CFR-310 Exam QuestionsBrowse all questions from this exam

CFR-310 Exam - Question 50


An incident response team is concerned with verifying the integrity of security information and event management (SIEM) events after being written to disk. Which of the following represents the BEST option for addressing this concern?

Show Answer
Correct Answer:

Discussion

1 comment
Sign in to comment
044f354Option: B
Sep 29, 2024

B. Log hashing Explanation: Log hashing involves generating a unique hash value (using algorithms like SHA-256) for each log entry or set of logs. This ensures that any unauthorized changes or tampering of the logs will alter the hash value, making it immediately evident that the log integrity has been compromised. This is an effective way to verify that the logs remain unchanged after they have been written to disk. Why the other answers are less suitable: A. Time synchronization: Ensures that timestamps across different systems are consistent, but it does not verify the integrity of the logs. C. Source validation: Verifies that logs are coming from the expected sources, but it does not protect against tampering after logs have been written to disk. D. Field name consistency: Ensures that logs have consistent formatting and structure, but it does not address the integrity or tamper detection of log contents.