Network workflow to launch one Aviatrix gateway for FireNet deployment.
If you have HA enabled, it automatically sets up the HA gateway for FireNet deployment.
* Specify Security Domain for Firewall Inspeco on - if you wish to inspect traffic between on-prem to VPC, connect Aviatrix Edge Domain to the Firewall Domain. This means on-prem traffic to any Spoke VPC is routed to the firewall first and then it is forwarded to the destination Spoke VPC. Conversely, any Spoke VPC traffic destined to on-prem is routed to the firewall first and then forwarded to on-prem.


NEW QUESTION # 36
Which of the following describes the sequence of the Global Protect agent connecting to a Gateway?

  • A. The agent connects to the portal, obtains a list of gateways, and connects to the gateway with the fastest PING
    response time
  • B. The agent connects to the closest Gateway and sends the HIP report to the portal
  • C. The agent connects to the portal and randomly establishes a connection to the first available gateway
  • D. The Agent connects to the Portal obtains a list of Gateways, and connects to the Gateway with the fastest SSL
    response time

Answer: D


NEW QUESTION # 37
Which of the following are accurate statements describing the HA3 link in an Active-Active HA deployment?

  • A. HA3 is the control link
  • B. The HA3 link is used to transfer Layer 7 information
  • C. HA3 is used to handle asymmetric routing
  • D. HA3 is used for session synchronization

Answer: D


NEW QUESTION # 38
Previous toPAN-OS 8.0the firewall was able to decode up to two levels. WithPAN-OS
8.0the firewall can now decode up to how many levels?

  • A. Five
  • B. Four
  • C. Three
  • D. Six

Answer: B


NEW QUESTION # 39
In PAN-OS 5.0, how is Wildfire enabled?

  • A. Wildfire is automatically enabled with a valid URL-Filtering license
  • B. Via the "Forward" and "Continue and Forward" File-Blocking actions
  • C. A custom file blocking action must be enabled for all PDF and PE type files
  • D. Via the URL-Filtering "Continue" Action.

Answer: B


NEW QUESTION # 40
What is the maximum file size of .EXE files uploaded from the firewall to WildFire?

  • A. Configurable up to 10 megabytes.
  • B. Configurable up to 2 megabytes.
  • C. Always 2 megabytes.
  • D. Always 10 megabytes.

Answer: A


NEW QUESTION # 41
Which one of the options describes the sequence of the GlobalProtect agent connecting to a Gateway?

  • A. The agent connects to the portal and randomly establishes connect to the first available Gateway
  • B. The agent connects to the portal, obtains a list of the Gateways, and connects to the Gateway with the fastest PING response time
  • C. The agent connects to the closest Gateway and sends the HIP report to the portal
  • D. The agent connects to the portal, obtains a list of the Gateways, and connects to the Gateway with the fastest SSL connect time

Answer: B


NEW QUESTION # 42
Which of the following statements is NOT True about Palo Alto Networks firewalls?

  • A. Initial configuration may be accomplished thru the MGT interface or the Console port.
  • B. System defaults may be restored by performing a factory reset in Maintenance Mode.
  • C. The Admin account may not be disabled.
  • D. The Admin account may be disabled.

Answer: D


NEW QUESTION # 43
When a user logs in via Captive Portal, their user information can be checked against:

  • A. Radius
  • B. Terminal Server Agent
  • C. XML API
  • D. Security Logs

Answer: A


NEW QUESTION # 44
Aviatrix Gateways support NAT capability in which public cloud?

  • A. All the the Public Cloud listed here in the options
  • B. Google Cloud
  • C. Microsoft Azure
  • D. AWS

Answer: A


NEW QUESTION # 45
Which two User-ID methods are used to verify known IP address*to*user mappings?
(Choosetwo.)

  • A. Client Probing
  • B. Server Monitoring
  • C. Session Monitoring
  • D. Captive Portal

Answer: A,B


NEW QUESTION # 46
What option should be configured when using User Identification?

  • A. Enable User Identification per Zone
  • B. Enable User Identification per Security Rule
  • C. None of the above
  • D. Enable User Identification per interface

Answer: A


NEW QUESTION # 47
With PAN-OS 5.0, how can a common NTP value be pushed to a cluster of firewalls?

  • A. Via a shared object in Panorama
  • B. Via a Panorama Device Group
  • C. Via a Device Group object in Panorama
  • D. Via a Panorama Template

Answer: A


NEW QUESTION # 48
Aviatrix platform provides rich capabilities around networking, security and operations in public cloud networks. In addition to Aviatrix Transit, it also helps customers overcome limitations of native public cloud constructs. Below, match the Aviatrix platform capability for AWS Transit Gateway (TGW) with the appropriate problem description.

Answer:

Explanation:


NEW QUESTION # 49
When using remote authentication for users (LDAP, RADIUS, Active Directory, etc.), what must be done to allow a user to authenticate through multiple methods?

  • A. This cannot be done. Although multiple authentication methods exist, a firewall must choose a single, global authentication type and all users must use this method.
  • B. This cannot be done. A single user can only use one authentication type.
  • C. Create multiple authentication profiles for the same user.
  • D. Create an Authentication Sequence, dictating the order of authentication profiles.

Answer: D


NEW QUESTION # 50
Which routing protocol is supported on the Palo Alto Networks platform?

  • A. BGP
  • B. RIPv1
  • C. ISIS
  • D. RSTP

Answer: A


NEW QUESTION # 51
Taking into account only the information in the screenshot above, answer the following question. Which applications will be allowed on their standard ports?

  • A. Gnutella
  • B. SSH
  • C. Skype
  • D. BitTorrent

Answer: B,D


NEW QUESTION # 52
A Security policy rule displayed in italic font indicates which condition?

  • A. The rule is disabled.
  • B. The rule has been overridden.
  • C. The rule is active.
  • D. The rule is a clone.

Answer: A


NEW QUESTION # 53
......

ACE PDF Dumps Are Helpful To produce Your Dreams Correct QA's: https://www.prepawaytest.com/Aviatrix/ACE-practice-exam-dumps.html

New ACE exam Free Sample Questions to Practice: https://drive.google.com/open?id=1j7Jcdqq2dtoc4cN7aF5yF4mizFe8wOc-

Contact Us

If you have any question please leave me your email address, we will reply and send email to you in 12 hours.

Our Working Time: ( GMT 0:00-15:00 )
From Monday to Saturday

Support: Contact now