200-201 Security Policies and Procedures Practice Question
A security manager is drafting a service level agreement (SLA) with a cloud service provider. The SLA must specify the maximum acceptable time for the provider to restore service after a disruption. Which metric should the manager include in the SLA to define this requirement?
⚠ Common exam trap
A common mix-up: candidates confuse RTO with RPO or with average repair times like MTTR, which do not define the maximum acceptable restoration time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Recovery Time Objective (RTO)
The Recovery Time Objective (RTO) defines the maximum acceptable time to restore a service after a disruption, making it the correct metric for the SLA. RPO addresses data loss, while MTBF and MTTR are reliability and repair averages, not restoration targets. The manager should specify RTO to ensure the provider meets business continuity requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Mean Time To Repair (MTTR)
Why it's wrong here
MTTR is the average time to repair a failed component, which is a historical metric rather than a target. It does not define the maximum acceptable restoration time in an SLA. The scenario requires a committed objective, not an average. MTTR is related but not the specific metric needed.
- ✗
Mean Time Between Failures (MTBF)
Why it's wrong here
MTBF measures the average time between failures of a system, indicating reliability. It does not specify how quickly service must be restored. While useful for maintenance planning, it does not address the maximum acceptable downtime. Therefore, it is not the appropriate metric for the SLA requirement.
- ✗
Recovery Point Objective (RPO)
Why it's wrong here
RPO defines the maximum acceptable amount of data loss measured in time, not the time to restore service. It answers how much data the organization can afford to lose. The scenario asks for the time to restore service, which is a different metric. Including RPO would not address the restoration time requirement.
- ✓
Recovery Time Objective (RTO)
Why this is correct
RTO is the maximum acceptable time to restore a service after a disruption. It directly defines the target for service restoration, making it the correct metric for the SLA. The manager should specify RTO to ensure the provider commits to a restoration timeframe that meets business needs. This aligns with the scenario's requirement.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.