medium · FRM Part 2 Operational Risk
A global investment bank defines its recovery time objective (RTO) for a critical payment-clearing process as 4 hours. During a cyber stress testing exercise involving a destructive malware scenario, the technical team identifies that while data can be restored from the last immutable backup within 3 hours, the subsequent integrity validation of the database requires an additional 2 hours.
Which of the following statements best describes the resilience posture of this process?
- The process is non-resilient because the recovery time exceeds the impact tolerance.
- The process is resilient because the data restoration component meets the RTO threshold.
- The process is resilient because RPO logic ensures no data is lost during the 5-hour window.
- The process is non-resilient because the recovery point objective has been breached by the validation delay.
Sign up free to see the explanation and track your rank →
More FRM Part 2 Operational Risk practice
- Which of the following describes the 'One Big Loss' principle for heavy-tailed (subexponen
- In the Bow-Tie analysis framework, where do 'Preventive Controls' sit relative to the oper
- A customer consistently deposits $9,800 in cash at three dif… — This behavior is a classic
- The Standardized Measurement Approach (SMA) formula is composed of two primary factors: th
- What is the regulatory treatment for 'Boundary Events' regarding capital requirements unde
- In the Standardized Measurement Approach (SMA), the Business Indicator (BI) serves as a pr
- Under a proper governance framework, 'Model Limitations' must be:
- If the bank had a poor loss history (LC > BIC), what is the impact on its capital?