Free CompTIA CySA+ CS0-003 Practice Question

While responding to an incident, you've been asked to ensure the data integrity of logs that may contain evidence of malicious activity. What is the first step you should take to validate the integrity of these logs?

  • Ensure all logs are time-stamped so that you can validate data was not altered based on the time of recording.

  • Calculate and securely record the hash values of the files and logs using a standardized hashing algorithm.

  • Take a complete copy of the logs and store them in a secure location before any analysis or hash calculations.

  • Use a proprietary algorithm to encrypt the files and logs to prevent unauthorized modification.

This question's topic:
CompTIA CySA+ CS0-003 / 
Incident Response and Management
Your Score:

Check or uncheck an objective to set which questions you will receive.