hardMultiple Choice
ISC2 CC Practice Question: During a disaster recovery test, the recovery…
During a disaster recovery test, the recovery time objective (RTO) for a critical application is 4 hours, but the actual recovery takes 6 hours. Which of the following best describes the impact?
⚠ Common exam trap
ISC2 often tests the distinction between RTO and RPO, and the trap here is confusing the two metrics — candidates may incorrectly associate a recovery time failure with data loss (RPO) instead of availability (RTO).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The application is unavailable for 2 hours longer than acceptable.
The recovery time objective (RTO) defines the maximum acceptable downtime for an application. Since the RTO is 4 hours but the actual recovery took 6 hours, the application was unavailable for 2 hours beyond the acceptable threshold, directly impacting business continuity. This is a failure to meet the RTO, not the RPO, which concerns data loss.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data loss beyond the recovery point objective (RPO).
Why it's wrong here
RPO measures tolerable data loss between the last backup and the failure, not elapsed recovery duration, so a six-hour restore says nothing about data loss. It is tempting because RPO and RTO are the paired metrics in any business impact analysis, and exceeding a target often coincides with data loss; here only the four-hour recovery time was breached.
- ✗
The recovery point objective (RPO) is not met.
Why it's wrong here
RPO concerns how much data can be lost, measured against backup frequency, whereas this test breached the four-hour recovery time target. It is tempting because RPO and RTO are always quoted together in disaster recovery planning, so a failed test invites confusion; the stem gives no data-loss information at all.
- ✓
The application is unavailable for 2 hours longer than acceptable.
Why this is correct
RTO defines the maximum tolerable downtime, so a 6-hour recovery against a 4-hour objective exceeds it by 2 hours. That gap represents unacceptable unavailability for the critical application, directly quantifying the shortfall against the stated objective.
- ✗
No impact because RTO is only a guideline.
Why it's wrong here
An RTO is a committed target derived from business impact analysis, and a two-hour overrun means the critical application was unavailable beyond the agreed window, so impact exists. It is tempting because RTO is not a physical limit and recovery still completed, but treating it as advisory ignores the downtime cost the objective was set to bound.
Go deeper
Related to this question
Learn chapter
Business Continuity and Disaster Recovery
Key term
Business continuity
Business continuity is the capability of an organization to continue delivering essential services during and after a disruptive event.
Key term
RTO
Recovery Time Objective is the maximum acceptable time to restore a system or data after a disaster, defining how quickly normal operations must resume.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An organization wants to ensure that a critical database can be restored within 2 hours after a failure. Which metric should the organization define?
easy- A.Maximum Tolerable Downtime (MTD)
- B.Service Level Agreement (SLA)
- C.Recovery Point Objective (RPO)
- ✓ D.Recovery Time Objective (RTO)
Why D: Recovery Time Objective (RTO) defines the maximum acceptable time to restore a system or service after a disruption. A requirement to restore a critical database within 2 hours is exactly an RTO. RTO drives backup, replication, and failover design decisions.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.