CGRC · Question #89
The point in time to which data must be recovered after an outage. Response:
The correct answer is A. Recovery Point Objective (RPO). The metric that defines the maximum acceptable amount of data loss measured in time, representing the point to which data must be recovered after an outage, is the Recovery Point Objective (RPO).
Question
The point in time to which data must be recovered after an outage. Response:
Options
- ARecovery Point Objective (RPO)
- BActive Security Testing (AST)
- CInternal Security Testing (IST)
- DGeneral Support System (GSS)
How the community answered
(22 responses)- A95% (21)
- D5% (1)
Why each option
The metric that defines the maximum acceptable amount of data loss measured in time, representing the point to which data must be recovered after an outage, is the Recovery Point Objective (RPO).
The Recovery Point Objective (RPO) specifies the maximum allowable amount of data that can be lost from an IT service due to a major incident or disruption. It dictates how far back in time data recovery efforts need to go, meaning if an RPO is 4 hours, data must be recoverable to a state no older than 4 hours before the outage.
Active Security Testing (AST) refers to techniques for testing the security of systems and applications while they are running, unrelated to data recovery timeframes.
Internal Security Testing (IST) is a type of security test conducted from within an organization's network, unrelated to data recovery metrics.
General Support System (GSS) is a categorization of an information system that provides common services, not a recovery objective.
Concept tested: Business continuity and disaster recovery metrics (RPO)
Source: https://csrc.nist.gov/glossary/term/recovery-point-objective
Topics
Community Discussion
No community discussion yet for this question.