ISC2 CC Business Continuity, DR & Incident Response Practice Question
A company's business continuity plan requires a maximum tolerable downtime of 2 hours for the ERP system. The current backup process takes 3 hours to restore. Which of the following is the BEST corrective action?
⚠ Common exam trap
ISC2 often tests the distinction between RTO and RPO, and the trap here is that candidates confuse backup frequency (which affects RPO) with restore speed (which affects RTO), leading them to incorrectly choose Option B.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement synchronous replication
The maximum tolerable downtime (MTD) is 2 hours, but the current restore process takes 3 hours, which exceeds the MTD. Synchronous replication writes data to both primary and secondary storage simultaneously, ensuring that the secondary copy is always current and can be failed over to in seconds or minutes, not hours. This reduces the recovery time objective (RTO) to well under the required 2 hours, directly addressing the gap.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reduce RTO to 1 hour
Why it's wrong here
Reducing RTO to one hour is a target, not a corrective action — it changes no mechanism, so the three-hour restore remains. It tempts because RTO defines the recovery time objective the plan must meet, and setting it below the two-hour MTD would be valid once a faster restore method, such as replication or snapshots, actually delivers that window.
- ✗
Increase backup frequency
Why it's wrong here
Increasing backup frequency shortens the recovery point objective, not the three-hour restore time, so the two-hour maximum tolerable downtime stays unmet. It is tempting because frequent backups genuinely reduce data loss after corruption or ransomware, which is the right fix when the requirement concerns how much data can be lost rather than how long restoration takes.
- ✓
Implement synchronous replication
Why this is correct
Synchronous replication writes to both primary and secondary sites before acknowledging the transaction, giving near-zero data loss and rapid failover within the two-hour recovery time objective. It directly satisfies the maximum tolerable downtime constraint that the three-hour restore breaches.
- ✗
Perform restoration testing quarterly
Why it's wrong here
Quarterly restoration testing validates that backups are recoverable but does nothing to reduce the three-hour restore time, so the two-hour maximum tolerable downtime remains unmet. It is tempting because testing is a genuine continuity control, and it would be the right choice where recovery capability is unproven rather than too slow.
Go deeper
Related to this question
Learn chapter
Business Continuity and Disaster Recovery
Key term
Business continuity
Business continuity is the capability of an organization to continue delivering essential services during and after a disruptive event.
Key term
MTD
MTD (Maximum Tolerable Downtime) is the longest period a business can function without a specific system or service before the damage becomes unacceptable.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.