CISSP Security and Risk Management Practice Question
A company is designing a disaster recovery plan. They need to recover critical systems within 4 hours and lose no more than 15 minutes of data. Which combination of RTO and RPO should be specified?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
RTO = 4 hours, RPO = 15 minutes
RTO (Recovery Time Objective) is the maximum acceptable downtime, here 4 hours. RPO (Recovery Point Objective) is the maximum acceptable data loss, here 15 minutes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
RTO = 15 minutes, RPO = 4 hours
Why it's wrong here
The Recovery Time Objective (RTO) of 15 minutes is significantly more aggressive than the assumed 4-hour requirement, potentially incurring unnecessary costs for rapid recovery infrastructure. More critically, the Recovery Point Objective (RPO) of 4 hours indicates an acceptable data loss of up to four hours, which far exceeds the assumed 15-minute data loss tolerance. This configuration fails to meet the critical data integrity requirement, making it an unsuitable disaster recovery strategy.
- ✗
RTO = 4 hours, RPO = 4 hours
Why it's wrong here
While the Recovery Time Objective (RTO) of 4 hours aligns with the assumed maximum acceptable downtime, the Recovery Point Objective (RPO) of 4 hours is unacceptable. An RPO of 4 hours means the organization is prepared to lose up to four hours of data in the event of a disaster. This directly contradicts the assumed requirement for a maximum of 15 minutes of data loss, making this option insufficient for data integrity.
- ✓
RTO = 4 hours, RPO = 15 minutes
Why this is correct
This option correctly defines the Recovery Time Objective (RTO) as the maximum acceptable downtime of 4 hours, meaning services must be restored within this period. Simultaneously, the Recovery Point Objective (RPO) of 15 minutes specifies that the maximum tolerable data loss is 15 minutes, ensuring recent data is preserved. These values precisely align with the assumed business requirements for both service availability and data integrity, making it the optimal disaster recovery strategy.
- ✗
RTO = 15 minutes, RPO = 15 minutes
Why it's wrong here
Although a Recovery Point Objective (RPO) of 15 minutes successfully meets the assumed data loss requirement, the Recovery Time Objective (RTO) of 15 minutes is overly ambitious. While technically satisfying the 4-hour RTO requirement, achieving a 15-minute RTO typically demands highly redundant systems, active-active configurations, or extensive warm/hot standby environments. Such aggressive recovery capabilities often involve substantial additional capital and operational expenditures that are not justified by the assumed 4-hour downtime tolerance, making it economically inefficient.
Go deeper
Related to this question
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.