New 2021 Guaranteed Success with DumpsValid ACE Dumps Aviatrix PDF Questions [Q34-Q59]

Share

New 2021 Guaranteed Success with DumpsValid ACE Dumps Aviatrix PDF Questions

Exceptional Practice To Aviatrix Certified Engineer (ACE) program Pass the First Time

NEW QUESTION 34
In PAN-OS 5.0, which of the following features is supported with regards to IPv6?

  • A. IPSec VPN tunnels
  • B. NAT64
  • C. None of the above
  • D. OSPF

Answer: B

 

NEW QUESTION 35
Which of the following types of protection are available in DoS policy?

  • A. Session Limit, Port Scanning, Host Swapping, UDP Flood
  • B. Session Limit, SYN Flood, UDP Flood
  • C. Session Limit, SYN Flood, Host Swapping, UDP Flood
  • D. Session Limit, SYN Flood, Port Scanning, Host Swapping

Answer: B

 

NEW QUESTION 36
Users can be authenticated serially to multiple authentication servers by configuring:

  • A. A custom Administrator Profile
  • B. Authentication Sequence
  • C. Multiple RADIUS Servers sharing a VSA configuration
  • D. Authentication Profile

Answer: B

 

NEW QUESTION 37
A user complains that they are no longer able to access a needed work application after you have implemented vulnerability and anti-spyware profiles. The user's application uses a unique port. What is the most efficient way to allow the user access to this application?

  • A. In the vulnerability and anti-spyware profiles, create an application exemption for the user's application.
  • B. Create a custom Security rule for this user to access the required application. Do not apply vulnerability and anti-spyware profiles to this rule.
  • C. In the Threat log, locate the event which is blocking access to the user's application and create a IP-based exemption for this user.
  • D. Utilize an Application Override Rule, referencing the custom port utilzed by this application. Application Override rules bypass all Layer 7 inspection, thereby allowing access to this application.

Answer: C

 

NEW QUESTION 38
In an HA configuration, which three functions are associated with the HA1 Control Link?
(Choose three.)

  • A. synchronizing configuration
  • B. synchronizing sessions
  • C. exchanging heartbeats
  • D. exchanging hellos

Answer: A,C,D

 

NEW QUESTION 39
Which three interface types can control or shape network traffic? (Choose three.)

  • A. Tap
  • B. Virtual Wire
  • C. Layer 3
  • D. Layer 2

Answer: A,C,D

 

NEW QUESTION 40
The Threat log records events from which three Security Profiles? (Choose three.)

  • A. Vulnerability Protection
  • B. WildFire Analysis
  • C. URL Filtering
  • D. Anti*Spyware
  • E. Antivirus
  • F. File Blocking

Answer: B,C,E

 

NEW QUESTION 41
The "Drive-By Download" protection feature, under File Blocking profiles in Content-ID, provides:

  • A. Increased speed on downloads of file types that are explicitly enabled.
  • B. The ability to use Authentication Profiles, in order to protect against unwanted downloads.
  • C. Protection against unwanted downloads by showing the user a response page indicating that a file is going to be downloaded.
  • D. Password-protected access to specific file downloads for authorized users.

Answer: C

 

NEW QUESTION 42
An Outbound SSL forward-proxy decryption rule cannot be created using which type of zone?

  • A. L3
  • B. Virtual Wire
  • C. Tap
  • D. L2

Answer: B

 

NEW QUESTION 43
The following can be configured as a next hop in a Static Route:

  • A. A Policy-Based Forwarding Rule
  • B. Virtual Router
  • C. A Dynamic Routing Protocol
  • D. Virtual System

Answer: B

 

NEW QUESTION 44
Which of the following CANNOT use the source user as a match criterion?

  • A. Antivirus Profile
  • B. QoS
  • C. DoS Protection
  • D. Policy Based Forwarding
  • E. Secuirty Policies

Answer: A

 

NEW QUESTION 45
In PANOS 6.0, rule numbers are:

  • A. Numbers that specify the order in which security policies are evaluated.
  • B. Numbers created to be unique identifiers in each firewall's policy database.
  • C. Numbers created to make it easier for users to discuss a complicated or difficult sequence of rules.
  • D. Numbers on a scale of 0 to 99 that specify priorities when two or more rules are in conflict.

Answer: A

 

NEW QUESTION 46
The IPSec tunnels terminating at AWS TGW/VGW, Azure VPN GW, and other native VPN support interconnecting networks with overlapping IP ranges SELECT THE CORRECT ANSWER

  • A. False
  • B. True

Answer: A

 

NEW QUESTION 47
A "Continue" action can be configured on the following Security Profiles:

  • A. URL Filteringn
  • B. URL Filtering and Antivirus
  • C. URL Filtering, File Blocking, and Data Filtering
  • D. URL Filtering and File Blocking

Answer: D

 

NEW QUESTION 48
What is the correct policy to most effectively block Skype?

  • A. Block Skype
  • B. Allow Skype, block Skype-probe
  • C. Block Skype-probe, block Skype
  • D. Allow Skype-probe, block Skype

Answer: B

 

NEW QUESTION 49
Which local interface cannot be assigned to the IKE gateway?

  • A. Loopback
  • B. VLAN
  • C. L3
  • D. Tunnel

Answer: D

 

NEW QUESTION 50
What is the default setting for 'Action' in a Decryption Policy's rule?

  • A. No-decrypt
  • B. None
  • C. Decrypt
  • D. Any

Answer: B

 

NEW QUESTION 51
Which of the following must be configured when deploying User-ID to obtain information from an 802.1x authenticator?

  • A. An Agentless deployment of User-ID, employing only the Palo Alto Networks Firewall
  • B. XML API for User-ID Agent
  • C. Terminal Server Agent
  • D. A User-ID agent, with the "Use for NTLM Authentication" option enabled.

Answer: B

 

NEW QUESTION 52
WildFire analyzes files to determine whether or not they are malicious. When doing so, WildFire will classify the file with an official verdict. This verdict is known as the WildFire Analysis verdict. Choose the three correct classifications as a result of this analysis and classification?

  • A. Safeware
  • B. Grayware
  • C. Spyware
  • D. Benign
  • E. Malware detection
  • F. Adware

Answer: B,D,E

 

NEW QUESTION 53
What is the maximum file size of .EXE files uploaded from the firewall to WildFire?

  • A. Always 10 megabytes.
  • B. Configurable up to 10 megabytes.
  • C. Configurable up to 2 megabytes.
  • D. Always 2 megabytes.

Answer: B

 

NEW QUESTION 54
Which of the following are accurate statements describing the HA3 link in an Active-Active HA deployment?

  • A. HA3 is used for session synchronization
  • B. HA3 is used to handle asymmetric routing
  • C. HA3 is the control link
  • D. The HA3 link is used to transfer Layer 7 information

Answer: A

 

NEW QUESTION 55
Aviatrix platform has several operational features and capabilities built-in to help network engineers perform day to day operational tasks.
Below, match the Aviatrix platform feature with the operational problem it addresses.

Answer:

Explanation:

Explanation

 

NEW QUESTION 56
In PAN-OS 5.0, how is Wildfire enabled?

  • A. Via the URL-Filtering "Continue" Action
  • B. Via the "Forward" and "Continue and Forward" File-Blocking actions
  • C. A custom file blocking action must be enabled for all PDF and PE type files
  • D. Wildfire is automaticaly enabled with a valid URL-Filtering license

Answer: A

 

NEW QUESTION 57
When troubleshooting Phase 1 of an IPSec VPN tunnel, what location will have the most informative logs?

  • A. Responding side, Traffic Logs
  • B. Initiating side, Traffic Logs
  • C. Initiating side, System Logs
  • D. Responding side, System Logs

Answer: D

 

NEW QUESTION 58
A local/enterprise PKI system is required to deploy outbound forward proxy SSL decryption capabilities.

  • A. False
  • B. True

Answer: A

 

NEW QUESTION 59
......

ACE EXAM DUMPS WITH GUARANTEED SUCCESS: https://www.dumpsvalid.com/ACE-still-valid-exam.html

Best Quality Aviatrix ACE Exam Questions: https://drive.google.com/open?id=1x43CoNP8egTNqYbsjCpUiZPYjce-qb56