A company is implementing a new SIEM. Which THREE factors are most important to ensure log integrity and usefulness for forensic investigations? (Choose THREE.)
Write-once storage prevents logs from being altered or deleted after capture, preserving evidential integrity. This directly satisfies the forensic requirement that records remain tamper-evident and unmodified, ensuring investigators can trust that what they review reflects the original event data.
Why this answer
Option A (write-once storage to prevent modification) is correct because WORM (Write Once Read Many) media or immutable storage ensures that once log data is written it cannot be altered or deleted, preserving evidentiary integrity for forensics. Option B (digital signing of logs to verify authenticity) is correct because cryptographic signatures or hashes let investigators prove logs were not tampered with and confirm their origin, supporting non-repudiation and chain-of-custody requirements. Option D (ensuring logs are retained for a period consistent with legal and regulatory requirements) is correct because forensic usefulness depends on having the relevant logs still available when an investigation occurs, and retention periods are often mandated by laws such as HIPAA, PCI DSS, or GDPR.
Option C is not correct because minimizing retention to cut storage costs directly undermines forensic and compliance needs by destroying potentially critical evidence prematurely. Option E is not correct because centralizing logs improves correlation and management but does not by itself guarantee integrity or forensic usefulness, and it can even concentrate risk if the repository is not protected.
Exam trap
A common trap on the SSCP exam is to select 'centralized aggregation' (Option E) as a key factor for log integrity, but aggregation alone does not protect against modification. The correct factors focus on preserving log authenticity and immutability, such as write-once storage and digital signatures.