ISC2 Certified in Cybersecurity (CC)Security PrinciplesHard

A financial institution is implementing a new system for processing high-value transactions. They have determined that in the event of a system failure, they can tolerate a maximum of 30 minutes of data loss. This specific requirement is known as the:

  1. AService Level Agreement (SLA)
  2. BMaximum Tolerable Downtime (MTD)
  3. CRecovery Point Objective (RPO)
  4. DRecovery Time Objective (RTO)
Show answer & explanation

Correct answer: C. Recovery Point Objective (RPO)

The Recovery Point Objective (RPO) defines the maximum acceptable amount of data that can be lost following a disaster or disruption. A 30-minute data loss tolerance directly corresponds to the RPO.

Why the other options are wrong

  • A. SLA is a contractual agreement defining service expectations, not an internal tolerance for data loss.
  • B. MTD is the total amount of time a system can be unavailable without causing unacceptable harm, encompassing both RTO and the time it takes to recover from data loss.
  • D. RTO is the maximum acceptable period of time for a system to be down after a disaster, not the data loss.

Recovery Point Objective (RPO)

The maximum acceptable amount of data loss measured in time. It defines the point in time to which data must be recovered.

  • Measures data loss tolerance.
  • Expressed in units of time (e.g., 30 minutes, 24 hours).
  • Determines backup frequency.

Memory trick: RTO is 'down-time', RPO is 'data-lost'.

More Security Principles questions