CompTIA CySA+ CS0-003 Practice Question
While responding to an incident, you've been asked to ensure the data integrity of logs that may contain evidence of malicious activity. What is the first step you should take to validate the integrity of these logs?
Use a proprietary algorithm to encrypt the files and logs to prevent unauthorized modification.
Calculate and securely record the hash values of the files and logs using a standardized hashing algorithm.
Take a complete copy of the logs and store them in a secure location before any analysis or hash calculations.
Ensure all logs are time-stamped so that you can validate data was not altered based on the time of recording.