CISA - Information Systems Operations and Business Resilience (26% of the exam) - Section 4.2

Evaluate business impact analysis and system and operational resilience.

Define business impact analysis and explain how it identifies critical processes, determines recovery time objectives (RTO) and recovery point objectives (RPO), and informs resilience strategies. Evaluate system resilience and operational resilience controls to confirm they can sustain or rapidly restore essential services after a disruption.

business impact analysisoperational resiliencesystem resilienceRTO and RPO

Practice question for this objective

Free sampleInformation Systems Operations and Business Resiliencemedium

Which statement about the recovery point objective and the recovery time objective is TRUE for a critical online order-entry application?

  • AThe recovery point objective specifies how long the application can be unavailable, while the recovery time objective specifies the volume of orders that may be lost during the outage.
  • BThe recovery point objective specifies the maximum acceptable data loss measured back from the disruption, while the recovery time objective specifies the maximum acceptable interval before service is restored. Correct
  • CBoth objectives are derived from the disaster recovery test schedule and revised only after a failed test, with no link to the business impact analysis.
  • DThe recovery point objective is always shorter than the recovery time objective because data must be available before applications can be made operable to users.
Define recovery point objective and recovery time objective and explain how each drives different recovery design choices. RPO answers how much data the business can afford to lose, measured backwards from the moment of disruption, and so dictates backup interval and replication mode. RTO answers how long the business can tolerate the service being down, and so dictates the type of recovery site, restoration sequence and resource pre-positioning. They are independent business decisions captured during the BIA.

Why A is wrong: This swaps the definitions, which is the most common candidate error; RPO concerns data loss, not duration of unavailability.

Why B is correct: This is the correct pairing: RPO is a data-currency target driving backup frequency and replication, while RTO is a service-availability target driving recovery infrastructure choices.

Why C is wrong: Tempting because test outcomes can refine plans, but RPO and RTO are derived from the BIA and approved by business owners; test schedules do not set them.

Why D is wrong: RPO can be shorter, equal to, or longer than RTO depending on the process; this option mistakes a sequencing intuition for a definitional rule.

See more CISA practice questions, answers explained.

Exam traps in Information Systems Operations and Business Resilience

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISA bank for this domain.

  • The methodology relies on business-unit self-nomination instead of an independent technical review, so the RTO figures should have been set by the IT recovery team using restore benchmarks.

    Why it is wrong: RTO is fundamentally a business decision driven by impact tolerance; letting IT set it inverts ownership. The flaw is the lack of cross-process consistency, not the use of business input.

  • Treat the test as fully successful because the recovery time objective for the core banking application was met within the documented four-hour window.

    Why it is wrong: Tempting because RTO is the headline metric most operations teams report against, but resilience requires meeting BOTH RTO and RPO, so accepting an RTO pass while ignoring the eleven-hour data loss understates a material control failure.

  • Engage the disaster recovery vendor to recalculate technical recovery times so that the BIA aligns with what the data centre can already deliver in practice.

    Why it is wrong: Tempting because alignment with technical capability sounds prudent, but this reverses the logic: BIA-driven RTOs set the requirement that DR must meet, so anchoring on vendor capacity hides any resilience shortfall instead of surfacing it.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.