FRM Part II · FRM Exam Part II · Risk Mitigation
A payments bank is drafting its business continuity plan for its card-authorisation service. Which measure defines the maximum amount of data loss, expressed in time, that the bank is prepared to tolerate after a disruption?
The recovery point objective (RPO) is correct. It expresses the maximum tolerable data loss as a time window, such as the last five minutes of transactions. RTO instead measures how quickly the service must be restored, so it does not capture data loss.
- ARecovery time objective (RTO)
- BRecovery point objective (RPO)Correct
- CMaximum tolerable outage
- DMinimum business continuity objective
Explanation
The recovery point objective states how far back in time data must be restorable, so it measures tolerated data loss. RTO is the target time to restore the service, not the amount of data lost. Maximum tolerable outage concerns the longest downtime acceptable.
Did you get it right without looking?
One question tells you little. A timed set on Risk Mitigation shows your real accuracy, how long you take and where you lose marks.
More Risk Mitigation questions
- A bank relies on a single cloud provider for its core trading platform. A risk manager is asked to address concentration risk in this third-…
- A bank's operations team reviews its payment-release process. A single clerk can create a new beneficiary, approve the payment and release f…
- A risk manager is evaluating insurance as an operational risk mitigant and notes that the insurer may take a long time to pay, may dispute c…
- A bank discovers that ransomware has encrypted production servers. Backups exist, but they are stored on the same network domain with the sa…
- A risk manager is evaluating whether buying cyber insurance adequately mitigates a bank's exposure to a major data breach. Which limitation …
- After a ransomware event at a peer firm, a bank reviews its backup design. Which design feature best protects the bank's ability to restore …