AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium

An auditor is reviewing an AWS account after a security incident and needs to determine which IAM user made a specific API call to terminate an EC2 instance, including the source IP address and timestamp. Which service provides this historical record of API activity?

  1. AAmazon CloudWatch Logs Insights
  2. BAWS CloudTrail
  3. CAWS Config
  4. DAWS Trusted Advisor
Show answer & explanation

Correct answer: B. AWS CloudTrail

AWS CloudTrail records API calls made within an AWS account, capturing details such as the identity of the caller, source IP address, and timestamp, making it the correct tool for this type of forensic investigation.

Why the other options are wrong

  • A. CloudWatch Logs Insights analyzes log data but does not natively capture AWS API call history.
  • C. AWS Config tracks configuration state and changes over time, not individual API call details like caller identity.
  • D. Trusted Advisor provides best-practice recommendations, not an audit trail of API activity.

AWS CloudTrail

A service that records API calls and account activity across AWS services, providing an audit trail for security analysis and compliance.

  • Captures caller identity, timestamp, source IP, and request parameters
  • Events can be stored in S3 for long-term retention and analysis
  • Enables detection of unauthorized or unusual account activity

Memory trick: CloudTrail leaves a trail of who did what, when, and from where.

More Security and Compliance questions