hardMultiple ChoiceObjective-mapped
ISC2 CC Practice Question: During a disaster recovery test, the recovery…
During a disaster recovery test, the recovery time objective (RTO) for a critical application is 4 hours, but the actual recovery takes 6 hours. Which of the following best describes the impact?
⚠ Common exam trap
ISC2 often tests the distinction between RTO and RPO, and the trap here is confusing the two metrics — candidates may incorrectly associate a recovery time failure with data loss (RPO) instead of availability (RTO).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The application is unavailable for 2 hours longer than acceptable.
The recovery time objective (RTO) defines the maximum acceptable downtime for an application. Since the RTO is 4 hours but the actual recovery took 6 hours, the application was unavailable for 2 hours beyond the acceptable threshold, directly impacting business continuity. This is a failure to meet the RTO, not the RPO, which concerns data loss.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data loss beyond the recovery point objective (RPO).
Why it's wrong here
No information about data loss is provided.
- ✗
The recovery point objective (RPO) is not met.
Why it's wrong here
RPO is about data loss, not recovery time.
- ✓
The application is unavailable for 2 hours longer than acceptable.
Why this is correct
Matches the definition of RTO breach.
- ✗
No impact because RTO is only a guideline.
Why it's wrong here
RTO is a requirement; exceeding it is a failure.
Go deeper
Related to this question
Learn chapter
Business Continuity and Disaster Recovery
Key term
Business continuity
Business continuity is the capability of an organization to continue delivering essential services during and after a disruptive event.
Key term
RTO
Recovery Time Objective is the maximum acceptable time to restore a system or data after a disaster, defining how quickly normal operations must resume.
About these practice questions
This CC question is part of Courseiva's 976-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An organization wants to ensure that a critical database can be restored within 2 hours after a failure. Which metric should the organization define?
easy- A.Maximum Tolerable Downtime (MTD)
- B.Service Level Agreement (SLA)
- C.Recovery Point Objective (RPO)
- ✓ D.Recovery Time Objective (RTO)
Why D: (Recovery Time Objective). RTO defines the maximum acceptable time to restore a system after a failure, which directly aligns with the requirement to restore the database within 2 hours. Option A (MTD) is the total downtime an organization can tolerate, but it is not the specific metric for restoration time; option B (SLA) is a contractual agreement; option C (RPO) deals with data loss, not downtime.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.