Which Metric Measures How Quickly Systems Must Be Restored After an Attack?

Answer Correct answer: D — The recovery time objective (RTO) sets the maximum acceptable downtime before a cyberattack outage causes unacceptable business disruption.

Due to a cyberattack, a company's IT systems were not operational for an extended period of time. The company wants to measure how quickly the systems must be restored in order to minimize business disruption. Which of the following would the company most likely use?

  1. Recovery point objective
  2. Risk appetite
  3. Risk tolerance
  4. Recovery time objective Correct Answer
  5. Mean time between failure

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests whether you can separate the two "recovery" metrics — RTO (maximum acceptable downtime) versus RPO (maximum acceptable data loss) — and the trap is that both names sound like a time-to-restore figure.

This SY0-701 question asks which metric defines how quickly IT systems must be restored after a cyberattack to minimize business disruption, and the answer is the recovery time objective (RTO). It contrasts RTO with the recovery point objective, risk appetite, risk tolerance and mean time between failure so you can tell downtime limits apart from data-loss limits.

The most common wrong pick is A (recovery point objective), because candidates associate any metric containing "recovery" with restoration speed; RPO actually measures how much data loss in time is tolerable, not how fast systems must come back online.

Community Discussion (3 comments)

9149f41 👍 1 Selected: D
RPO-maximum acceptable amount of data loss. RTO-maximum acceptable downtime
Anyio 👍 1 Selected: D
The correct answer is: D. Recovery Time Objective (RTO) Explanation: Recovery Time Objective (RTO) refers to the maximum acceptable amount of time that IT systems can be offline after a disruption before it significantly impacts the business. It helps organizations define how quickly systems need to be restored to minimize downtime and business disruption. Other Options: A. Recovery Point Objective (RPO): Refers to the maximum amount of data loss acceptable in terms of time (e.g., last backup point), not how quickly systems must be restored. B. Risk Appetite: Represents the level of risk an organization is willing to accept and does not measure recovery time. C. Risk Tolerance: Refers to the acceptable deviation from the risk appetite but is not specific to system recovery. E. Mean Time Between Failure (MTBF): Measures the average time between system failures and is unrelated to recovery objectives.
jennyka76 👍 2 Selected: D
A recovery time objective (RTO) is a time limit for how long a system, network, computer, or application can be down after a disaster or failure. RTOs are a key part of disaster recovery and data protection plans. They are based on the potential risks and impacts to a business, such as customer dissatisfaction, financial losses, regulatory compliance, and reputation damage.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Recovery time objective (RTO) is defined as the maximum acceptable amount of time a system, application or process can remain unavailable after a disruption before the business impact becomes unacceptable. The scenario states the systems were down for an extended period and the company now wants to measure "how quickly the systems must be restored," which is exactly the downtime target RTO expresses. RTO is a core element of business continuity and disaster recovery planning, derived from a business impact analysis that weighs customer dissatisfaction, revenue loss, regulatory exposure and reputation damage. As jennyka76 put it, RTO is "a time limit for how long a system, network, computer, or application can be down after a disaster or failure." That framing matches the question's wording about restoring systems to minimize business disruption.

Why the Other Options Are Wrong

A (recovery point objective) is the mirror-image metric: it defines the maximum tolerable data loss measured backward from the incident, which drives backup frequency, not restoration speed. B (risk appetite) is the amount of risk an organization is willing to accept while pursuing its objectives, and C (risk tolerance) is the acceptable deviation from that appetite — neither is expressed as a restoration deadline. E (mean time between failure) is a reliability statistic describing the average interval between failures of a component, so it says nothing about how fast service must be recovered. The one-line distinction from commenter 9149f41 is the cleanest way to remember it: "RPO-maximum acceptable amount of data loss" versus RTO as maximum acceptable downtime.

Community Comment Notes

Every voter selected D, and the explanations are consistent rather than contradictory, so the community record aligns with the analysis above. Anyio's walkthrough states "the maximum acceptable amount of time that IT systems can be offline after a disruption" and correctly lists RPO as the distractor to reject. jennyka76 adds useful context that RTOs are part of disaster recovery and data protection plans and are anchored in business risks such as financial loss and regulatory compliance. No commenter defended A, B, C or E, so there is no dissenting reasoning to weigh against the official answer key.

Official Reference

Exam Strategy

When a stem mentions downtime, outage length or how fast services must return, lock onto RTO; when it mentions losing data, backup windows or points in time, lock onto RPO. Read the verb carefully — "restored" points to time-to-recovery, while "lost data" points to the recovery point. Metric distractors such as MTBF and risk tolerance are usually decoys unless the stem explicitly discusses failure frequency or acceptable risk levels.

Frequently Asked Questions

Why is a recovery point objective (RPO) the wrong metric for restoration speed?

RPO measures the maximum acceptable data loss in time, which drives how often backups run. It does not state how long systems may stay down, so it cannot answer how quickly services must return.

Does risk tolerance define how fast systems must be restored after an attack?

No. Risk tolerance is the acceptable deviation from the organization's risk appetite, a governance concept rather than a downtime target. The restoration-speed target is set by the recovery time objective (RTO).

More SY0-701 FAQ →

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide