Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An IS auditor is reviewing the business impact analysis (BIA) for a financial services company. Which THREE metrics are typically defined in a BIA?

⚠ Common exam trap

A common mix-up: candidates confuse operational metrics like MTBF and MTTR (which are used in IT service management and availability calculations) with the business-focused recovery metrics (RTO, RPO, MTD) that are defined in a BIA, leading them to select options A or B instead of the correct trio.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Recovery point objective (RPO).

The BIA defines the recovery objectives that drive continuity and DR planning: C (Recovery point objective, RPO) specifies the maximum acceptable data loss measured in time before the disruption, determining backup frequency; D (Maximum tolerable downtime, MTD) is the total time a business process can be unavailable before unacceptable impact occurs, and it bounds the recovery strategy; and E (Recovery time objective, RTO) is the target time to restore the process or system after disruption, which must be less than the MTD. These three are business-driven metrics derived from process criticality and impact over time. By contrast, A (MTTR) and B (MTBF) are operational reliability and maintainability metrics of components or systems, not business impact metrics defined in a BIA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Mean time to repair (MTTR).

    Why it's wrong here

    MTTR measures recovery duration after a failure, so it belongs to availability and incident management reporting, not BIA metric definition. It is tempting because recovery timing feels impact-related, yet a BIA defines RTO, RPO and MTD, which set tolerable outage and data-loss thresholds before recovery mechanisms are chosen.

  • ✗

    Mean time between failures (MTBF).

    Why it's wrong here

    MTBF quantifies reliability between hardware failures, an operational maintenance statistic rather than a BIA output. It appears relevant because downtime drives impact, but a BIA instead establishes RTO, RPO and MTD, which express how long an outage or data loss the business can tolerate.

  • ✓

    Recovery point objective (RPO).

    Why this is correct

    RPO defines the maximum tolerable data loss, expressed as time, and directly drives backup frequency. A BIA must record it so recovery strategies align with the financial services company's tolerance for lost transactions, making it one of the three core metrics alongside RTO and MTD.

  • ✓

    Maximum tolerable downtime (MTD).

    Why this is correct

    Maximum tolerable downtime sets the longest period a business process may remain unavailable before unacceptable impact occurs. The BIA derives it from impact over time, and it bounds the recovery strategy chosen for each critical financial process.

  • ✓

    Recovery time objective (RTO).

    Why this is correct

    RTO specifies the target duration within which a disrupted function or system must be restored. The BIA records it to translate business impact into recovery requirements, ensuring restoration priorities and resource commitments remain within the maximum tolerable downtime.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.