FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks
A payments firm sets a recovery time objective (RTO) of 4 hours and a recovery point objective (RPO) of 15 minutes for its card authorisation system. Backups are replicated to a secondary site every 30 minutes. Which statement is correct?
The 30-minute replication interval is inconsistent with the 15-minute RPO, because the recovery point objective limits tolerable data loss and up to 30 minutes of transactions could be lost. The RTO measures permitted downtime and does not offset this gap.
- AThe replication interval is inconsistent with the RPO, since up to 30 minutes of data could be lostCorrect
- BThe replication interval is consistent with the RPO because the RTO is longer than 30 minutes
- CThe RPO governs how long the system may be offline, so the 4-hour figure is breached
- DThe replication interval is irrelevant because RPO applies only to the RTO
Explanation
RPO is the maximum tolerable data loss measured in time. With 30-minute replication, worst-case loss is 30 minutes, exceeding the 15-minute RPO. RTO concerns downtime, not data loss, so option two and three confuse the two measures.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.
More Case Study: Cyberthreats and Information Security Risks questions
- A bank estimates that a ransomware outage of its trading platform would cost USD 2.0 million per hour in lost revenue for the first 3 hours,…
- A bank experienced a data breach in which attackers exfiltrated customer records over several months. The investigation shows that a known v…
- An analyst at an asset manager discovers that an unauthorised insider changed the settlement account numbers on several pending trade instru…
- A risk manager reviews incident data showing that attackers increasingly compromise a bank's software vendor and use the vendor's trusted up…
- A bank scores three cyber controls on design effectiveness (D) and operating effectiveness (O), each as a percentage of risk reduction, and …
- A risk manager is reviewing the bank's exposure to a malicious insider, such as a database administrator with privileged access. Compared wi…