Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 82 pages
Exam (elaborations)

Illinois Security Contractor Licensing Actual Exam And Practice Tests Newest With Complete Questions And Correct Detailed Answers| Brand New Version!

Document preview thumbnail
Preview 4 out of 82 pages

Illinois Security Contractor Licensing Actual Exam And Practice Tests Newest With Complete Questions And Correct Detailed Answers| Brand New Version! A financial organization has adopted a new secure, encrypted document-sharing application to help with its customer loan process. Some important PII needs to be shared across this new platform, but it is getting blocked by the DLP systems. Which of the following actions will BEST allow the PII to be shared with the secure application without compromising the organization's security posture? A. Configure the DLP policies to allow all PII B. Configure the firewall to allow all ports that are used by this application C. Configure the antivirus software to allow the application D. Configure the DLP policies to whitelist this application with the specific PII E. Configure the application to encrypt the PII D. Configure the DLP policies to whitelist this application with the specific PII An auditor is performing an assessment of a security appliance with an embedded OS that was vulnerable during the last two assessments. Which of the following BEST explains the appliance's vulnerable state? A. The system was configured with weak default security settings. B. The device uses weak encryption ciphers. C. The vendor has not supplied a patch for the appliance. D. The appliance requires administrative credentials for the assessment. C. The vendor has not supplied a patch for the appliance. A company's bank has reported that multiple corporate credit cards have been stolen over the past several weeks. The bank has provided the names of the affected cardholders to the company's forensics team to assist in the cyber-incident investigation. An incident responder learns the following information: The timeline of stolen card numbers corresponds closely with affected users making Internetbased purchases from diverse websites via enterprise desktop PCs. All purchase connections were encrypted, and the company uses an SSL inspection proxy for the inspection of encrypted traffic of the hardwired network. Purchases made with corporate cards over the corporate guest WiFi network, where no SSL inspection occurs, were unaffected. Which of the following is the MOST likely root cause? A. HTTPS sessions are being downgraded to insecure cipher suites B. The SSL inspection proxy is feeding events to a compromised SIEM C. The payment providers are insecurely processing credit card charges D. The adversary has not yet established a presence on the guest WiFi network 1 | P a g e C. The payment providers are insecurely processing credit card charges A pharmaceutical sales representative logs on to a laptop and connects to the public WiFi to check emails and update reports. Which of the following would be BEST to prevent other devices on the network from directly accessing the laptop? (Choose two.) A. Trusted Platform Module B. A host-based firewall C. A DLP solution D. Full disk encryption E. A VPN F. Antivirus software A. Trusted Platform Module B. A host-based firewall A company is implementing MFA for all applications that store sensitive data. The IT manager wants MFA to be non-disruptive and user friendly. Which of the following technologies should the IT manager use when implementing MFA? A. One-time passwords B. Email tokens C. Push notifications D. Hardware authentication C. Push notifications The CSIRT is reviewing the lessons learned from a recent incident. A worm was able to spread unhindered throughout the network and infect a large number of computers and servers. Which of the following recommendations would be BEST to mitigate the impacts of a similar incident in the future? A. Install a NIDS device at the boundary. B. Segment the network with firewalls. C. Update all antivirus signatures daily. D. Implement application blacklisting. B. Segment the network with firewalls. A company is adopting a BYOD policy and is looking for a comprehensive solution to protect company information on user devices. Which of the following solutions would BEST support the policy? A. Mobile device management B. Full-device encryption C. Remote wipe D. Biometrics A. Mobile device management A development team employs a practice of bringing all the code changes from multiple team members into the same development project through automation. A tool is utilized to validate the code and track source code through version control. Which of the following BEST describes this process? 2 | P a g e A. Continuous delivery B. Continuous integration C. Continuous validation D. Continuous monitoring B. Continuous integration A cybersecurity administrator needs to add disk redundancy for a critical server. The solution must have a two-drive failure for better fault tolerance. Which of the following RAID levels should the administrator select? A. 0 B. 1 C. 5 D. 6 D. 6 Which of the following BEST explains the reason why a server administrator would place a document named on the desktop of an administrator account on a server? A. The document is a honeyfile and is meant to attract the attention of a cyberintruder. B. The document is a backup file if the system needs to be recovered. C.The document is a standard file that the OS needs to verify the login credentials. D. The document is a keylogger that stores all keystrokes should the account be compromised. A. The document is a honeyfile and is meant to attract the attention of a cyberintruder. A small company that does not have security staff wants to improve its security posture. Which of the following would BEST assist the company? A. MSSP B. SOAR C. IaaS D. PaaS B. SOAR An organization's help desk is flooded with phone calls from users stating hey can no longer access certain websites. The help desk escalates the issue to the security team, as these websites were accessible the previous day. The security analysts run the following command: ipconfig /flushdns, but the issue persists. Finally, an analyst changes the DNS server for an impacted machine, and the issue goes away. Which of the following attacks MOST likely occurred on the original DNS server? A. DNS cache poisoning B. Domain hijacking C. Distributed denial-of-service D. DNS tunneling A. DNS cache poisoning

