2022 Realistic Verified Free Aviatrix ACE Exam Questions [Q15-Q32]

Share

2022 Realistic Verified Free Aviatrix ACE Exam Questions

ACE Real Exam Questions and Answers FREE

NEW QUESTION 15
Which of the following statements is NOT True regarding a Decryption Mirror interface?

  • A. Can be a member of any VSYS
  • B. Supports SSL inbound
  • C. Requires superuser privilege
  • D. Supports SSL outbound

Answer: A

 

NEW QUESTION 16
ACE Inc. has 50 VPCs in AWS with applications that need access to SaaS services on the internet using pre-defined.
FQDNs. Current deployment has AWS NAT instances deployed that allow full internet access.
ACE Inc.'s security team has mandated that these applications should only be allowed access to pre-approved FQDNs.
You have been tasked to solve this problem considering the following three goals.
1. Solution must be easy to implement
2. Same URLs definitions can be used for multiple applications
3. Keep the cost down

  • A. Deploy a WAF solution
  • B. Deploy a NGFW firewall In each VPC
  • C. Deploy Aviatrix Gateways to perform FQDN filtering
  • D. Configure NAT policies on the AWS NAT instance

Answer: C

 

NEW QUESTION 17
Which fields can be altered in the default Vulnerability Protection Profile?

  • A. None
  • B. Severity
  • C. Category

Answer: A

 

NEW QUESTION 18
What are the connectivity options for customers to access Azure?

  • A. Internet, VPN, ExpressRoute
  • B. Internet, VPN, and DirectConnect
  • C. Internet Only
  • D. VPN and Express Route

Answer: B

 

NEW QUESTION 19
Azure Firewall (native services):
SELECT THE CORRECT ANSWER

  • A. Handles UDR updates and route propagation for all peered spoke VNETs
  • B. By default provides Malware protection, IDS (intrusion Detection) and IPS.....
  • C. Is encrypting the traffic in transit
  • D. Perform Load Balancing and SNAT automatically

Answer: D

Explanation:
Azure Firewall includes the following features:* Built-in high availability
* Availability Zones
* Unrestricted cloud scalability
* Application FQDN filtering rules
* Network traffic filtering rules
* FQDN tags
* Service tags
* Threat intelligence
* Outbound SNAT support
* Inbound DNAT support
* Multiple public IP addresses
* Azure Monitor logging
* Forced tunneling
* Certifications

 

NEW QUESTION 20
An interface in Virtual Wire mode must be assigned an IP address.

  • A. True
  • B. False

Answer: B

 

NEW QUESTION 21
Which of the following types of protection are available in DoS policy?

  • A. Session Limit, SYN Flood, UDP Flood
  • B. Session Limit, SYN Flood, Port Scanning, Host Swapping
  • C. Session Limit, Port Scanning, Host Swapping, UDP Flood
  • D. Session Limit, SYN Flood, Host Swapping, UDP Flood

Answer: A

 

NEW QUESTION 22
Taking into account only the information in the screenshot above, answer the following question. Which applications
will be allowed on their standard ports? (Select all correct answers.)

  • A. SSH
  • B. Gnutella
  • C. BitTorrent
  • D. Skype

Answer: A,C

 

NEW QUESTION 23
What are the benefits gained when the "Enable Passive DNS Monitoring" checkbox is chosen on the firewall? (Select all correct answers.)

  • A. Improved PANDB malware detection.
  • B. Improved malware detection in WildFire.
  • C. Improved BrightCloud malware detection.
  • D. Improved DNSbased C&C signatures.

Answer: A,B,D

 

NEW QUESTION 24
Statefull Firewall rule:

  • A. Alone can easily satisfy the enterprise security needs
  • B. Allows the return traffic implicitly
  • C. Is another name for Azure Active Directory Firewall
  • D. Requires explicit rule for the return traffic

Answer: B

Explanation:
Aviatrix stateful firewall is feature on the Aviatrix gateway. It is a L4 stateful firewall that filters network CIDR, protocol and port on the packet forwarding path.
The stateful firewall allows each individual rule to be defined as Allow, Deny and Force Drop, in addition to a base rule.

 

NEW QUESTION 25
Can the Aviatrix platform help you interconnect VPCs/VNets/VCNs with overlapping IP address ranges?

  • A. No
  • B. Yes, using standard encrypted peering
  • C. Yes, using FiightPath
  • D. Yes, using S2C (Site-to-Cloud)

Answer: D

 

NEW QUESTION 26
When configuring Security rules based on FQDN objects, which of the following statements are true?

  • A. The firewall resolves the FQDN first when the policy is committed, and is refreshed at TTL expiration.
    There is no limit on the number of IP addresses stored for each resolved FQDN.
  • B. The firewall resolves the FQDN first when the policy is committed, and is refreshed each time Security rules are evaluated.
  • C. In order to create FQDN-based objects, you need to manually define a list of associated IP. Up to 10 IP addresses can be configured for each FQDN entry.
  • D. The firewall resolves the FQDN first when the policy is committed, and is refreshed at TTL expiration.
    The resolution of this FQDN stores up to 10 different IP addresses.

Answer: C

 

NEW QUESTION 27
A local/enterprise PKI system is required to deploy outbound forward proxy SSL decryption capabilities.

  • A. True
  • B. False

Answer: B

 

NEW QUESTION 28
What is the maximum file size of .EXE files uploaded from the firewall to WildFire?

  • A. Configurable up to 10 megabytes.
  • B. Configurable up to 2 megabytes.
  • C. Always 10 megabytes.
  • D. Always 2 megabytes.

Answer: A

 

NEW QUESTION 29
Which of the following CANNOT use the source user as a match criterion?

  • A. QoS
  • B. Antivirus Profile
  • C. Secuirty Policies
  • D. DoS Protection
  • E. Policy Based Forwarding

Answer: B

 

NEW QUESTION 30
When creating a Security Policy to allow Facebook in PAN-OS 5.0, how can you be sure that no other web-browsing traffic is permitted?

  • A. Ensure that the Service column is defined as "application-default" for this security rule. This will automatically include the implicit web-browsing application dependency.
  • B. When creating the rule, ensure that web-browsing is added to the same rule. Both applications will be processed by the Security policy, allowing only Facebook to be accessed. Any other applications can be permitted in subsequent rules.
  • C. No other configuration is required on the part of the administrator, since implicit application dependencies will be added automatically.
  • D. Create a subsequent rule which blocks all other traffic

Answer: C

 

NEW QUESTION 31
Administrative Alarms can be enabled for which of the following except?

  • A. Security Policy Tags
  • B. Certificate Expirations
  • C. Traffic Log capacity
  • D. Security Violation Thresholds

Answer: B

 

NEW QUESTION 32
......

Exam Dumps ACE Practice Free Latest Aviatrix Practice Tests: https://testprep.dumpsvalid.com/ACE-brain-dumps.html