AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringMedium

A security engineer is investigating a series of suspicious activities originating from an EC2 instance, including unusual outbound network connections and attempts to access internal resources. The engineer needs to quickly determine which AWS Identity and Access Management (IAM) role or user was used to launch the affected EC2 instance and what other actions that IAM entity has performed recently. Which AWS service provides the most direct and efficient way to retrieve this information?

  1. AAWS Config
  2. BAmazon GuardDuty
  3. CAWS CloudTrail
  4. DAmazon CloudWatch Logs
Show answer & explanation

Correct answer: C. AWS CloudTrail

AWS CloudTrail records all API calls made in your AWS account, including the `RunInstances` API call that launches an EC2 instance. The CloudTrail event for `RunInstances` will contain details about the IAM user or role that initiated the launch, along with the instance ID. CloudTrail also provides a history of all other API calls made by that IAM entity.

Why the other options are wrong

  • A. AWS Config tracks configuration changes over time, but it doesn't directly provide the IAM principal that launched an instance or a detailed history of API calls made by that principal.
  • B. Amazon GuardDuty detects threats and suspicious activity, but it doesn't provide the historical API call information or directly link an instance launch to a specific IAM principal in the way CloudTrail does for forensic investigation.
  • D. Amazon CloudWatch Logs aggregates logs from various sources, but to find the specific `RunInstances` event and associated IAM principal, you would typically need CloudTrail logs ingested into CloudWatch Logs, making CloudTrail the more direct source.

AWS CloudTrail for Forensics

A service that records all API calls and related events made in an AWS account, providing an audit trail for security analysis, compliance, and operational troubleshooting.

  • Captures management and data events.
  • Records identity of the caller (IAM user/role), IP address, time, and API call.
  • Essential for forensic investigations to trace actions and identify responsible principals.

Memory trick: CloudTrail leaves the trail of who did what, when, and where.

More Domain 2: Logging and Monitoring questions