What This Domain Covers
Incident lifecycle support, forensics, evidence handling, business continuity, disaster recovery, backup, redundancy, RTO, RPO, MTD, drills, and lessons learned.
Official weighting: 14%.
Exam Objectives
4.1 Understand and support incident response lifecycle
Core idea: incident sequence.
Scenario: A ransomware alert is confirmed on one endpoint and file-share encryption is still spreading.
Practitioner response: Contain the active spread, preserve evidence, escalate through the incident plan, then eradicate and recover from trusted backups.
Concepts to Understand
- preparation: preparation is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
- detection, analysis, and escalation: detection, analysis, and escalation is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
- containment: containment is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
- eradication: eradication is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
- recovery: recovery is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
- post-incident activities: post-incident activities is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
4.2 Understand and support forensic investigations
Core idea: forensic handling.
Scenario: Operations wants to log in to a suspected compromised server and remove tools before legal decides whether evidence is needed.
Practitioner response: Preserve snapshots, logs, metadata, and chain of custody before changes alter the evidence state.
Concepts to Understand
- civil, criminal, administrative, and ethical principles: civil, criminal, administrative, and ethical principles is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
- first responder responsibilities: first responder responsibilities is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
- triage: triage is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
- chain of custody: Chain of custody records who handled evidence, when, how it was protected, and whether integrity was preserved.
- scene preservation: scene preservation is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
- analysis reporting: analysis reporting is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
- security policy compliance: security policy compliance is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
4.3 Understand and support BCP and DRP
Core idea: recovery planning.
Scenario: Backups meet RPO, but the identity system and DNS needed for failover have never been tested.
Practitioner response: Test full recovery dependencies against RTO and MTD, not only data restore time.
Concepts to Understand
- emergency response plans: emergency response plans is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
- interim and alternate processing: interim and alternate processing is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
- RTO, RPO, and MTD: RTO is the time target for restoring service. It must include dependencies such as identity, DNS, backups, staff, and procedures.
- backup and redundancy implementation: backup and redundancy implementation is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
- playbooks, tabletops, DR exercises, and scheduling: playbooks, tabletops, DR exercises, and scheduling is testable because a practitioner must know what control it supports, who owns it, what evidence proves it worked, and what failure looks like.
Decision Patterns
BEST
Choose the answer that satisfies the security requirement and leaves a defensible operational record.
FIRST
Prioritize safety, containment, authority, and evidence before convenience or final cleanup.
MOST EFFECTIVE
Prefer the control that changes the outcome, not merely the control that creates more information.
LEAST
Think least privilege, least disruption, or least residual risk depending on the stem.
Common Exam Traps
- Destroying evidence while trying to restore service.
- Calling a backup strategy complete without restore tests.
- Missing the words FIRST or NEXT and choosing a later remediation step.
Comparisons
identification vs containment vs eradication vs recovery
This comparison is covered through the domain objectives above and the SSCP review sheet.
RTO vs RPO vs MTD
| Option | Primary difference | Best use |
|---|---|---|
| RTO | How fast service must return | Restore-time target |
| RPO | How much data loss is acceptable | Backup/replication target |
| MTD | Maximum tolerable downtime | Business survival boundary |
Exam clue: Backups prove RPO only when restores are tested; they do not automatically meet RTO.
backup vs replication
This comparison is covered through the domain objectives above and the SSCP review sheet.
Hot vs Warm vs Cold Recovery Sites
| Option | Primary difference | Best use |
|---|---|---|
| Hot | Running or near-running | Fastest recovery, highest cost |
| Warm | Partially prepared | Balanced cost and recovery speed |
| Cold | Space and basics only | Lowest cost, slowest recovery |
Exam clue: Choose based on RTO/MTD and cost tolerance, not on the most impressive architecture.
Knowledge Check
- Can you identify the accountable owner before choosing the control?
- What evidence would prove the control worked?
- What changes if this becomes legally regulated or time-critical?
- What would fail if the administrator account, log source, or recovery dependency is unavailable?
Domain Mastery Checklist
Practice in the Arcade
This domain currently has 9 validated SSCP practice questions mapped to it.
Practice This DomainSources
ISC2 SSCP Certification Exam Outline
Reviewed 2026-08-08 for SSCP.
ISC2 SSCP Experience Requirements
Reviewed 2026-08-08 for SSCP.
ISC2 Endorsement
Reviewed 2026-08-08 for SSCP.
ISC2 Member Policies
Reviewed 2026-08-08 for SSCP.