A. It determines the likelihood of an incident and its cost.
B. It determines the roles and responsibilities for incident responders.
C. It determines the state that systems should be restored to following an incident.
D. It determines how long an organization can tolerate downtime after an incident.
Explanation:
Recovery Time Objective (RTO) defines the maximum acceptable downtime before business operations must be restored. It helps organizations set expectations for recovery speed and prioritize system restoration accordingly.
A (likelihood of an incident and cost) relates to risk assessment, not RTO.
B (roles and responsibilities) falls under incident response planning, not RTO.
C (state of restored systems) is covered by Recovery Point Objective (RPO), not RTO.
Reference: CompTIA Security+ SY0-701 Official Study Guide, Security Program Management and Oversight domain.