SSCP Incident Response and Recovery Practice Question
A financial services firm's incident response plan defines a Recovery Time Objective (RTO) of 2 hours for its online trading platform. During a tabletop exercise, the team discovers that the current disaster recovery runbook requires manual steps that take approximately 6 hours to complete. The Chief Information Security Officer (CISO) asks for a recommendation to align the recovery capability with the RTO without increasing the budget significantly. Which of the following is the MOST appropriate recommendation?
⚠ Common exam trap
The trap here is assuming that achieving a lower RTO always requires expensive new infrastructure, when automation of existing manual steps can often close the gap within budget.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automate the manual steps using existing orchestration tools and scripts to reduce recovery time.
Automating manual recovery steps using existing orchestration tools is the most cost-effective way to reduce recovery time and meet the 2-hour RTO. It leverages current investments, minimizes new spending, and directly targets the delay. Increasing the RTO ignores business needs, while hot site or MSSP options likely exceed the budget and may not fully resolve the manual process bottleneck.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Outsource the entire recovery process to a managed security service provider (MSSP) with a 2-hour SLA.
Why it's wrong here
Outsourcing recovery to an MSSP with a 2-hour SLA may introduce significant recurring costs and may not integrate seamlessly with existing systems. It also does not address the internal manual steps that cause the delay; the MSSP would still need to execute them or replace them. Without a major budget increase, this is unlikely to be feasible. It also shifts control and may complicate compliance in financial services.
- ✗
Increase the RTO to 6 hours to match the current manual recovery process.
Why it's wrong here
Increasing the RTO to match the manual process negates the business requirement for a 2-hour recovery, which is likely driven by regulatory or competitive needs in trading. The RTO is a business decision, not a technical convenience. Adjusting it downward to fit the current capability would expose the firm to unacceptable downtime and potential financial penalties. The CISO asked for alignment without significant budget increase, so changing the objective is not the right approach.
- ✓
Automate the manual steps using existing orchestration tools and scripts to reduce recovery time.
Why this is correct
Automating manual steps with existing orchestration tools can significantly reduce recovery time without major new spending. Many organizations already have configuration management or scripting platforms that can be leveraged to streamline failover and recovery. This approach directly addresses the gap between the 6-hour manual process and the 2-hour RTO. It also reduces human error and improves consistency, making it the most appropriate recommendation given the budget constraint.
- ✗
Implement a hot site with real-time replication, which will guarantee a 2-hour recovery.
Why it's wrong here
A hot site with real-time replication is expensive and may exceed the budget, violating the constraint of no significant increase. While it can achieve low RTO, it is not the most appropriate when cost is a concern. Additionally, real-time replication alone does not guarantee a 2-hour recovery if the failover process itself is manual or untested. The scenario emphasizes budget constraints, so this option is less suitable than automation using existing tools.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.