nerdexam
IsacaIsaca

CISA · Question #345

CISA Question #345: Real Exam Question with Answer & Explanation

The correct answer is D: Downtime cost of a disaster. The Recovery Time Objective (RTO) defines the maximum acceptable duration of downtime after a disaster. The primary driver for setting this threshold is the cost of that downtime to the business - revenue loss, regulatory penalties, reputational damage, etc. Offsite backup costs

Submitted by hans_de· Apr 18, 2026Information Systems Operations and Business Resilience

Question

Which of the following is the PRIMARY factor in determining a recovery time objective (RTO)?

Options

  • ACost of offsite backup premises
  • BResponse time of the emergency action plan
  • CCost of testing the business continuity plan (BCP)
  • DDowntime cost of a disaster

Explanation

The Recovery Time Objective (RTO) defines the maximum acceptable duration of downtime after a disaster. The primary driver for setting this threshold is the cost of that downtime to the business - revenue loss, regulatory penalties, reputational damage, etc. Offsite backup costs (A) and BCP testing costs (C) are recovery expenses, not RTO drivers. Emergency action plan response time (B) may influence feasibility but does not determine the objective itself. The business impact of downtime sets the RTO ceiling.

Topics

#Recovery Time Objective (RTO)#Business Continuity Planning (BCP)#Disaster Recovery (DR)#Downtime Cost

Community Discussion

No community discussion yet for this question.

Full CISA PracticeBrowse All CISA Questions