SYSTEMS SECURITY 2026 QUESTIONS AND
CORRECT ANSWERS A+ STUDY GUIDE
AND EXAM PREP
Which of the following refers to the amount of time it should take for an
organization to recover a resource and bring it back to normal function? -
CORRECT ANSWER-Recovery time objective (RTO)
Which of the following refers to the total collection of possible
vulnerabilities that could provide unauthorized access to computer
resources? - CORRECT ANSWER-Attack surface
Which term describes what a user can do to an object on a computer? -
CORRECT ANSWER-Permissions A backup doesn't guarantee that you'll
be able to recover all the data you've lost, but it does make recovery a
possibility. - CORRECT ANSWER-True
A cloud service provider should meet or exceed the security requirements
you use for your internal network. - CORRECT ANSWER-True
A collection of configuration settings is called a baseline and can take on
many forms. - CORRECT ANSWER-True
, A gateway is a network device that connects two or more separate networks
using different protocols. - CORRECT ANSWER-True
Agile methods encourage developers to plan for security and then test for
security at the end of each sprint. - CORRECT ANSWER-True
Although the TCP/IP and OSI Reference Models are organized differently
in terms of the layers, which layer name (though not necessarily function)
do they share? - CORRECT ANSWER-Got this one wrong... Dont choose
Transport.
Any event that results in a violation of an organization's security policy, or
poses an imminent threat to the security policy, is an incident. - CORRECT
ANSWER-True
A secure application is one that protects the three C-I-A properties of data
security. - CORRECT ANSWER-True
A security policy is a description of how an organization defines a secure
computing environment - CORRECT ANSWER-True
A security strategy that requires multiple controls be compromised to
exploit any vulnerability is referred to as defense in depth. - CORRECT
ANSWER-True