CRISC Information Technology and Security Practice Question
A risk practitioner is assessing the organization's backup and recovery controls for a critical on-premises database. The recovery time objective (RTO) is four hours and the recovery point objective (RPO) is fifteen minutes. The current design replicates backups nightly to an offsite tape vault. Which finding is MOST significant?
⚠ Common exam trap
The trap here is focusing on operational details like tape shelf life or offsite retrieval delay, when the decisive issue is that nightly backups cannot meet a fifteen-minute RPO.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Nightly backups cannot satisfy the fifteen-minute recovery point objective, so up to a day of data could be lost.
The RPO of fifteen minutes requires that no more than fifteen minutes of data can be lost, which demands frequent replication or continuous data protection. Nightly backups leave up to a full day of transactions at risk, so the design cannot meet the business requirement. This mismatch is the most significant finding and must drive a redesign toward more frequent replication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Tape media have a limited shelf life and may degrade before they are needed for restoration.
Why it's wrong here
Tape degradation is a real concern and requires periodic integrity testing and media rotation, but it is a secondary issue here. The dominant deficiency is the mismatch between nightly backup frequency and the fifteen-minute RPO. Even perfectly preserved tapes would still leave the organization unable to meet its data loss tolerance.
- ✗
The recovery time objective of four hours may be unachievable without a documented disaster recovery test.
Why it's wrong here
Testing is essential to validate that recovery can be performed within the RTO, and the absence of testing is a legitimate gap. However, the design already fails the RPO requirement by a wide margin, which is a more fundamental and certain deficiency than an untested but potentially achievable RTO. The RPO mismatch should be addressed first.
- ✓
Nightly backups cannot satisfy the fifteen-minute recovery point objective, so up to a day of data could be lost.
Why this is correct
The RPO defines the maximum tolerable data loss. A nightly backup means the organization could lose up to twenty-four hours of transactions, far exceeding the fifteen-minute RPO. This is the most significant finding because the design fundamentally cannot meet the stated business requirement, exposing the organization to unacceptable data loss in a recovery scenario.
- ✗
The backup media are stored offsite, which introduces a delay in retrieving them during a recovery.
Why it's wrong here
Offsite storage is a sound practice that protects backups from a site-wide disaster. While retrieval does add time, the more fundamental problem is that nightly backups cannot meet a fifteen-minute RPO regardless of where the media are stored. Offsite storage itself is not the primary deficiency in this design.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.