easyMultiple SelectObjective-mapped
What Are the Key Components of a Disaster Recovery Plan?
Which TWO of the following are considered key components of a disaster recovery plan?
Quick Answer
RTO is a key component of a disaster recovery plan because it sets the concrete target that every other technical decision in the plan gets built around: the maximum amount of time the organization can tolerate a system being down after a disaster before that downtime itself becomes unacceptable to the business. Everything from failover automation to standby infrastructure capacity gets sized against this number, since a short RTO demands a fundamentally different, and more expensive, recovery architecture than a longer one. It works hand in hand with RPO, the other core metric, which instead defines the maximum acceptable data loss measured as a span of time, essentially how far back the restored data can lag behind the moment of failure. RPO is what dictates backup and replication frequency, since achieving a tight RPO requires backing up or replicating data often enough that no more than that amount of time's worth of data could ever be lost. Together, RTO and RPO translate business tolerance for downtime and data loss into concrete engineering requirements, which is why disaster recovery plans are built around them rather than around vaguer goals like recovering quickly. When a question asks about the fundamental metrics that shape a DR plan's technical design, RTO and RPO are the pair to look for, each addressing a distinct dimension: time down versus data lost.
⚠ Common exam trap
ISC2 often tests the distinction between DR plan components (RPO/RTO) and broader business continuity concepts (BCP) or contractual metrics (SLA), leading candidates to confuse SLA with RTO or think BCP is part of the DR plan itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
RPO (Recovery Point Objective)
RPO and RTO are fundamental metrics in a disaster recovery plan. RPO defines the maximum acceptable data loss measured in time, dictating the frequency of backups. RTO defines the maximum acceptable downtime after a disaster, setting the target for system restoration. Both directly drive the technical design of replication, backup schedules, and failover procedures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SLA (Service Level Agreement)
Why it's wrong here
SLA is a contractual commitment, not a technical DR component.
- ✓
RPO (Recovery Point Objective)
Why this is correct
RPO defines the maximum acceptable data loss in terms of time.
- ✓
RTO (Recovery Time Objective)
Why this is correct
RTO specifies the maximum acceptable downtime after a disaster.
- ✗
BCP (Business Continuity Plan)
Why it's wrong here
BCP is broader and includes disaster recovery but is not a component of the DR plan itself.
- ✗
MTBF (Mean Time Between Failures)
Why it's wrong here
MTBF is a reliability metric for hardware, not a DR plan component.
Go deeper
Related to this question
About these practice questions
One of 920 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO components are essential for an effective disaster recovery plan (DRP)?
easy- A.Automated failover system
- ✓ B.Recovery Point Objective (RPO)
- C.Business Impact Analysis (BIA)
- D.Redundant array of independent disks (RAID)
- ✓ E.Recovery Time Objective (RTO)
Why B: The Recovery Point Objective (RPO) defines the maximum acceptable data loss measured in time, which directly determines the required backup frequency and data replication strategy. Without an RPO, the DRP cannot specify how much data can be lost, making it impossible to design appropriate backup and recovery mechanisms. This metric is essential because it drives the technical implementation of data protection, such as snapshot intervals or synchronous replication.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.