CompTIA CySA+ CS0-003 Practice Question
When compiling an incident report, which of the following would BEST serve as reliable evidence that is admissible in legal proceedings?
Witness statements providing accounts of the security incident
A forensic image hash to prove that the image of a system has not been altered
Log files showing unauthorized access attempts
Chain of custody documents that detail how evidence was collected, handled, and preserved