SK0-005 security-disaster-recovery Practice Question
A large financial services company must comply with federal regulations mandating quarterly disaster recovery tests. Their primary data center in New York hosts all trading applications, and a hot site in Chicago is maintained with real-time data replication via synchronous mirroring. During the last DR test, the IT team successfully failed over network and storage within 8 minutes, meeting the 15-minute RTO for connectivity. However, they encountered a major issue: the hot site's firewalls, intrusion detection systems, and application-level access controls were not configured to match the primary environment. The security team had to manually create firewall rules, update IDS signatures, and reconfigure access policies based on documentation, which took over 4 hours. As a result, the total system readiness exceeded 4.5 hours, causing a significant gap in trading operations. The regulatory auditor noted this deficiency and required a corrective action plan. The company must ensure that the next DR test achieves full operational readiness, including security controls, within the 15-minute RTO. The IT budget is already allocated for the current fiscal year, so large capital expenditures are not possible, but the team can leverage existing tools and automation. Which of the following is the BEST approach to address this issue?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a configuration management tool that automatically synchronizes firewall rules, IDS signatures, and access controls to the hot site in near real-time.
Option A is correct because implementing a configuration management or synchronization tool directly addresses the root cause—manual configuration—by automating the replication of security policies to the hot site in near real-time. This eliminates human error and delay, meeting the 15-minute RTO without requiring new hardware. Option B (detailed runbooks and drills) still relies on manual interaction, which is unlikely to achieve 15-minute readiness. Option C merely lowers the standard instead of fixing the process and would likely be rejected by regulators. Option D (identical hardware) does not automatically transfer configurations; they would still need to be applied, so it does not solve the time problem.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Develop detailed runbooks for the security team to manually configure devices during failover; then conduct quarterly drills to reduce configuration time.
Why it's wrong here
Even with practice, manually configuring complex security devices within 15 minutes is unrealistic due to the volume of rules and potential for error; human speed cannot match automation.
- ✗
Re-evaluate the RTO to extend it to 4 hours and inform regulators of a realistic capability.
Why it's wrong here
Changing the RTO does not solve the technical deficiency; it merely accepts failure and would likely not satisfy regulatory mandates that require a 15-minute recovery capability.
- ✗
Replace the existing firewalls and IDS at the hot site with identical hardware from the same vendors as the primary site.
Why it's wrong here
Identical hardware alone does not ensure configurations match; the security rules and policies still need to be manually or automatically applied, so this does not reduce the configuration time.
- ✓
Implement a configuration management tool that automatically synchronizes firewall rules, IDS signatures, and access controls to the hot site in near real-time.
Why this is correct
Automation ensures the hot site security posture mirrors the primary continuously, eliminating the manual delay and making it possible to meet the 15-minute RTO during failover.
Go deeper
Related to this question
Learn chapter
Disaster Recovery and Business Continuity Planning
Key term
RTO
Recovery Time Objective is the maximum acceptable time to restore a system or data after a disaster, defining how quickly normal operations must resume.
Key term
Update
An update is a piece of software released to fix problems, add features, or improve security in an existing program or system.
About these practice questions
One of 185 original SK0-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed July 2026 · checked against the official CompTIA exam blueprint
This SK0-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SK0-005 exam.