Courseiva
Security and Risk ManagementmediumMultiple ChoiceObjective-mapped

CISSP Security and Risk Management Practice Question

During a Business Impact Analysis (BIA), the maximum amount of time a business process can be unavailable before causing significant harm is determined. Which metric represents this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Maximum Tolerable Period of Disruption (MTPD)

Maximum Tolerable Period of Disruption (MTPD) is the longest time a process can be disrupted before recovery is required.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Work Recovery Time (WRT)

    Why it's wrong here

    Work Recovery Time (WRT) measures the duration needed to restore a process to its normal operational state after systems are technically online, not the maximum tolerable downtime before harm occurs. The stem explicitly asks for the metric defining the point at which unavailability causes significant harm, which is Recovery Time Objective (RTO). WRT is tempting because it is also a time-based BIA metric, and in a scenario where the question focused on post-restoration catch-up activities rather than total allowable downtime, WRT would be the correct choice.

  • Maximum Tolerable Period of Disruption (MTPD)

    Why this is correct

    The Maximum Tolerable Period of Disruption (MTPD) represents the absolute longest time a business process or function can be inoperative before the organization experiences unacceptable consequences, such as significant financial loss, regulatory penalties, or irreparable reputational damage. It is a critical business-driven metric established during the BIA, defining the ultimate threshold for downtime that the business can endure without suffering severe harm. All recovery objectives, including RTO, must be set to ensure MTPD is not exceeded.

  • Recovery Point Objective (RPO)

    Why it's wrong here

    The Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss, measured in time, that an organization can tolerate following a disruption. It specifies the point in time to which data must be recovered, meaning any data created or modified after this point is considered lost. RPO is focused on data integrity and availability, not the total duration of system or process unavailability, making it distinct from the overall disruption period.

  • Recovery Time Objective (RTO)

    Why it's wrong here

    The Recovery Time Objective (RTO) is the targeted duration of time within which a business process or system must be restored to an operational state after a disaster or disruption to avoid unacceptable consequences. While RTO is a critical recovery target for technical systems, it represents the *goal* for system restoration, not the *maximum tolerable period* for the entire business function to be down. RTO is typically *less than or equal to* the MTPD, serving as a technical objective to ensure the MTPD is met.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.