Which Metric Measures How Quickly Systems Must Be Restored After an Attack?
Due to a cyberattack, a company's IT systems were not operational for an extended period of time. The company wants to measure how quickly the systems must be restored in order to minimize business disruption. Which of the following would the company most likely use?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests whether you can separate the two "recovery" metrics — RTO (maximum acceptable downtime) versus RPO (maximum acceptable data loss) — and the trap is that both names sound like a time-to-restore figure.
This SY0-701 question asks which metric defines how quickly IT systems must be restored after a cyberattack to minimize business disruption, and the answer is the recovery time objective (RTO). It contrasts RTO with the recovery point objective, risk appetite, risk tolerance and mean time between failure so you can tell downtime limits apart from data-loss limits.
The most common wrong pick is A (recovery point objective), because candidates associate any metric containing "recovery" with restoration speed; RPO actually measures how much data loss in time is tolerable, not how fast systems must come back online.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Recovery time objective (RTO) is defined as the maximum acceptable amount of time a system, application or process can remain unavailable after a disruption before the business impact becomes unacceptable. The scenario states the systems were down for an extended period and the company now wants to measure "how quickly the systems must be restored," which is exactly the downtime target RTO expresses. RTO is a core element of business continuity and disaster recovery planning, derived from a business impact analysis that weighs customer dissatisfaction, revenue loss, regulatory exposure and reputation damage. As jennyka76 put it, RTO is "a time limit for how long a system, network, computer, or application can be down after a disaster or failure." That framing matches the question's wording about restoring systems to minimize business disruption.
Why the Other Options Are Wrong
A (recovery point objective) is the mirror-image metric: it defines the maximum tolerable data loss measured backward from the incident, which drives backup frequency, not restoration speed. B (risk appetite) is the amount of risk an organization is willing to accept while pursuing its objectives, and C (risk tolerance) is the acceptable deviation from that appetite — neither is expressed as a restoration deadline. E (mean time between failure) is a reliability statistic describing the average interval between failures of a component, so it says nothing about how fast service must be recovered. The one-line distinction from commenter 9149f41 is the cleanest way to remember it: "RPO-maximum acceptable amount of data loss" versus RTO as maximum acceptable downtime.
Community Comment Notes
Every voter selected D, and the explanations are consistent rather than contradictory, so the community record aligns with the analysis above. Anyio's walkthrough states "the maximum acceptable amount of time that IT systems can be offline after a disruption" and correctly lists RPO as the distractor to reject. jennyka76 adds useful context that RTOs are part of disaster recovery and data protection plans and are anchored in business risks such as financial loss and regulatory compliance. No commenter defended A, B, C or E, so there is no dissenting reasoning to weigh against the official answer key.
Official Reference
Exam Strategy
When a stem mentions downtime, outage length or how fast services must return, lock onto RTO; when it mentions losing data, backup windows or points in time, lock onto RPO. Read the verb carefully — "restored" points to time-to-recovery, while "lost data" points to the recovery point. Metric distractors such as MTBF and risk tolerance are usually decoys unless the stem explicitly discusses failure frequency or acceptable risk levels.
Frequently Asked Questions
Why is a recovery point objective (RPO) the wrong metric for restoration speed?
RPO measures the maximum acceptable data loss in time, which drives how often backups run. It does not state how long systems may stay down, so it cannot answer how quickly services must return.
Does risk tolerance define how fast systems must be restored after an attack?
No. Risk tolerance is the acceptable deviation from the organization's risk appetite, a governance concept rather than a downtime target. The restoration-speed target is set by the recovery time objective (RTO).
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →