SY0-701 Security Program Management and Oversight Practice Question
Exhibit
Business impact analysis excerpt: System A - Payroll Maximum tolerable downtime: 8 hours Recovery time objective: 4 hours Recovery point objective: 1 hour Impact note: regulatory penalties begin after one missed payroll cycle System B - Customer portal Maximum tolerable downtime: 24 hours Recovery time objective: 8 hours Recovery point objective: 15 minutes Impact note: revenue loss approx. $240,000/day System C - Email Maximum tolerable downtime: 72 hours Recovery time objective: 24 hours Recovery point objective: 8 hours System D - Dev test lab Maximum tolerable downtime: 30 days Recovery time objective: 7 days Recovery point objective: 24 hours
Based on the exhibit, which system should be restored first after a total site outage?
⚠ Common exam trap
The trap here is that candidates often prioritize systems based solely on revenue loss or a general assumption (like communication first), ignoring the critical role of MTD and compliance impact in determining restoration order.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Payroll, because it has the shortest maximum tolerable downtime and the strongest compliance impact.
Payroll should be restored first because it has the shortest maximum tolerable downtime (MTD) and the strongest compliance impact. In disaster recovery, systems with the lowest MTD must be prioritized to avoid exceeding the recovery time objective (RTO), and compliance-driven systems like payroll often carry legal or regulatory penalties for extended outages.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Payroll, because it has the shortest maximum tolerable downtime and the strongest compliance impact.
Why this is correct
Payroll must be restored first because its maximum tolerable downtime is only eight hours, which is tighter than every other system listed. The exhibit also notes regulatory penalties if a payroll cycle is missed, making this system both time-sensitive and business-critical. In a recovery sequence, the system with the most restrictive business requirement generally receives priority.
- ✗
Customer portal, because it produces the largest daily revenue loss and has the shortest RPO.
Why it's wrong here
Despite generating the largest daily revenue loss and having the shortest RPO, the customer portal's maximum tolerable downtime is significantly longer than payroll's eight-hour limit. An RPO only defines how much data loss is acceptable, not how quickly services must return, while MTD sets the hard deadline for restoration. Because the portal can survive a lengthier outage without triggering regulatory or contractual consequences, it is not the first system to restore.
- ✗
Email, because restoring communication always takes precedence over all other services.
Why it's wrong here
The claim that communication always outranks other services is a common misconception; in this exhibit, email's allowable outage window is far longer than payroll's, meaning it can wait. Restoring email first would merely support internal coordination, while missing the payroll cycle triggers immediate regulatory penalties and employee impact. Recovery priorities are driven by quantitative MTD and compliance obligations, not by generic operational convenience.
- ✗
Dev test lab, because lower business impact means it is easiest to restore first.
Why it's wrong here
The dev test lab's lower business impact makes it the least urgent, not the easiest or most logical first choice; its MTD is the most lenient, and it has no revenue or compliance exposure. 'Ease of restoration' is irrelevant to prioritization—recovery ordering follows criticality and time sensitivity, with non-production environments typically restored last after core business systems are stabilized. Restoring it first would waste resources that must be devoted to interrupting critical revenue and regulatory processes.
Go deeper
Related to this question
Learn chapter
Business Continuity and Disaster Recovery
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
Key term
Recovery time objective
Recovery time objective (RTO) is the maximum acceptable time that an IT system can be offline after a failure before the business is severely impacted.
About these practice questions
This SY0-701 question is part of Courseiva's 1,030-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.