Courseiva

CISSP Security and Risk Management Practice Question

During a business impact analysis (BIA), which metric represents the maximum amount of time a business process can be disrupted before causing significant harm to the organization?

⚠ Common exam trap

CISSP often tests the confusion between business-driven MTPD and technology-driven RTO, tricking candidates into selecting RTO because it sounds like the 'maximum time' a system can be down.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Maximum Tolerable Period of Disruption (MTPD)

The Maximum Tolerable Period of Disruption (MTPD) is the metric defined during a BIA that captures the absolute upper bound of time a business process can be unavailable before the organization suffers unacceptable or significant harm. It is derived from business-side impact analysis (financial, regulatory, reputational) rather than technical recovery capabilities, and it serves as the ceiling from which RTO is derived. Because MTPD represents the business's tolerance limit, it is the correct answer for the maximum disruption time before significant harm.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Work Recovery Time (WRT)

    Why it's wrong here

    Work Recovery Time (WRT) represents the total time required to fully restore all business operations to their normal, pre-incident state, including any manual workarounds or data synchronization. It extends beyond the initial system recovery, focusing on the complete stabilization and return to full productivity. Therefore, WRT is a post-recovery metric, not the maximum period a business can tolerate disruption.

  • ✗

    Recovery Point Objective (RPO)

    Why it's wrong here

    Recovery Point Objective (RPO) defines the maximum acceptable amount of data that can be lost, measured in time, following a disruptive event. It quantifies the permissible data loss window, such as 'no more than 4 hours of data loss,' directly impacting backup and replication strategies. RPO is fundamentally concerned with data integrity and freshness, not the duration of system or process unavailability.

  • ✓

    Maximum Tolerable Period of Disruption (MTPD)

    Why this is correct

    The Maximum Tolerable Period of Disruption (MTPD), also known as Maximum Tolerable Downtime (MTD), is the absolute longest period a business process or function can be inoperative before experiencing unacceptable consequences. This critical metric, determined during a Business Impact Analysis (BIA), establishes the ultimate deadline for recovery, guiding the prioritization of resources and recovery strategies to prevent severe organizational harm.

  • ✗

    Recovery Time Objective (RTO)

    Why it's wrong here

    Recovery Time Objective (RTO) is the targeted duration within which a business process or IT system must be restored to an operational state after an outage to avoid unacceptable consequences. It represents the *goal* for recovery, dictating how quickly systems need to be brought back online. While crucial for planning, RTO is a recovery target, not the absolute maximum period of disruption the business can endure.

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.