SSCP Domain 4 / 14%

Incident Response and Recovery

SSCP incident questions reward sequence discipline. Preserve evidence, contain the active path, escalate correctly, recover from trusted sources, and update controls after the incident.

What This Domain Covers

Incident lifecycle support, forensics, evidence handling, business continuity, disaster recovery, backup, redundancy, RTO, RPO, MTD, drills, and lessons learned.

Official weighting: 14%.

Incident Response and Recovery control loop
Incident Response and Recovery control loop A practitioner loop showing policy, control implementation, monitoring evidence, risk review, and remediation for Incident Response and Recovery. Policy ImplementControl MonitorEvidence ReviewRisk Remediate and improve

Exam Objectives

4.1 Understand and support incident response lifecycle

Core idea: incident sequence.

Scenario: A ransomware alert is confirmed on one endpoint and file-share encryption is still spreading.

Practitioner response: Contain the active spread, preserve evidence, escalate through the incident plan, then eradicate and recover from trusted backups.

Concepts to Understand

  • preparation: preparation is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
  • detection, analysis, and escalation: detection, analysis, and escalation is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
  • containment: containment is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
  • eradication: eradication is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
  • recovery: recovery is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
  • post-incident activities: post-incident activities is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
Practice 4.1

4.2 Understand and support forensic investigations

Core idea: forensic handling.

Scenario: Operations wants to log in to a suspected compromised server and remove tools before legal decides whether evidence is needed.

Practitioner response: Preserve snapshots, logs, metadata, and chain of custody before changes alter the evidence state.

Concepts to Understand

  • civil, criminal, administrative, and ethical principles: civil, criminal, administrative, and ethical principles is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
  • first responder responsibilities: first responder responsibilities is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
  • triage: triage is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
  • chain of custody: Chain of custody records who handled evidence, when, how it was protected, and whether integrity was preserved.
  • scene preservation: scene preservation is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
  • analysis reporting: analysis reporting is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
  • security policy compliance: security policy compliance is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
Practice 4.2

4.3 Understand and support BCP and DRP

Core idea: recovery planning.

Scenario: Backups meet RPO, but the identity system and DNS needed for failover have never been tested.

Practitioner response: Test full recovery dependencies against RTO and MTD, not only data restore time.

Concepts to Understand

  • emergency response plans: emergency response plans is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
  • interim and alternate processing: interim and alternate processing is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
  • RTO, RPO, and MTD: RTO is the time target for restoring service. It must include dependencies such as identity, DNS, backups, staff, and procedures.
  • backup and redundancy implementation: backup and redundancy implementation is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
  • playbooks, tabletops, DR exercises, and scheduling: playbooks, tabletops, DR exercises, and scheduling is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
Practice 4.3

Decision Patterns

BEST

Choose the answer that satisfies the security requirement and leaves a defensible operational record.

FIRST

Prioritize safety, containment, authority, and evidence before convenience or final cleanup.

MOST EFFECTIVE

Prefer the control that changes the outcome, not merely the control that creates more information.

LEAST

Think least privilege, least disruption, or least residual risk depending on the stem.

Common Exam Traps

  • Destroying evidence while trying to restore service.
  • Calling a backup strategy complete without restore tests.
  • Missing the words FIRST or NEXT and choosing a later remediation step.

Comparisons

identification vs containment vs eradication vs recovery

This comparison is covered through the domain objectives above and the SSCP review sheet.

RTO vs RPO vs MTD

RTO vs RPO vs MTD
OptionPrimary differenceBest use
RTOHow fast service must returnRestore-time target
RPOHow much data loss is acceptableBackup/replication target
MTDMaximum tolerable downtimeBusiness survival boundary

Exam clue: Backups prove RPO only when restores are tested; they do not automatically meet RTO.

backup vs replication

This comparison is covered through the domain objectives above and the SSCP review sheet.

Hot vs Warm vs Cold Recovery Sites

Hot vs Warm vs Cold Recovery Sites
OptionPrimary differenceBest use
HotRunning or near-runningFastest recovery, highest cost
WarmPartially preparedBalanced cost and recovery speed
ColdSpace and basics onlyLowest cost, slowest recovery

Exam clue: Choose based on RTO/MTD and cost tolerance, not on the most impressive architecture.

Knowledge Check

  • Can you identify the accountable owner before choosing the control?
  • What evidence would prove the control worked?
  • What changes if this becomes legally regulated or time-critical?
  • What would fail if the administrator account, log source, or recovery dependency is unavailable?

Domain Mastery Checklist

Practice in the Arcade

This domain currently has 9 validated SSCP practice questions mapped to it.

Practice This Domain

Sources