Courseiva

ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response

After a ransomware attack, the IT team restores systems from backups. The CEO asks how quickly data can be recovered. Which metric addresses the acceptable amount of data loss?

⚠ Common exam trap

The trap is confusing RPO with RTO — both are recovery metrics, but RPO is about data loss (how much data) while RTO is about downtime (how long), and exam questions often swap the phrasing to test whether candidates can distinguish the two.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Recovery Point Objective (RPO)

RPO (Recovery Point Objective) defines the maximum acceptable amount of data loss measured in time — i.e., how far back in time you can afford to lose data. The CEO's question about 'acceptable amount of data loss' maps directly to RPO. RTO, by contrast, addresses how quickly systems must be restored, not how much data can be lost.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Work Recovery Time (WRT)

    Why it's wrong here

    WRT measures time to resume normal business operations after systems are restored, not the volume of data lost. It is tempting because it is a recovery-time metric, but the acceptable data loss window is expressed by Recovery Point Objective (RPO).

  • ✗

    Recovery Time Objective (RTO)

    Why it's wrong here

    RTO defines the maximum acceptable downtime before systems must be operational again, not the volume of data that can be lost. It is tempting because RTO and RPO are both recovery metrics, but RPO specifically sets the acceptable data-loss window measured backwards from the incident.

  • ✗

    Maximum Tolerable Downtime (MTD)

    Why it's wrong here

    MTD defines the total time a business can tolerate an outage before unacceptable harm, not the data loss threshold. It is tempting as a downtime metric, but the acceptable amount of lost data is quantified by Recovery Point Objective (RPO), measured backwards from the incident.

  • ✓

    Recovery Point Objective (RPO)

    Why this is correct

    Recovery Point Objective (RPO) defines the maximum tolerable data loss measured in time, directly answering how much data can be lost between the last backup and the incident. It satisfies the CEO's question about acceptable data loss, unlike Recovery Time Objective, which measures restoration duration.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.