Exit demo 640-554 Implementing Cisco IOS Network Security (IINS v2.0) PDF format · free preview

Cisco 640-554 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/640-554.html

Question 1
Single choice

Which statement about ACL operations is true?

A.

The access list is evaluated in its entirety.

B.

The access list is evaluated one access-control entry at a time.

C.

The access list is evaluated by the most specific entry.

D.

The default explicit deny at the end of an access list causes all packets to be dropped.

Question 2
Multiple choice

Which three statements about access lists are true? (Choose three.)

A.

Extended access lists should be placed as near as possible to the destination.

B.

Extended access lists should be placed as near as possible to the source.

C.

Standard access lists should be placed as near as possible to the destination.

D.

Standard access lists should be placed as near as possible to the source.

E.

Standard access lists filter on the source address.

F.

Standard access lists filter on the destination address.

Question 3
Single choice

Which command configures a device to actively watch connection requests and provide immediate protection from DDoS attacks?

A.

router(config)# ip tcp intercept mode intercept

B.

router(config)# ip tcp intercept mode watch

C.

router(config)# ip tcp intercept max-incomplete high 100

D.

router(config)# ip tcp intercept drop-mode random

Question 4
Single choice

Which command will block external spoofed addresses?

A.

access-list 128 deny ip 10.0.0.0 0.0.255.255 any

B.

access-list 128 deny ip 192.168.0.0 0.0.0.255 any

C.

access-list 128 deny ip 10.0.0.0 0.255.255.255 any

D.

access-list 128 deny ip 192.168.0.0 0.0.31.255 any

Question 5
Multiple choice

Which two countermeasures can mitigate ARP spoofing attacks? (Choose two.)

A.

port security

B.

DHCP snooping

C.

IP source guard

D.

dynamic ARP inspection

Question 6
Single choice

What is the Cisco preferred countermeasure to mitigate CAM overflows?

A.

port security

B.

dynamic port security

C.

IP source guard

D.

root guard

Question 7
Single choice

What is the most common Cisco Discovery Protocol version 1 attack?

A.

denial of service

B.

MAC-address spoofing

C.

CAM-table overflow

D.

VLAN hopping

Question 8
Single choice

Which option describes a function of a virtual VLAN?

A.

A virtual VLAN creates a logically partitioned LAN to place switch ports in a separate broadcast domain.

B.

A virtual VLAN creates trunks and links two switches together.

C.

A virtual VLAN adds every port on a switch to its own collision domain.

D.

A virtual VLAN connects many hubs together.

Question 9
Single choice

Which action can you take to add bandwidth to a trunk between two switches and end up with only one logical interface?

A.

Configure another trunk link.

B.

Configure EtherChannel.

C.

Configure an access port.

D.

Connect a hub between the two switches.

Question 10
Single choice

If the native VLAN on a trunk is different on each end of the link, what is a potential consequence?

A.

The interface on both switches may shut down.

B.

STP loops may occur.

C.

The switch with the higher native VLAN may shut down.

D.

The interface with the lower native VLAN may shut down.

Showing 10 of 287 questions · Unlock the full set