Courseiva
Security OperationseasyMultiple ChoiceObjective-mapped

CISSP Security Operations Practice Question

An organization has a maximum tolerable downtime (MTD) of 8 hours for a critical application. The recovery time objective (RTO) is set to 4 hours. Which of the following best describes the purpose of the RTO?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The time within which IT systems must be restored

RTO defines the maximum time allowed to restore IT services after a disaster, ensuring the MTD is not exceeded.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The total downtime the organization can tolerate

    Why it's wrong here

    This statement accurately describes the Maximum Tolerable Downtime (MTD), also known as Maximum Allowable Outage (MAO). MTD represents the absolute longest period a business process or system can be inoperative before the organization experiences unacceptable consequences, such as severe financial losses, regulatory penalties, or irreparable reputational damage. While MTD sets the ultimate boundary for recovery, the Recovery Time Objective (RTO) is a *target* for restoring services *within* that MTD, making this option incorrect for RTO.

  • The time within which IT systems must be restored

    Why this is correct

    This precisely defines the Recovery Time Objective (RTO). The RTO is a critical metric in business continuity and disaster recovery planning, specifying the maximum acceptable duration for a business process or IT service to be unavailable following an incident before significant business impact occurs. It dictates the target timeframe within which IT infrastructure, applications, and data must be brought back online and fully operational to meet business needs. Achieving the RTO requires careful planning, resource allocation, and robust recovery strategies.

  • The maximum amount of data loss acceptable

    Why it's wrong here

    This statement describes the Recovery Point Objective (RPO), not the RTO. The RPO quantifies the maximum tolerable period in which data might be lost from an IT service due to a major incident or disaster. It determines the necessary frequency of data backups, snapshots, or replication to ensure that, upon recovery, the amount of lost data does not exceed the business's acceptable threshold. Unlike RTO, which focuses on the time to restore *functionality*, RPO specifically addresses the *volume* of data loss.

  • The time required to repair a failed component

    Why it's wrong here

    This statement accurately describes the Mean Time To Repair (MTTR). MTTR is an operational metric that represents the average time it takes to diagnose, repair, and restore a failed system or component to full operational status. It is typically used for hardware or software component reliability and maintenance planning. While MTTR contributes to overall system availability, it focuses on individual component repair rather than the comprehensive restoration of entire business services or IT systems, which is the scope of the RTO.

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.