Official 2014 Latest Cisco 640-554 Dump Free Download(81-90)!
QUESTION 81
A Cisco ASA appliance has three interfaces configured. The first interface is the inside interface with a security level of 100. The second interface is the DMZ interface with a security level of 50. The third interface is the outside interface with a security level of 0.
By default, without any access list configured, which five types of traffic are permitted? (Choose five.)
A. outbound traffic initiated from the inside to the DMZ
B. outbound traffic initiated from the DMZ to the outside
C. outbound traffic initiated from the inside to the outside
D. inbound traffic initiated from the outside to the DMZ
E. inbound traffic initiated from the outside to the inside
F. inbound traffic initiated from the DMZ to the inside
G. HTTP return traffic originating from the inside network and returning via the outside interface
H. HTTP return traffic originating from the inside network and returning via the DMZ interface
I. HTTP return traffic originating from the DMZ network and returning via the inside interface
J. HTTP return traffic originating from the outside network and returning via the inside interface
Answer: ABCGH
QUESTION 82
Which two protocols enable Cisco Configuration Professional to pull IPS alerts from a Cisco ISR router? (Choose two.)
A. syslog
B. SDEE
C. FTP
D. TFTP
E. SSH
F. HTTPS
Answer: BF
QUESTION 83
Which two functions are required for IPsec operation? (Choose two.)
A. using SHA for encryption
B. using PKI for pre-shared key authentication
C. using IKE to negotiate the SA
D. using AH protocols for encryption and authentication
E. using Diffie-Hellman to establish a shared-secret key
Answer: CE
QUESTION 84
Which statement about disabled signatures when using Cisco IOS IPS is true?
A. They do not take any actions, but do produce alerts.
B. They are not scanned or processed.
C. They still consume router resources.
D. They are considered to be “retired” signatures.
Answer: C
QUESTION 85
Which type of intrusion prevention technology is the primary type used by the Cisco IPS security appliances?
A. profile-based
B. rule-based
C. protocol analysis-based
D. signature-based
E. NetFlow anomaly-based
Answer: D
QUESTION 86
Which two services are provided by IPsec? (Choose two.)
A. Confidentiality
B. Encapsulating Security Payload
C. Data Integrity
D. Authentication Header
E. Internet Key Exchange
Answer: AC
QUESTION 87
Which type of Cisco IOS access control list is identified by 100 to 199 and 2000 to 2699?
A. standard
B. extended
C. named
D. IPv4 for 100 to 199 and IPv6 for 2000 to 2699
Answer: B
QUESTION 88
Which priority is most important when you plan out access control lists?
A. Build ACLs based upon your security policy.
B. Always put the ACL closest to the source of origination.
C. Place deny statements near the top of the ACL to prevent unwanted traffic from passing through the router.
D. Always test ACLs in a small, controlled production environment before you roll it out into the larger
production network.
Answer: A
QUESTION 89
Which step is important to take when implementing secure network management?
A. Implement in-band management whenever possible.
B. Implement telnet for encrypted device management access.
C. Implement SNMP with read/write access for troubleshooting purposes.
D. Synchronize clocks on hosts and devices.
E. Implement management plane protection using routing protocol authentication.
Answer: D
QUESTION 90
Which statement best represents the characteristics of a VLAN?
A. Ports in a VLAN will not share broadcasts amongst physically separate switches.
B. A VLAN can only connect across a LAN within the same building.
C. A VLAN is a logical broadcast domain that can span multiple physical LAN segments.
D. A VLAN provides individual port security.
Answer: C
If you want to pass the Cisco 640-554 Exam sucessfully, recommend to read latest Cisco 640-554 Dump full version.