mediumMultiple Choice
ISC2 CC Practice Question: Designing a backup strategy for a critical…
You are designing a backup strategy for a critical database. The business requires that in the event of a failure, data loss must not exceed 15 minutes. Which metric primarily addresses this requirement?
⚠ Common exam trap
The trap is confusing RPO with RTO; candidates often mix up the two, but RPO is about data loss (how much data you can afford to lose), while RTO is about downtime (how long you can afford to be down).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Recovery Point Objective (RPO)
Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time. A requirement that data loss must not exceed 15 minutes directly translates to an RPO of 15 minutes. RPO determines how frequently backups or snapshots must be taken to meet the business continuity requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Service Level Agreement (SLA)
Why it's wrong here
An SLA is a contractual service commitment, not a data-loss metric; the stem's 15-minute maximum loss defines recovery point objective, which measures tolerable data loss. It tempts because SLAs often state availability and recovery targets, and an SLA is the correct artefact when defining agreed service expectations with a provider.
- ✗
Mean Time Between Failures (MTBF)
Why it's wrong here
MTBF measures average elapsed time between hardware or component failures, describing reliability rather than how much data is lost during recovery. It is tempting because it quantifies failure frequency, but the 15-minute limit concerns the recovery point objective, which MTBF does not express.
- ✓
Recovery Point Objective (RPO)
Why this is correct
Recovery Point Objective defines the maximum tolerable data loss measured in time, directly satisfying the 15-minute constraint. Because it governs backup frequency, an RPO of 15 minutes or less ensures no more than a quarter-hour of transactions is lost. Recovery Time Objective instead addresses downtime duration, which the stem does not specify.
- ✗
Recovery Time Objective (RTO)
Why it's wrong here
RTO defines how quickly service must be restored after failure, not how much data may be lost. It is tempting because RTO and RPO are the paired recovery metrics, and RTO would be correct if the business instead specified a maximum acceptable downtime.
Go deeper
Related to this question
Learn chapter
Business Continuity and Disaster Recovery
Key term
Business continuity
Business continuity is the capability of an organization to continue delivering essential services during and after a disruptive event.
Key term
Recovery
Recovery is the process of restoring systems, data, and operations after a security incident, failure, or disaster to return to normal functioning.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.