CISA Practice Question: Information Systems Operations and Business Resilience
An IS auditor is reviewing the business impact analysis (BIA) for a financial services company. Which THREE metrics are typically defined in a BIA?
⚠ Common exam trap
A common mix-up: candidates confuse operational metrics like MTBF and MTTR (which are used in IT service management and availability calculations) with the business-focused recovery metrics (RTO, RPO, MTD) that are defined in a BIA, leading them to select options A or B instead of the correct trio.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Recovery point objective (RPO).
The BIA defines the recovery objectives that drive continuity and DR planning: C (Recovery point objective, RPO) specifies the maximum acceptable data loss measured in time before the disruption, determining backup frequency; D (Maximum tolerable downtime, MTD) is the total time a business process can be unavailable before unacceptable impact occurs, and it bounds the recovery strategy; and E (Recovery time objective, RTO) is the target time to restore the process or system after disruption, which must be less than the MTD. These three are business-driven metrics derived from process criticality and impact over time. By contrast, A (MTTR) and B (MTBF) are operational reliability and maintainability metrics of components or systems, not business impact metrics defined in a BIA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Mean time to repair (MTTR).
Why it's wrong here
MTTR measures recovery duration after a failure, so it belongs to availability and incident management reporting, not BIA metric definition. It is tempting because recovery timing feels impact-related, yet a BIA defines RTO, RPO and MTD, which set tolerable outage and data-loss thresholds before recovery mechanisms are chosen.
- ✗
Mean time between failures (MTBF).
Why it's wrong here
MTBF quantifies reliability between hardware failures, an operational maintenance statistic rather than a BIA output. It appears relevant because downtime drives impact, but a BIA instead establishes RTO, RPO and MTD, which express how long an outage or data loss the business can tolerate.
- ✓
Recovery point objective (RPO).
Why this is correct
RPO defines the maximum tolerable data loss, expressed as time, and directly drives backup frequency. A BIA must record it so recovery strategies align with the financial services company's tolerance for lost transactions, making it one of the three core metrics alongside RTO and MTD.
- ✓
Maximum tolerable downtime (MTD).
Why this is correct
Maximum tolerable downtime sets the longest period a business process may remain unavailable before unacceptable impact occurs. The BIA derives it from impact over time, and it bounds the recovery strategy chosen for each critical financial process.
- ✓
Recovery time objective (RTO).
Why this is correct
RTO specifies the target duration within which a disrupted function or system must be restored. The BIA records it to translate business impact into recovery requirements, ensuring restoration priorities and resource commitments remain within the maximum tolerable downtime.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.