FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
A bank's cyber-resilience framework sets a recovery time objective (RTO) for its payment-processing system. Which statement best describes what the RTO represents?
The recovery time objective is the target duration within which a system or service must be restored after a disruption. It is distinct from the recovery point objective, which limits acceptable data loss, and from detection or evidence retention periods.
- AThe maximum amount of data, measured in time, that the bank can afford to lose
- BThe target duration within which the system must be restored after a disruptionCorrect
- CThe time taken to detect that an attack has begun
- DThe period over which forensic evidence must be retained
Explanation
RTO is the targeted time within which a service must be restored after disruption. The maximum tolerable data loss is the recovery point objective (RPO), which is the key distractor. Detection time and evidence retention are separate concepts.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- After a destructive cyberattack, a bank's recovery plan relies on restoring from backups held on the same network as production systems. Whi…
- A global bank's cyber strategy is aligned with the three lines model. The first-line technology team has reported that all controls tested a…
- During a cyber risk self-assessment, a bank's business units rate their own control effectiveness as strong, yet internal audit finds repeat…
- A risk manager wants to test whether the bank's cyber defences and response would hold up against a realistic, targeted attack by a skilled …
- After a significant cyber incident is contained, a firm's CISO proposes a post-incident review. Which outcome of the review is most consiste…
- A bank is deciding how to govern cyber risk. Which arrangement is most consistent with sound cyber-resilience practice?