ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response
After a ransomware attack, the IT team restores systems from backups. The CEO asks how quickly data can be recovered. Which metric addresses the acceptable amount of data loss?
⚠ Common exam trap
The trap is confusing RPO with RTO — both are recovery metrics, but RPO is about data loss (how much data) while RTO is about downtime (how long), and exam questions often swap the phrasing to test whether candidates can distinguish the two.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Recovery Point Objective (RPO)
RPO (Recovery Point Objective) defines the maximum acceptable amount of data loss measured in time — i.e., how far back in time you can afford to lose data. The CEO's question about 'acceptable amount of data loss' maps directly to RPO. RTO, by contrast, addresses how quickly systems must be restored, not how much data can be lost.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Work Recovery Time (WRT)
Why it's wrong here
WRT measures time to resume normal business operations after systems are restored, not the volume of data lost. It is tempting because it is a recovery-time metric, but the acceptable data loss window is expressed by Recovery Point Objective (RPO).
- ✗
Recovery Time Objective (RTO)
Why it's wrong here
RTO defines the maximum acceptable downtime before systems must be operational again, not the volume of data that can be lost. It is tempting because RTO and RPO are both recovery metrics, but RPO specifically sets the acceptable data-loss window measured backwards from the incident.
- ✗
Maximum Tolerable Downtime (MTD)
Why it's wrong here
MTD defines the total time a business can tolerate an outage before unacceptable harm, not the data loss threshold. It is tempting as a downtime metric, but the acceptable amount of lost data is quantified by Recovery Point Objective (RPO), measured backwards from the incident.
- ✓
Recovery Point Objective (RPO)
Why this is correct
Recovery Point Objective (RPO) defines the maximum tolerable data loss measured in time, directly answering how much data can be lost between the last backup and the incident. It satisfies the CEO's question about acceptable data loss, unlike Recovery Time Objective, which measures restoration duration.
Go deeper
Related to this question
Learn chapter
Business Continuity and Disaster Recovery
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
Key term
Business Continuity Planning
Business Continuity Planning is the process of creating a strategy to keep an organization's essential functions running during and after a major disruption.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.