CISSP Security and Risk Management Practice Question
A company is designing a disaster recovery plan. They need to recover critical systems within 4 hours and lose no more than 15 minutes of data. Which combination of RTO and RPO should be specified?
⚠ Common exam trap
CISSP often tests the classic RTO/RPO swap — candidates who memorize the acronyms but not their definitions reverse them, picking RTO for data loss and RPO for downtime, which is exactly what Option A represents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
RTO = 4 hours, RPO = 15 minutes
RTO (Recovery Time Objective) defines the maximum acceptable downtime — how long until systems are restored — so 4 hours matches the requirement to recover critical systems within 4 hours. RPO (Recovery Point Objective) defines the maximum acceptable data loss measured in time, so 15 minutes matches the requirement to lose no more than 15 minutes of data. Option C is the only pairing that maps each objective to its correct definition.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
RTO = 15 minutes, RPO = 4 hours
Why it's wrong here
The Recovery Time Objective (RTO) of 15 minutes is significantly more aggressive than the assumed 4-hour requirement, potentially incurring unnecessary costs for rapid recovery infrastructure. More critically, the Recovery Point Objective (RPO) of 4 hours indicates an acceptable data loss of up to four hours, which far exceeds the assumed 15-minute data loss tolerance. This configuration fails to meet the critical data integrity requirement, making it an unsuitable disaster recovery strategy.
- ✗
RTO = 4 hours, RPO = 4 hours
Why it's wrong here
While the Recovery Time Objective (RTO) of 4 hours aligns with the assumed maximum acceptable downtime, the Recovery Point Objective (RPO) of 4 hours is unacceptable. An RPO of 4 hours means the organization is prepared to lose up to four hours of data in the event of a disaster. This directly contradicts the assumed requirement for a maximum of 15 minutes of data loss, making this option insufficient for data integrity.
- ✓
RTO = 4 hours, RPO = 15 minutes
Why this is correct
This option correctly defines the Recovery Time Objective (RTO) as the maximum acceptable downtime of 4 hours, meaning services must be restored within this period. Simultaneously, the Recovery Point Objective (RPO) of 15 minutes specifies that the maximum tolerable data loss is 15 minutes, ensuring recent data is preserved. These values precisely align with the assumed business requirements for both service availability and data integrity, making it the optimal disaster recovery strategy.
- ✗
RTO = 15 minutes, RPO = 15 minutes
Why it's wrong here
Although a Recovery Point Objective (RPO) of 15 minutes successfully meets the assumed data loss requirement, the Recovery Time Objective (RTO) of 15 minutes is overly ambitious. While technically satisfying the 4-hour RTO requirement, achieving a 15-minute RTO typically demands highly redundant systems, active-active configurations, or extensive warm/hot standby environments. Such aggressive recovery capabilities often involve substantial additional capital and operational expenditures that are not justified by the assumed 4-hour downtime tolerance, making it economically inefficient.
Go deeper
Related to this question
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.