Courseiva
mediumMultiple Choice

CISA Practice Question: Experiences a critical system failure during…

An organization experiences a critical system failure during non-business hours. The IT team discovers that the last full backup was 48 hours ago, and the incremental backups for the past 24 hours are corrupted. The recovery time objective (RTO) for this system is 4 hours, and the recovery point objective (RPO) is 1 hour. Which of the following is the MOST immediate concern?

⚠ Common exam trap

The trap here is that candidates focus on the RTO (4 hours) as the most urgent metric, overlooking that the RPO violation (data loss of 24+ hours vs. 1-hour tolerance) is a more fundamental and immediate business continuity failure, since lost data cannot be recovered by simply restoring faster.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The data loss may exceed the recovery point objective (RPO)

The RPO of 1 hour means the organization can tolerate losing at most 1 hour of data. With the last full backup 48 hours old and incremental backups for the past 24 hours corrupted, the usable recovery point is at least 24 hours old, resulting in data loss far exceeding the 1-hour RPO. This gap between actual and acceptable data loss is the most immediate concern because it directly violates the business continuity requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The backup schedule should be changed to daily full backups

    Why it's wrong here

    Changing to daily full backups is a forward-looking remediation that cannot restore the corrupted 24 hours of incrementals; the immediate concern is the data-loss gap against the one-hour RPO. Daily fulls would be considered when designing the schedule to reduce dependency on incrementals.

  • ✓

    The data loss may exceed the recovery point objective (RPO)

    Why this is correct

    Corrupted incremental backups mean recovery can only restore data as of the last full backup, 48 hours ago, breaching the one-hour RPO by a wide margin. The four-hour RTO remains achievable; the immediate concern is the volume of unrecoverable transactions, making data loss the priority over restoration speed.

  • ✗

    The root cause of the failure must be determined before recovery

    Why it's wrong here

    Root-cause analysis is a later investigative step; recovery must proceed now from the last valid full backup, and the pressing issue is the 48-hour data-loss exposure against the one-hour RPO. Determining cause first would be right after service is restored.

  • ✗

    The recovery time objective (RTO) of 4 hours will be exceeded

    Why it's wrong here

    Recovery can start immediately from the 48-hour-old full backup, so the four-hour RTO is achievable; the corrupted incrementals instead force restoration to a point 48 hours old, breaching the one-hour RPO by 47 hours. RTO concerns arise when restoration itself cannot finish in time.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.