ISC2 CC Business Continuity, DR & Incident Response Practice Question
Which metric defines the maximum acceptable amount of data loss measured in time?
⚠ Common exam trap
ISC2 often tests the distinction between RPO and RTO, where candidates confuse 'data loss' (RPO) with 'downtime' (RTO); the trap is that both are time-based metrics, but RPO is about how far back in time you can recover data, while RTO is about how long it takes to restore service.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Recovery Point Objective (RPO)
The Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time, typically expressed in seconds, minutes, or hours. It represents the age of the most recent backup or replicated data that must be available to resume operations after a disaster, directly determining the frequency of backups or replication intervals.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Recovery Point Objective (RPO)
Why this is correct
Recovery Point Objective (RPO) specifies the maximum tolerable data loss expressed as elapsed time before an incident, directly satisfying the stem's requirement for a time-measured loss threshold. It determines backup frequency, unlike Recovery Time Objective, which bounds service restoration duration instead.
- ✗
Mean Time Between Failures (MTBF)
Why it's wrong here
MTBF measures average elapsed time between hardware or component failures, so it quantifies reliability rather than tolerable data loss. It is tempting because both metrics are expressed in time units, but MTBF supports availability planning and maintenance scheduling, not the recovery point objective that defines acceptable data loss.
- ✗
Mean Time to Repair (MTTR)
Why it's wrong here
MTTR measures the average time taken to restore a failed component, addressing availability and recovery speed. Recovery Point Objective (RPO) defines the maximum tolerable data loss measured in time, which is the metric the question describes.
- ✗
Recovery Time Objective (RTO)
Why it's wrong here
RTO defines the maximum acceptable time to restore service after disruption, not the tolerable data loss window. It is tempting because both are recovery metrics expressed in time, but RTO governs downtime duration, whereas the recovery point objective governs how much data may be lost.
Go deeper
Related to this question
Learn chapter
Business Continuity and Disaster Recovery
Key term
Business Continuity Planning
Business Continuity Planning is the process of creating a strategy to keep an organization's essential functions running during and after a major disruption.
Key term
Recovery
Recovery is the process of restoring systems, data, and operations after a security incident, failure, or disaster to return to normal functioning.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.