Courseiva
Security and Risk ManagementhardMultiple ChoiceObjective-mapped

CISSP Security and Risk Management Practice Question

A company is designing a disaster recovery plan. They need to recover critical systems within 4 hours and lose no more than 15 minutes of data. Which combination of RTO and RPO should be specified?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

RTO = 4 hours, RPO = 15 minutes

RTO (Recovery Time Objective) is the maximum acceptable downtime, here 4 hours. RPO (Recovery Point Objective) is the maximum acceptable data loss, here 15 minutes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • RTO = 15 minutes, RPO = 4 hours

    Why it's wrong here

    The Recovery Time Objective (RTO) of 15 minutes is significantly more aggressive than the assumed 4-hour requirement, potentially incurring unnecessary costs for rapid recovery infrastructure. More critically, the Recovery Point Objective (RPO) of 4 hours indicates an acceptable data loss of up to four hours, which far exceeds the assumed 15-minute data loss tolerance. This configuration fails to meet the critical data integrity requirement, making it an unsuitable disaster recovery strategy.

  • RTO = 4 hours, RPO = 4 hours

    Why it's wrong here

    While the Recovery Time Objective (RTO) of 4 hours aligns with the assumed maximum acceptable downtime, the Recovery Point Objective (RPO) of 4 hours is unacceptable. An RPO of 4 hours means the organization is prepared to lose up to four hours of data in the event of a disaster. This directly contradicts the assumed requirement for a maximum of 15 minutes of data loss, making this option insufficient for data integrity.

  • RTO = 4 hours, RPO = 15 minutes

    Why this is correct

    This option correctly defines the Recovery Time Objective (RTO) as the maximum acceptable downtime of 4 hours, meaning services must be restored within this period. Simultaneously, the Recovery Point Objective (RPO) of 15 minutes specifies that the maximum tolerable data loss is 15 minutes, ensuring recent data is preserved. These values precisely align with the assumed business requirements for both service availability and data integrity, making it the optimal disaster recovery strategy.

  • RTO = 15 minutes, RPO = 15 minutes

    Why it's wrong here

    Although a Recovery Point Objective (RPO) of 15 minutes successfully meets the assumed data loss requirement, the Recovery Time Objective (RTO) of 15 minutes is overly ambitious. While technically satisfying the 4-hour RTO requirement, achieving a 15-minute RTO typically demands highly redundant systems, active-active configurations, or extensive warm/hot standby environments. Such aggressive recovery capabilities often involve substantial additional capital and operational expenditures that are not justified by the assumed 4-hour downtime tolerance, making it economically inefficient.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.