Question 160 of 144
SK0-005 security-disaster-recovery Practice Question
A large financial services company must comply with federal regulations mandating quarterly disaster recovery tests. Their primary data center in New York hosts all trading applications, and a hot site in Chicago is maintained with real-time data replication via synchronous mirroring. During the last DR test, the IT team successfully failed over network and storage within 8 minutes, meeting the 15-minute RTO for connectivity. However, they encountered a major issue: the hot site's firewalls, intrusion detection systems, and application-level access controls were not configured to match the primary environment. The security team had to manually create firewall rules, update IDS signatures, and reconfigure access policies based on documentation, which took over 4 hours. As a result, the total system readiness exceeded 4.5 hours, causing a significant gap in trading operations. The regulatory auditor noted this deficiency and required a corrective action plan. The company must ensure that the next DR test achieves full operational readiness, including security controls, within the 15-minute RTO. The IT budget is already allocated for the current fiscal year, so large capital expenditures are not possible, but the team can leverage existing tools and automation. Which of the following is the BEST approach to address this issue?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a configuration management tool that automatically synchronizes firewall rules, IDS signatures, and access controls to the hot site in near real-time.
Option A is correct because implementing a configuration management or synchronization tool directly addresses the root cause—manual configuration—by automating the replication of security policies to the hot site in near real-time. This eliminates human error and delay, meeting the 15-minute RTO without requiring new hardware. Option B (detailed runbooks and drills) still relies on manual interaction, which is unlikely to achieve 15-minute readiness. Option C merely lowers the standard instead of fixing the process and would likely be rejected by regulators. Option D (identical hardware) does not automatically transfer configurations; they would still need to be applied, so it does not solve the time problem.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Develop detailed runbooks for the security team to manually configure devices during failover; then conduct quarterly drills to reduce configuration time.
Why it's wrong here
Even with practice, manually configuring complex security devices within 15 minutes is unrealistic due to the volume of rules and potential for error; human speed cannot match automation.
- ✗
Re-evaluate the RTO to extend it to 4 hours and inform regulators of a realistic capability.
Why it's wrong here
Changing the RTO does not solve the technical deficiency; it merely accepts failure and would likely not satisfy regulatory mandates that require a 15-minute recovery capability.
- ✗
Replace the existing firewalls and IDS at the hot site with identical hardware from the same vendors as the primary site.
Why it's wrong here
Identical hardware alone does not ensure configurations match; the security rules and policies still need to be manually or automatically applied, so this does not reduce the configuration time.
- ✓
Implement a configuration management tool that automatically synchronizes firewall rules, IDS signatures, and access controls to the hot site in near real-time.
Why this is correct
Automation ensures the hot site security posture mirrors the primary continuously, eliminating the manual delay and making it possible to meet the 15-minute RTO during failover.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jul 26, 2026
This SK0-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SK0-005 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.