ISC2 CC Recovery Time Objective (RTO) Practice Question
A financial services company is conducting a Business Impact Analysis (BIA) for its online banking platform. Which THREE of the following are correctly defined metrics used in BIA?
⚠ Common exam trap
The trap is mixing risk-analysis metrics (ALE, SLE, ARO) with BIA recovery metrics (RTO, RPO, MTD) — candidates see 'metric' and pick ALE because it sounds quantitative and important.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Recovery Time Objective (RTO) – the maximum amount of time to restore a business function after a disruption.
Option B is correct because the Recovery Time Objective (RTO) is a core BIA metric defining the maximum acceptable time to restore a business function or process after a disruption before unacceptable consequences occur. Option C is correct because the Maximum Tolerable Downtime (MTD), also called Maximum Acceptable Outage (MAO), defines the total time a business function can be unavailable before causing irreparable harm to the organization, and it typically bounds the RTO. Option E is correct because the Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time, determining the required backup or replication frequency. Option A is not a BIA metric but a contractual service commitment, and Option D is a risk-analysis quantitative value (SLE × ARO) rather than a BIA recovery metric.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Service Level Agreement (SLA) – the contractual uptime percentage guaranteed to customers.
Why it's wrong here
An SLA is a contractual service commitment, not a metric produced by a BIA; BIA defines RTO, RPO and MTD from business impact. It tempts because uptime targets sound impact-related, but SLAs are negotiated externally, whereas BIA derives recovery objectives internally from process criticality.
- ✓
Recovery Time Objective (RTO) – the maximum amount of time to restore a business function after a disruption.
Why this is correct
RTO defines the maximum tolerable downtime before a business function's disruption causes unacceptable impact, so it correctly bounds restoration time for the online banking platform. This matches the BIA metric definition, distinct from RPO, which measures tolerable data loss rather than recovery duration.
- ✓
Maximum Tolerable Downtime (MTD) – the total time a business function can be unavailable before causing irreparable harm.
Why this is correct
Maximum Tolerable Downtime defines the absolute limit a business function may remain unavailable before irreparable harm occurs, making it a core BIA metric. It bounds recovery objectives such as RTO and RPO, directly satisfying the financial platform's need to quantify tolerable outage duration before unacceptable business damage.
- ✗
Annualized Loss Expectancy (ALE) – the expected monetary loss per year from a risk.
Why it's wrong here
ALE is a quantitative risk-management figure (SLE × ARO), not a BIA metric; BIA quantifies outage impact through RTO, RPO, MTD and criticality ratings. It tempts because BIA feeds risk analysis, so monetary loss feels relevant, but ALE belongs to risk assessment, not business impact measurement.
- ✓
Recovery Point Objective (RPO) – the maximum acceptable amount of data loss measured in time.
Why this is correct
RPO defines the maximum tolerable data loss expressed as time, directly satisfying the BIA requirement to quantify recovery metrics for the online banking platform. It sets the restore point target, distinct from RTO, which measures acceptable downtime rather than data loss.
Go deeper
Related to this question
Learn chapter
Risk Management and Security Controls
Key term
RTO
Recovery Time Objective is the maximum acceptable time to restore a system or data after a disaster, defining how quickly normal operations must resume.
Key term
SLE
SLE (Single Loss Expectancy) is the monetary loss expected each time a specific risk event occurs, calculated as asset value times exposure factor.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.