List of questions
Related questions
Question 787 - CISM discussion
For event logs to be acceptable for incident investigation, which of the following is the MOST important consideration to establish chain of evidence?
A.
Centralized logging
B.
Time clock synchronization
C.
Available forensic tools
D.
Administrator log access
Your answer:
0 comments
Sorted by
Leave a comment first