CompTIA CySA+ CS0-003 Practice Question

While responding to an incident, you've been asked to ensure the data integrity of logs that may contain evidence of malicious activity. What is the first step you should take to validate the integrity of these logs?

  • Ensure all logs are time-stamped so that you can validate data was not altered based on the time of recording.

  • Use a proprietary algorithm to encrypt the files and logs to prevent unauthorized modification.

  • Calculate and securely record the hash values of the files and logs using a standardized hashing algorithm.

  • Take a complete copy of the logs and store them in a secure location before any analysis or hash calculations.

CompTIA CySA+ CS0-003
Incident Response and Management
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot