Aviatrix Certified Engineer (ACE) Program ACE Exam Questions

Page: 1 / 14
Total 72 questions
Question 1

Stateful Firewall rule:

SELECT THE CORRECT ANSWER



Answer : B


Question 2

You can peer AWS TGWS within a Region



Answer : A

You can peer two transit gateways and route traffic between them, which includes IPv4 and IPv6 traffic. To do this, create a peering attachment on your transit gateway, and specify a transit gateway in another AWS Region. The peer transit gateway can be in your account or a different AWS account.


Question 3

Which Aviatrix Controller feature automates the configuration of AWS Transit Gateway, VPC Route Tables, Direct Connect learned routes and Security Domain?



Answer : D

Aviatrix Controller programs all VPC route tables and Transit Gateway route tables so that two Security Domains with a connection policy can communicate with each other automatically with the help of Aviatrix AWS TGW Orchestrator.


Question 4

Customer has an Aviatrix Controller deployed in AW5 and wants to back up the Aviatrix Controller configuration. Where would the backup file be saved?



Answer : A

Aviatrix stores the Controller backup in an AWS S3 bucket or an Azure Container. Before you

begin, determine where you would like to store the backup and create either the S3 bucket or Azure

Container.


Question 5

Which Azure component groups items together for better organization control of a specific workload?



Answer : C


Question 6

In order for a customer to leverage Aviatrix Firenet to orchestrate the deployment and insertion of NGFWs, customers must leverage Aviatrix gateways in the spokes VPC/VNETs in order to program the necessary routing to insert the firewall into the traffic flow?



Answer : A

FireNet is a solution for integrating firewalls in the AWS TGW deployment.

Aer creang Firewall Domain we have to launch Aviatrix FireNet Gateway.

This step leverages the Transit Network workflow to launch one Aviatrix gateway for FireNet deployment.

If you have HA enabled, it automatically sets up the HA gateway for FireNet deployment.

Specify Security Domain for Firewall Inspecon - if you wish to inspect traffic between on-prem to VPC,

connect Aviatrix Edge Domain to the Firewall Domain. This means on-prem traffic to any Spoke VPC is

routed to the firewall first and then it is forwarded to the destination Spoke VPC. Conversely, any Spoke

VPC traffic destined to on-prem is routed to the firewall first and then forwarded to on-prem.


Question 7

What is a challenge of using ExpressRoute Edge Routers as transit to interconnect VNets in Azure?



Answer : D


Page:    1 / 14   
Total 72 questions