640-554 Exam Details

  • Exam Code
    :640-554
  • Exam Name
    :Implementing Cisco IOS Network Security (IINS v2.0)
  • Certification
    :Cisco Certifications
  • Vendor
    :Cisco
  • Total Questions
    :287 Q&As
  • Last Updated
    :Dec 14, 2021

Cisco 640-554 Online Questions & Answers

  • Question 181:

    Which three statements about the IPsec ESP modes of operation are true? (Choose three.)

    A. Tunnel mode is used between a host and a security gateway.
    B. Tunnel mode is used between two security gateways.
    C. Tunnel mode only encrypts and authenticates the data.
    D. Transport mode authenticates the IP header.
    E. Transport mode leaves the original IP header in the clear.

  • Question 182:

    What does the MD5 algorithm do?

    A. takes a message less than 2^64 bits as input and produces a 160-bit message digest
    B. takes a variable-length message and produces a 168-bit message digest
    C. takes a variable-length message and produces a 128-bit message digest
    D. takes a fixed-length message and produces a 128-bit message digest

  • Question 183:

    Which type of address translation should be used when a Cisco ASA is in transparent mode?

    A. Static NAT
    B. Dynamic NAT
    C. Overload
    D. Dynamic PAT

  • Question 184:

    What is a possible reason for the error message?Router(config)#aaa server?% Unrecognized command

    A. The command syntax requires a space after the word "server"
    B. The command is invalid on the target device
    C. The router is already running the latest operating system
    D. The router is a new device on which the aaa new-model command must be applied before continuing

  • Question 185:

    Which option is a key difference between Cisco IOS interface ACL configurations and Cisco ASA appliance interface ACL configurations?

    A. The Cisco IOS interface ACL has an implicit permit-all rule at the end of each interface ACL.
    B. Cisco IOS supports interface ACL and also global ACL. Global ACL is applied to all interfaces.
    C. The Cisco ASA appliance interface ACL configurations use netmasks instead of wildcard masks.
    D. The Cisco ASA appliance interface ACL also applies to traffic directed to the IP addresses of the Cisco ASA appliance interfaces.
    E. The Cisco ASA appliance does not support standard ACL. The Cisco ASA appliance only support extended ACL.

  • Question 186:

    For what purpose is the Cisco ASA appliance web launch SSL VPN feature used?

    A. to enable split tunneling when using clientless SSL VPN access
    B. to enable users to login to a web portal to download and launch the AnyConnect client
    C. to enable smart tunnel access for applications that are not web-based
    D. to optimize the SSL VPN connections using DTLS
    E. to enable single-sign-on so the SSL VPN users need only log in once

  • Question 187:

    Under which higher-level policy is a VPN security policy categorized?

    A. application policy
    B. DLP policy
    C. remote access policy
    D. compliance policy
    E. corporate WAN policy

  • Question 188:

    Which type of NAT is used where you translate multiple internal IP addresses to a single global, routable IP address?

    A. policy NAT
    B. dynamic PAT
    C. static NAT
    D. dynamic NAT
    E. policy PAT

  • Question 189:

    Refer to the exhibit.

    Using a stateful packet firewall and given an inside ACL entry of permit ip 192.16.1.0 0.0.0.255 any, what would be the resulting dynamically configured ACL for the return traffic on the outside ACL?

    A. permit tcp host 172.16.16.10 eq 80 host 192.168.1.11 eq 2300
    B. permit ip 172.16.16.10 eq 80 192.168.1.0 0.0.0.255 eq 2300
    C. permit tcp any eq 80 host 192.168.1.11 eq 2300
    D. permit ip host 172.16.16.10 eq 80 host 192.168.1.0 0.0.0.255 eq 2300

  • Question 190:

    Which technology provides an automated digital certificate management system for use with IPsec?

    A. ISAKMP
    B. public key infrastructure
    C. Digital Signature Algorithm
    D. Internet Key Exchange

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 640-554 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.