Updated Dec-2021 Test Engine to Practice ACE Test Questions [Q17-Q35]

Share

Updated Dec-2021 Test Engine to Practice ACE Test Questions

ACE Real Exam Questions Test Engine Dumps Training With 63 Questions


How to study the Aviatrix Certified Engineer (ACE) Exam

Aviatrix provides learning materials and courses on its website to help candidates perpare for the exam. ACE Multi-cloud network training portal provides access to all the associate, professional and design architect level courses. Best practice material is the ACE practice tests that allow complete understanding of the exam format and question types. Follow the links below to access these learning portals and materials. Join the Aviatrix community via the link down below to interact with fellow learners and seniors to help get better understanding by solving queries of each other and by sharing exam resources.

ACE Training Portal Online Course Study Notes Practice Tests Aviatrix Community

 

NEW QUESTION 17
Which of the following statements is NOT True about Palo Alto Networks firewalls?

  • A. System defaults may be restored by performing a factory reset in Maintenance Mode.
  • B. The Admin account may not be disabled.
  • C. The Admin account may be disabled.
  • D. Initial configuration may be accomplished thru the MGT interface or the Console port.

Answer: C

 

NEW QUESTION 18
Operations team has noticed that during the peak working hours, Aviatrix Gateway's throughput utilization stays around 80% of the current instance size. A decision has been made to scale up the instance size to provide more throughput. Which below statement accurately describes instance sizing of Aviatrix Gateways?

  • A. Aviatrix Gateways can scale up and down both
  • B. Aviatrix Gateways can scale down but not scale up
  • C. Aviatrix Gateways instance size has to be chosen at deployment and can't change later
  • D. Aviatrix Gateways can scale up but not scale down

Answer: A

 

NEW QUESTION 19
Choose two statements that best describe Aviatrix UserVPN/OpenVPN service?

  • A. Requires AWS NAT Gateway
  • B. Is limited to one Gateway per VPC/VNET
  • C. Can integrate with Active Directory
  • D. Can integrate with DUO for MFA

Answer: A,D

 

NEW QUESTION 20
Users may be authenticated sequentially to multiple authentication servers by configuring:

  • A. Multiple RADIUS servers sharing a VSA configuration.
  • B. A custom Administrator Profile.
  • C. An Authentication Sequence.
  • D. An Authentication Profile.

Answer: C

 

NEW QUESTION 21
As per the cloud architecture best practices guidelines in Multi-Cloud Network Architecture (MCNA), which component provides a consistent transit available in all regions across all public cloud providers.

  • A. Global Transit Layer
  • B. Cloud Applications Layer
  • C. Cloud Security Layer
  • D. Cloud Operations Layer

Answer: A

 

NEW QUESTION 22
Which of the following interface types can have an IP address assigned to it?

  • A. Virtual Wire
  • B. Layer 3
  • C. Tap
  • D. Layer 2

Answer: B

 

NEW QUESTION 23
Using the API in PAN-OS 6.1, WildFire subscribers can upload up to how many samples per day?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A

 

NEW QUESTION 24
What option should be configured when using User-ID?

  • A. None of the above
  • B. Enable User-ID per Security Policy
  • C. Enable User-ID per interface
  • D. Enable User-ID per zone

Answer: B

 

NEW QUESTION 25

Taking into account only the information in the screenshot above, answer the following question.
An administrator is using SSH on port 3333 and BitTorrent on port 7777.
Which statements are true?

  • A. The BitTorrent traffic will be allowed.
  • B. The BitTorrent traffic will be denied.
  • C. The SSH traffic will be allowed.
  • D. The SSH traffic will be denied.

Answer: B,C

 

NEW QUESTION 26
In an HA configuration, which three functions are associated with the HA1 Control Link?
(Choose three.)

  • A. exchanging hellos
  • B. synchronizing sessions
  • C. exchanging heartbeats
  • D. synchronizing configuration

Answer: A,C,D

 

NEW QUESTION 27
ACE Inc. is currently using AWS Transit Gateway (TGW) with 100 VPCs attached to it from different security domains.
These 100 VPCs are used as following:
* 20 VPCs belong to Production,
* 40 VPCs belong to Development,
* 20 are part of UAT and
* 20 VPCs are for shared services and miscellanous common needs.
ACE Inc. requirements are to:
* provide network and traffic segmentation between Prod, Development, UAT VPCs such that there is no traffic between VPCs belonging to different domains
* allow all VPCs in each domain to communicate with each other
* allow every VPC access to shared services VPCs
Which Aviatrix feature would help to not only provide this segmentation but also decrease the complexity of this topology and routing configuration by orchestrating life-cycle management of AWS Transit Gateways?
(Choose 2)

  • A. Aviatrix Slte-io-Cloud (S2C)
  • B. Aviatrix AWS-TGW Encrypted Peering
  • C. Aviatrix Security Domain
  • D. Aviatrix TGW Orchestrator

Answer: B,C

 

NEW QUESTION 28
Which best describes how Palo Alto Networks firewall rules are applied to a session?

  • A. all matches applied
  • B. first match applied
  • C. last match applied
  • D. most specific match applied

Answer: B

 

NEW QUESTION 29
Which of the following platforms supports the Decryption Port Mirror function?

  • A. PA3000
  • B. VMSeries 100
  • C. PA2000
  • D. PA4000

Answer: A

 

NEW QUESTION 30
In a Destination NAT configuration, the Translated Address field may be populated with either an IP address or an
Address Object.

  • A. False
  • B. True

Answer: B

 

NEW QUESTION 31
In PAN-OS 7.0 which of the available choices serves as an alert warning by defining patterns of suspicious traffic and network anomalies that may indicate a host has been compromised?

  • A. Correlation Objects
  • B. App-ID Signatures
  • C. Custom Signatures
  • D. Command & Control Signatures
  • E. Correlation Events

Answer: C

 

NEW QUESTION 32
To properly configure DOS protection to limit the number of sessions individually from specific source IPs you would configure a DOS Protection rule with the following characteristics:

  • A. Action: Protect, Aggregate Profile with "Resources Protection" configured
  • B. Action: Deny, Classified Profile with "Resources Protection" configured, and Classified Address with
    "source-ip-only" configured
  • C. Action: Deny, Aggregate Profile with "Resources Protection" configured
  • D. Action: Protect, Classified Profile with "Resources Protection" configured, and Classified Address with
    "source-ip-only" configured

Answer: D

 

NEW QUESTION 33
Which of the following interfaces types will have a MAC address?

  • A. Vwire
  • B. Layer 3
  • C. Layer 2
  • D. Tap

Answer: C

 

NEW QUESTION 34
Which of the following fields is not available in DoS policy?

  • A. Service
  • B. Destination Zone
  • C. Application
  • D. Source Zone

Answer: C

 

NEW QUESTION 35
......

ACE Actual Questions Answers PDF 100% Cover Real Exam Questions: https://www.exam-killer.com/ACE-valid-questions.html

ACE Exam questions and answers: https://drive.google.com/open?id=1YUt0D9qwER4iUFKZjiRPbxdsmXYl_QnK