AWS Certified Security – SpecialtyDomain 1: Incident ResponseMedium
A company's security team has detected a sophisticated, persistent threat actor attempting to establish persistence within their AWS environment. The threat actor is using compromised IAM credentials to make unusual API calls, including attempts to create new IAM users and attach policies. The security team needs to quickly identify all API calls made by the compromised credentials, across all regions, to understand the full scope of the compromise and the actions taken by the attacker. Which AWS service is best suited for this comprehensive investigation?
- AAWS Config.
- BAWS CloudTrail.
- CAmazon CloudWatch Logs.
- DAmazon GuardDuty.
Show answer & explanationAnswer & explanation
Correct answer: B. AWS CloudTrail.
AWS CloudTrail records all API calls made in an AWS account, including those made by compromised credentials. It provides a comprehensive audit trail, including the identity of the caller, the API action, and the resources affected, making it ideal for investigating the scope of actions by a threat actor.
Why the other options are wrong
- A. AWS Config records configuration changes to resources, but it doesn't capture all API calls made by an identity, nor does it provide the full context of the API call itself, only the resulting configuration change.
- C. CloudWatch Logs stores various logs, but CloudTrail is specifically designed for API call logging, which is what's needed here.
- D. GuardDuty is a threat detection service that can identify suspicious activity, but it doesn't provide the detailed, historical API call logs needed for a full scope investigation; it flags anomalies which CloudTrail then helps investigate.
AWS API Call Forensics
AWS CloudTrail provides a complete history of API calls made in an AWS account, including who made the call, when, from where, and what resources were affected. It is essential for security investigations involving compromised credentials.
- Records all AWS API calls and related events.
- Logs are delivered to S3 and can be sent to CloudWatch Logs.
- Crucial for security auditing, compliance, and incident response.
Memory trick: CloudTrail is the ultimate detective's notebook for every AWS action.