Content preview

Illinois Security Contractor Licensing Actual
Exam And Practice Tests Newest With
Complete Questions And Correct Detailed
Answers| Brand New Version!
A financial organization has adopted a new secure, encrypted document-sharing
application to help with its customer loan process. Some important PII needs to be
shared across this new platform, but it is getting blocked by the DLP systems. Which of
the following actions will BEST allow the PII to be shared with the secure application
without compromising the organization's
security posture?
A. Configure the DLP policies to allow all PII
B. Configure the firewall to allow all ports that are used by this application
C. Configure the antivirus software to allow the application
D. Configure the DLP policies to whitelist this application with the specific PII
E. Configure the application to encrypt the PII
D. Configure the DLP policies to whitelist this application with the specific PII
An auditor is performing an assessment of a security appliance with an embedded OS
that was vulnerable during the last two assessments. Which of the following BEST
explains the appliance's vulnerable state?
A. The system was configured with weak default security settings.
B. The device uses weak encryption ciphers.
C. The vendor has not supplied a patch for the appliance.
D. The appliance requires administrative credentials for the assessment.
C. The vendor has not supplied a patch for the appliance.
A company's bank has reported that multiple corporate credit cards have been stolen
over the past several weeks. The bank has provided the names of the affected
cardholders to the company's forensics team to assist in the cyber-incident
investigation. An incident responder learns the following information:
The timeline of stolen card numbers corresponds closely with affected users making
Internetbased purchases from diverse websites via enterprise desktop PCs.
All purchase connections were encrypted, and the company uses an SSL inspection
proxy for the inspection of encrypted traffic of the hardwired network.
Purchases made with corporate cards over the corporate guest WiFi network, where no
SSL inspection occurs, were unaffected.
Which of the following is the MOST likely root cause?
A. HTTPS sessions are being downgraded to insecure cipher suites
B. The SSL inspection proxy is feeding events to a compromised SIEM
C. The payment providers are insecurely processing credit card charges
D. The adversary has not yet established a presence on the guest WiFi network


1|Page

,C. The payment providers are insecurely processing credit card charges
A pharmaceutical sales representative logs on to a laptop and connects to the public
WiFi to check emails and update reports. Which of the following would be BEST to
prevent other devices on the network from directly accessing the laptop? (Choose two.)
A. Trusted Platform Module
B. A host-based firewall
C. A DLP solution
D. Full disk encryption
E. A VPN
F. Antivirus software
A. Trusted Platform Module
B. A host-based firewall
A company is implementing MFA for all applications that store sensitive data. The IT
manager wants MFA to be non-disruptive and user friendly. Which of the following
technologies should the IT manager use when implementing MFA?
A. One-time passwords
B. Email tokens
C. Push notifications
D. Hardware authentication
C. Push notifications
The CSIRT is reviewing the lessons learned from a recent incident. A worm was able to
spread unhindered throughout the network and infect a large number of computers and
servers. Which of the following recommendations would be BEST to mitigate the
impacts of a similar incident in the future?
A. Install a NIDS device at the boundary.
B. Segment the network with firewalls.
C. Update all antivirus signatures daily.
D. Implement application blacklisting.
B. Segment the network with firewalls.
A company is adopting a BYOD policy and is looking for a comprehensive solution to
protect company information on user devices. Which of the following solutions would
BEST support the policy?
A. Mobile device management
B. Full-device encryption
C. Remote wipe
D. Biometrics
A. Mobile device management
A development team employs a practice of bringing all the code changes from multiple
team members into the same development project through automation. A tool is utilized
to validate the code and track source code through version control. Which of the
following BEST describes this process?

