SSCP Incident Response and Recovery Practice Question
A multinational corporation has a disaster recovery plan with a Recovery Time Objective (RTO) of 2 hours for its customer-facing e-commerce platform. During a regional power outage, the primary data center goes offline. The DR team activates the hot site, but the database replication lag causes the e-commerce platform to come online after 5 hours. Which of the following should the incident response team do FIRST after restoring services?
⚠ Common exam trap
The trap here is focusing on restoring services or updating documentation, when the critical next step is to analyze why the RTO was missed and fix the root cause.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a root cause analysis of the replication lag and RTO miss.
After restoring services, the incident response team should perform a root cause analysis to understand why the hot site did not meet the 2-hour RTO. The replication lag is a technical issue that must be diagnosed and corrected to improve DR readiness. Punitive actions, plan normalization, or untested failback do not address the underlying cause and could worsen future outcomes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately fail back to the primary data center without testing.
Why it's wrong here
Failing back without testing risks another outage if the primary site is not fully stable. The first priority after restoration is to analyze the RTO miss, not to rush back. In this scenario, an untested failback could disrupt the e-commerce platform again and compound the business impact.
- ✗
Terminate the DR team lead for failing to meet the RTO.
Why it's wrong here
Terminating the DR team lead is punitive and does not address the technical cause of the missed RTO. The replication lag is a systemic issue that requires analysis and remediation, not blame. In this scenario, punitive action would harm morale and fail to prevent recurrence of the RTO miss.
- ✗
Update the DR plan to reflect the actual recovery time achieved.
Why it's wrong here
Updating the plan to match a failed RTO would normalize an unacceptable outcome rather than correct it. The first priority after restoration is to understand why the RTO was missed and address the root cause. In this scenario, simply changing the plan would not fix the replication lag that caused the 5-hour recovery and could leave the business exposed to future SLA breaches.
- ✓
Conduct a root cause analysis of the replication lag and RTO miss.
Why this is correct
After restoring services, the team should investigate why the hot site failed to meet the 2-hour RTO, focusing on database replication lag. A root cause analysis identifies whether the lag was due to bandwidth, configuration, or capacity issues, enabling corrective actions. This aligns with post-incident activity and ensures the DR capability is improved for future outages.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.