AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringMedium

A security engineer is investigating a potential compromise of an AWS access key associated with an IAM user. They need to determine the last time the access key was used, from which IP address, and what AWS services it accessed. This information is crucial for incident response. Which AWS service and its features would provide this specific audit information?

  1. AIAM Access Analyzer to review resource access and generate findings.
  2. BAmazon GuardDuty to detect unusual API calls and generate security findings.
  3. CCloudTrail Event History for recent activity and CloudTrail Lake for long-term query.
  4. DAWS Config rules to track IAM user changes and notify via SNS.
Show answer & explanation

Correct answer: C. CloudTrail Event History for recent activity and CloudTrail Lake for long-term query.

CloudTrail records all AWS API calls and console actions, including details like `sourceIPAddress`, `userIdentity`, and the API operation performed. CloudTrail Event History allows viewing recent events, and CloudTrail Lake provides advanced querying capabilities for long-term logs, making it ideal for forensic analysis of access key usage.

Why the other options are wrong

  • A. IAM Access Analyzer helps identify unintended access to resources from outside your account, but it does not provide a historical log of *when* or *where* an access key was used for specific API calls.
  • B. GuardDuty detects *unusual* or *malicious* activity (like compromised credentials), but it generates findings based on patterns. It does not provide the raw, detailed log of *every* API call made by a specific access key with its source IP and service, which is what CloudTrail does.
  • D. AWS Config tracks *changes* to IAM resources (e.g., user creation, policy attachments), but it does not log individual API calls made *by* an IAM user or access key.

CloudTrail for Access Key Forensics

Using AWS CloudTrail's Event History and CloudTrail Lake to investigate the usage of compromised access keys, including source IP, time, and services accessed.

  • CloudTrail logs all API calls and console actions.
  • Records `sourceIPAddress`, `userIdentity`, and `eventName` (API call).
  • Event History provides a 90-day searchable view.
  • CloudTrail Lake allows advanced queries over long-term, aggregated logs.

Memory trick: CloudTrail's history, like a detective's eye, reveals where a key has flown, and why.

More Domain 2: Logging and Monitoring questions