Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

In business continuity planning, a company identifies a critical business process with a maximum tolerable downtime (MTD) of 4 hours. What is the primary purpose of this metric?

⚠ Common exam trap

The trap is confusing MTD with RTO or RPO; candidates must remember that MTD is the business tolerance limit, and RTO is the technical recovery target derived from it — MTD does not define backup frequency (that is RPO).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To determine the recovery time objective (RTO)

The maximum tolerable downtime (MTD) defines the maximum time a business process can be unavailable before unacceptable consequences occur. The recovery time objective (RTO) is derived from the MTD — it is the target time within which the process must be restored, and it must be less than the MTD to provide a safety margin. Therefore, the primary purpose of the MTD is to determine the RTO for the process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To define the backup frequency

    Why it's wrong here

    Backup frequency derives from the recovery point objective, which bounds acceptable data loss, not from MTD. MTD defines how long the process may remain unavailable, driving recovery time objectives and continuity strategies rather than backup scheduling intervals.

  • ✗

    To calculate the mean time between failures (MTBF)

    Why it's wrong here

    MTBF measures average elapsed time between hardware or component failures, derived from reliability data, and says nothing about how long a process may remain unavailable. It would be the correct metric when analysing equipment reliability or planning preventive replacement intervals for infrastructure components.

  • ✗

    To establish service level agreements (SLAs)

    Why it's wrong here

    An MTD of four hours defines the recovery time objective driving continuity and recovery strategies, not contractual service commitments. SLAs specify agreed service levels between provider and customer, so they would be the correct artefact when negotiating availability guarantees, response times or penalties with an external supplier.

  • ✓

    To determine the recovery time objective (RTO)

    Why this is correct

    MTD defines the maximum time a process can be unavailable, and the RTO must be set at or below it to keep downtime tolerable. Deriving the RTO from the 4-hour MTD ensures recovery capabilities align with business tolerance.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.