Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

During a business impact analysis (BIA), the IS auditor identifies that the maximum tolerable downtime (MTD) for an online payment system is 2 hours, and the recovery point objective (RPO) is 15 minutes. The current disaster recovery solution uses nightly backups (12-hour RPO) and can restore the system in 4 hours. Which risk is most critical?

⚠ Common exam trap

The trap here is that candidates focus on the recovery time exceeding the MTD (Option C) because it seems more obvious, but the RPO gap is more critical because data loss has a longer-lasting financial and operational impact than temporary downtime.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Data loss exceeds the RPO.

The current solution has a 12-hour RPO (nightly backups), but the business requires an RPO of 15 minutes. This means up to 11 hours and 45 minutes of transaction data could be lost, far exceeding the acceptable data loss threshold. While the recovery time of 4 hours also exceeds the MTD of 2 hours, the most critical risk is data loss because the gap between the actual RPO and the required RPO is proportionally larger and directly impacts transaction integrity and financial reconciliation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The backup frequency is not aligned with the RPO.

    Why it's wrong here

    This is a restatement of the issue, but the risk is data loss.

  • The disaster recovery plan has not been tested.

    Why it's wrong here

    Testing is important, but the immediate risk is the RPO gap.

  • Recovery time exceeds the MTD.

    Why it's wrong here

    Recovery time of 4 hours exceeds 2-hour MTD, but data loss is more critical.

  • Data loss exceeds the RPO.

    Why this is correct

    The RPO of 15 minutes is not met by 12-hour backups, risking significant data loss.

About these practice questions

Courseiva writes every CISA question from scratch — 995 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.