When acquiring evidence, what can you use to validate that data and applications were not modified after analysis?
When acquiring evidence, what can you use to validate that data and applications were not modified after analysis?
- Network and traffic logs
- Hashes or checksums of data
- Time offset data
Explanation: Hashes or checksums of all data and applications before and after any analysis, to validate that they were not modified.
Related exam: Cybersecurity Essentials Module 6 Quiz Answers
About The Author
The ITExamAnswers Editorial Team is a dedicated group of certified IT professionals and network engineers. We rigorously review, verify, and update all exam materials to ensure you receive the most accurate and reliable resources for your certification journey.