Updated PDF (New 2023) Actual Aviatrix ACE Exam Questions [Q37-Q57]

Share

Updated PDF (New 2023) Actual Aviatrix ACE Exam Questions

Verified ACE Exam Dumps PDF [2023] Access using Prep4King

NEW QUESTION # 37
When using remote authentication for users (LDAP, RADIUS, Active Directory, etc.), what must be done to allow a user to authenticate through multiple methods?

  • A. Create an Authentication Sequence, dictating the order of authentication profiles.
  • B. This cannot be done. A single user can only use one authentication type.
  • C. Create multiple authentication profiles for the same user.
  • D. This cannot be done. Although multiple authentication methods exist, a firewall must choose a single, global authentication type and all users must use this method.

Answer: A


NEW QUESTION # 38
Taking into account only the information in the screenshot above, answer the following question. Which applications will be allowed on their standard ports?

  • A. SSH
  • B. BitTorrent
  • C. Gnutella
  • D. Skype

Answer: A,B


NEW QUESTION # 39
Which interface type does NOT require any configuration changes to adjacent network devices?

  • A. Layer 2
  • B. Virtual Wire
  • C. Tap
  • D. Layer 3

Answer: B


NEW QUESTION # 40
Which of the following CANNOT use the source user as a match criterion?

  • A. Antivirus Profile
  • B. QoS
  • C. Secuirty Policies
  • D. Policy Based Forwarding
  • E. DoS Protection

Answer: A


NEW QUESTION # 41
Which of the following platforms supports the Decryption Port Mirror function?

  • A. PA3000
  • B. PA2000
  • C. PA4000
  • D. VMSeries 100

Answer: A


NEW QUESTION # 42
When troubleshooting Phase 1 of an IPSec VPN tunnel, what location will have the most informative logs?

  • A. Responding side, Traffic Logs
  • B. Initiating side, System Logs
  • C. Responding side, System Logs
  • D. Initiating side, Traffic Logs

Answer: C


NEW QUESTION # 43
In PANOS 6.0, rule numbers are:

  • A. Numbers that specify the order in which security policies are evaluated.
  • B. Numbers created to be unique identifiers in each firewall's policy database.
  • C. Numbers on a scale of 0 to 99 that specify priorities when two or more rules are in conflict.
  • D. Numbers created to make it easier for users to discuss a complicated or difficult sequence of rules.

Answer: A


NEW QUESTION # 44
When configuring Security rules based on FQDN objects, which of the following statements are true?

  • A. In order to create FQDN-based objects, you need to manually define a list of associated IP. Up to 10 IP addresses can be configured for each FQDN entry.
  • B. The firewall resolves the FQDN first when the policy is committed, and is refreshed at TTL expiration. The resolution of this FQDN stores up to 10 different IP addresses.
  • C. The firewall resolves the FQDN first when the policy is committed, and is refreshed each time Security rules are evaluated.
  • D. The firewall resolves the FQDN first when the policy is committed, and is refreshed at TTL expiration. There is no limit on the number of IP addresses stored for each resolved FQDN.

Answer: A


NEW QUESTION # 45
A local/enterprise PKI system is required to deploy outbound forward proxy SSL decryption capabilities.

  • A. False
  • B. True

Answer: A


NEW QUESTION # 46
What happens at the point of Threat Prevention license expiration?

  • A. Threat Prevention no longer used; applicable traffic is blocked
  • B. Threat Prevention is no longer used; applicable traffic is allowed
  • C. Threat Prevention no longer used; traffic is allowed or blocked by configuration per Security Rule
  • D. Threat Prevention no longer updated; existing database still effective

Answer: D


NEW QUESTION # 47
After configuring Captive Portal in Layer 3 mode, users in the Trust Zone are not receiving the Captive Portal
authentication page when they launch their web browsers. How can this be corrected?

  • A. Enable "Response Pages" in the Interface Management Profile that is applied to the L3 Interface in the Trust Zone.
  • B. Confirm that Captive Portal Timeout value is not set below 2 seconds
  • C. Ensure that all users in the Trust Zone are using NTLM-capable browsers
  • D. Enable "Redirect " as the Mode type in the Captive Portal Settings

Answer: A,C


NEW QUESTION # 48
Which of the following is NOT a valid option for builtin CLI Admin roles?

  • A. read/write
  • B. superuser
  • C. deviceadmin
  • D. devicereader

Answer: A


NEW QUESTION # 49

Taking into account only the information in the screenshot above, answer the following question:
A span port or a switch is connected to e1/4, but there are no traffic logs.
Which of the following conditions most likely explains this behavior?

  • A. The interface is not assigned an IP address.
  • B. The interface is not up.
  • C. There is no zone assigned to the interface.
  • D. The interface is not assigned a virtual router.

Answer: C


NEW QUESTION # 50
Which three network modes are supported by active/passive HA? (Choose three.)

  • A. Virtual Wire
  • B. Layer 2
  • C. Layer 3
  • D. Tap

Answer: A,B,C


NEW QUESTION # 51
Which of the following objects cannot use User-ID as a match criteria?

  • A. QoS
  • B. None of the above
  • C. Security Policies
  • D. Policy Based Forwarding
  • E. DoS Protection

Answer: B


NEW QUESTION # 52
When allowing an Application in a Security policy on a PAN-OS 5.0 device, would a dependency Application need to
also be enabled if the application does not employ HTTP, SSL, MSRPC, RPC, t.120, RTSP, RTMP, and NETBIOS-SS.

  • A. No
  • B. Yes

Answer: B


NEW QUESTION # 53
Which of the following represents HTTP traffic events that can be used to identify potential Botnets?

  • A. Traffic from users that browse to IP addresses instead of fully-qualified domain names, traffic to domains that have
    been registered in the last 60 days, downloading executable files from unknown URL's, IRC-based Command and
    Control traffic
  • B. Traffic from users that browse to IP addresses instead of fully-qualified domain names, downloading
    W32.Welchia.Worm from a Windows share, traffic to domains that have been registered in the last 30 days,
    downloading executable files from unknown URL's
  • C. Traffic from users that browse to IP addresses instead of fully-qualified domain names, traffic to domains that have
    been registered in the last 30 days.
  • D. Traffic from users that browse to IP addresses instead of fully-qualified domain names, traffic to domains that have
    been registered in the last 60 days, downloading executable files from unknown URL's

Answer: C


NEW QUESTION # 54
Can multiple administrator accounts be configured on a single firewall?

  • A. No
  • B. Yes

Answer: B


NEW QUESTION # 55
Aviatrix platform provides rich capabilities around networking, security and operations in public cloud networks. In addition to Aviatrix Transit, it also helps customers overcome limitations of native public cloud constructs. Below, match the Aviatrix platform capability for AWS Transit Gateway (TGW) with the appropriate problem description.

Answer:

Explanation:


NEW QUESTION # 56
Which link is used by an Active-Passive cluster to synchronize session information?

  • A. The Control Link
  • B. The Uplink
  • C. The Management Link
  • D. The Data Link

Answer: D


NEW QUESTION # 57
......


Aviatrix ACE certification exam is designed to test the skills and knowledge of network professionals in cloud networking. ACE exam covers a wide range of topics, including cloud networking architecture, security, automation, and troubleshooting. ACE exam is designed to be challenging, and it is recommended that candidates have at least two years of experience in cloud networking before attempting the exam.

 

Try Best ACE Exam Questions from Training Expert Prep4King: https://www.prep4king.com/ACE-exam-prep-material.html

Practice Examples and Dumps & Tips for 2023 Latest ACE Valid Tests Dumps: https://drive.google.com/open?id=1jALAKoQwGUM8s31wTrOCOom-mJudrrvi