640-554 Exam Details

  • Exam Code
    :640-554
  • Exam Name
    :Implementing Cisco IOS Network Security (IINS v2.0)
  • Certification
    :Cisco Certifications
  • Vendor
    :Cisco
  • Total Questions
    :287 Q&As
  • Last Updated
    :Dec 14, 2021

Cisco 640-554 Online Questions & Answers

  • Question 161:

    Which IPsec component takes an input message of arbitrary length and produces a fixed-length output message?

    A. the transform set
    B. the group policy
    C. the hash
    D. the crypto map

  • Question 162:

    If the native VLAN on a trunk is different on each end of the link, what is a potential consequence?

    A. The interface on both switches may shut down.
    B. STP loops may occur.
    C. The switch with the higher native VLAN may shut down.
    D. The interface with the lower native VLAN may shut down.

  • Question 163:

    Which command causes a Layer 2 switch interface to operate as a Layer 3 interface?

    A. no switchport nonnegotiate
    B. switchport
    C. no switchport mode dynamic auto
    D. no switchport

  • Question 164:

    Which option is the most effective placement of an IPS device within the infrastructure?

    A. Inline, behind the internet router and firewall
    B. Inline, before the internet router and firewall
    C. Promiscuously, after the Internet router and before the firewall
    D. Promiscuously, before the Internet router and the firewall

  • Question 165:

    A clientless SSL VPN user who is connecting on a Windows Vista computer is missing the menu option for Remote Desktop Protocol on the portal web page. Which action should you take to begin troubleshooting?

    A. Ensure that the RDP2 plug-in is installed on the VPN gateway
    B. Reboot the VPN gateway
    C. Instruct the user to reconnect to the VPN gateway
    D. Ensure that the RDP plug-in is installed on the VPN gateway

  • Question 166:

    Which two functions are required for IPsec operation? (Choose two.)

    A. using SHA for encryption
    B. using PKI for pre-shared key authentication
    C. using IKE to negotiate the SA
    D. using AH protocols for encryption and authentication
    E. using Diffie-Hellman to establish a shared-secret key

  • Question 167:

    Which Cisco IOS command will verify authentication between a router and a AAA server?

    A. debug aaa authentication
    B. test aaa group
    C. test aaa accounting
    D. aaa new-model

  • Question 168:

    On which protocol number does the authentication header operate?

    A. 06
    B. 47
    C. 50
    D. 51

  • Question 169:

    Which statement is true about configuring access control lists to control Telnet traffic destined to the router itself?

    A. The ACL is applied to the Telnet port with the ip access-group command.
    B. The ACL should be applied to all vty lines in the in direction to prevent an unwanted user from connecting to an unsecured port.
    C. The ACL applied to the vty lines has no in or out option like ACL being applied to an interface.
    D. The ACL must be applied to each vty line individually.

  • Question 170:

    Which options are filtering options used to display SDEE message types? (Choose two.)

    A. stop
    B. none
    C. error
    D. all

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 640-554 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.