Academy Login

Weekly CISSP Practice

Exam Questions

Week 38 - Question 2

Which of the following is NOT a Business Continuity Planning (BCP) concept?

A. Maximum Tolerable Downtime (MTD)
B. Minimum Required Bandwidth (MRB)
C. Recovery Time Objective (RTO)
D. Recovery Point Objective (RPO)

Answer: B

Explanation:

A. Maximum Tolerable Downtime (MTD)

MTD (sometimes called Maximum Allowable Downtime) is the most critical metric in BCP.

  • The Concept: It represents the absolute maximum time a business function can be inoperable before the organization suffers "irreparable harm."  This harm could be bankruptcy, loss of life, or a complete loss of public trust. 

  •  The Rule: Your RTO must always be less than or equal to your MTD.  If a process must be back in 24 hours (MTD) but your IT team needs 48 hours to fix it (RTO), the plan fails. 

B. Minimum Required Bandwidth (MRB)

MRB is a Networking/Operational term, not a core BCP metric.

  • Why it's the Answer: While an engineer might calculate the bandwidth needed for off-site replication, "Minimum Required Bandwidth" is not a standardized term used to define the business continuity requirements during a Business Impact Analysis (BIA). BCP focuses on time and data, not specific network throughput specifications.

C. Recovery Time Objective (RTO)

RTO is the target time set for the resumption of a product, service, or activity after a disaster.  

  • The Concept: This is the "deadline" for the IT team. It is a subset of the MTD. If the MTD for the payroll system is 3 days, management might set an RTO of 24 hours to ensure there is a "safety buffer."

D. Recovery Point Objective (RPO)

RPO defines the maximum age of files that must be recovered from backup storage for operations to resume.  

  • The Concept: This is essentially a measurement of acceptable data loss.  If you back up your database every night at midnight and a crash happens at 11:00 PM, you have lost 23 hours of data. If your RPO was 4 hours, your current backup strategy is non-compliant.

Podcasts

Check out my weekly podcasts that delve deep into the relevant topics related to each of CISSP domains. In addition, I will go over specific questions and they can be interpreted and answered.

Listen Podcasts

CISSP Cyber Training Academy

Tired of not knowing how to study for the CISSP Exam? 

Check out the CISSP Cyber Training Academy to help you on your journey!

Learn about the Academy!

CISSP Cyber Training - YouTube

Check out my video collection on YouTube discussing all the details needed to help you pass the CISSP exam.   

Check out channel