ACE Exam Question 6
ACE Inc. has 50 VPCs in AWS with applications that need access to SaaS services on the internet using pre-defined.
FQDNs. Current deployment has AWS NAT instances deployed that allow full internet access.
ACE Inc.'s security team has mandated that these applications should only be allowed access to pre-approved FQDNs.
You have been tasked to solve this problem considering the following three goals.
1. Solution must be easy to implement
2. Same URLs definitions can be used for multiple applications
3. Keep the cost down
FQDNs. Current deployment has AWS NAT instances deployed that allow full internet access.
ACE Inc.'s security team has mandated that these applications should only be allowed access to pre-approved FQDNs.
You have been tasked to solve this problem considering the following three goals.
1. Solution must be easy to implement
2. Same URLs definitions can be used for multiple applications
3. Keep the cost down
ACE Exam Question 7
What is the maximum file size of .EXE files uploaded from the firewall to WildFire?
ACE Exam Question 8
When AWS Direct Connect, Azure ExpressRoute, Google Interconnect and OCI FastConnect are encrypted without using Aviatrix High Performance Encryption, the effective throughput is reduced to____. SELECT THE CORRECT ANSWER
ACE Exam Question 9
Which of the following interface types can have an IP address assigned to it? (Select all correct answers.)
ACE Exam Question 10
ACE Inc. is currently using AWS Transit Gateway (TGW) with 100 VPCs attached to it from different security domains.
These 100 VPCs are used as following:
* 20 VPCs belong to Production,
* 40 VPCs belong to Development,
* 20 are part of UAT and
* 20 VPCs are for shared services and miscellanous common needs.
ACE Inc. requirements are to:
* provide network and traffic segmentation between Prod, Development, UAT VPCs such that there is no traffic between VPCs belonging to different domains
* allow all VPCs in each domain to communicate with each other
* allow every VPC access to shared services VPCs
Which Aviatrix feature would help to not only provide this segmentation but also decrease the complexity of this topology and routing configuration by orchestrating life-cycle management of AWS Transit Gateways?
(Choose 2)
These 100 VPCs are used as following:
* 20 VPCs belong to Production,
* 40 VPCs belong to Development,
* 20 are part of UAT and
* 20 VPCs are for shared services and miscellanous common needs.
ACE Inc. requirements are to:
* provide network and traffic segmentation between Prod, Development, UAT VPCs such that there is no traffic between VPCs belonging to different domains
* allow all VPCs in each domain to communicate with each other
* allow every VPC access to shared services VPCs
Which Aviatrix feature would help to not only provide this segmentation but also decrease the complexity of this topology and routing configuration by orchestrating life-cycle management of AWS Transit Gateways?
(Choose 2)