2|Page

,A. Continuous delivery
B. Continuous integration
C. Continuous validation
D. Continuous monitoring
B. Continuous integration
A cybersecurity administrator needs to add disk redundancy for a critical server. The
solution must have a two-drive failure for better fault tolerance. Which of the following
RAID levels should the administrator select?
A. 0
B. 1
C. 5
D. 6
D. 6
Which of the following BEST explains the reason why a server administrator would
place a document named password.txt on the desktop of an administrator account on a
server?
A. The document is a honeyfile and is meant to attract the attention of a cyberintruder.
B. The document is a backup file if the system needs to be recovered.
C.The document is a standard file that the OS needs to verify the login credentials.
D. The document is a keylogger that stores all keystrokes should the account be
compromised.
A. The document is a honeyfile and is meant to attract the attention of a cyberintruder.
A small company that does not have security staff wants to improve its security posture.
Which of the following would BEST assist the company?
A. MSSP
B. SOAR
C. IaaS
D. PaaS
B. SOAR
An organization's help desk is flooded with phone calls from users stating hey can no
longer access certain websites. The help desk escalates the issue to the security team,
as these websites were accessible the previous day. The security analysts run the
following command: ipconfig /flushdns, but the issue persists. Finally, an analyst
changes the DNS server for an impacted machine, and the issue goes away. Which of
the following attacks MOST likely occurred
on the original DNS server?
A. DNS cache poisoning
B. Domain hijacking
C. Distributed denial-of-service
D. DNS tunneling
A. DNS cache poisoning

3|Page

, A cybersecurity manager has scheduled biannual meetings with the IT team and
department leaders to discuss how they would respond to hypothetical cyberattacks.
During these meetings, the manager presents a scenario and injects additional
information throughout the session to replicate what might occur in a dynamic
cybersecurity event involving the company, its facilities, its
data, and its staff. Which of the following describes what the manager is doing?
A. Developing an incident response plan
B. Building a disaster recovery plan
C. Conducting a tabletop exercise
D. Running a simulation exercise
C. Conducting a tabletop exercise
A RAT that was used to compromise an organization's banking credentials was found
on a user's computer. The RAT evaded antivirus detection. It was installed by a user
who has local administrator rights to the system as part of a remote management tool
set. Which of the following recommendations would BEST prevent this from
reoccurring?
A. Create a new acceptable use policy.
B. Segment the network into trusted and untrusted zones.
C. Enforce application whitelisting.
D. Implement DLP at the network boundary.
C. Enforce application whitelisting.
A security analyst is reviewing a new website that will soon be made publicly available.
The analyst sees the following in the URL:
http://dev-site.comptia.org/home/show.php?sessionID=77276554&loc=us
The analyst then sends an internal user a link to the new website for testing purposes,
and when the user clicks the link, the analyst is able to browse the website with the
following URL:
http://dev-site.comptia.org/home/show.php?sessionID=98988475&loc=us
Which of the following application attacks is being tested?
A. Pass-the-hash
B. Session replay
C. Object deference
D. Cross-site request forgery
B. Session replay
A network administrator has been asked to install an IDS to improve the security
posture of an organization. Which of the following control types is an IDS?
A. Corrective
B. Physical
C. Detective
D. Administrative
C. Detective



4|Page

Document information

Uploaded on
April 3, 2026
Number of pages
82
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$21.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
48
Followers
3
Items
263
Last sold
1 month ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions