AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringEasy
A security engineer is investigating a potential compromise involving an AWS access key. The key was used to make several unauthorized API calls from an unknown IP address. The engineer needs to quickly determine the exact API calls made, the resources affected, the source IP address, and the user identity associated with the access key. Which AWS service is the primary source for this forensic investigation?
- AAWS CloudTrail
- BAmazon GuardDuty
- CAWS Config
- DAmazon CloudWatch Logs
Show answer & explanationAnswer & explanation
Correct answer: A. AWS CloudTrail
AWS CloudTrail records all API calls made in your AWS account, providing a detailed history of actions. For a compromised access key, CloudTrail logs will contain the exact API calls, the resources targeted, the source IP address of the caller, and the IAM user or role identity associated with the access key, which is crucial for forensic analysis.
Why the other options are wrong
- B. Amazon GuardDuty detects threats and generates findings, but it provides summaries and context, not the raw, granular API call history needed for a detailed forensic investigation of all actions taken by a compromised key.
- C. AWS Config tracks configuration changes to resources, but it does not record the API calls that caused those changes or the identity of the caller, which is essential for forensic analysis of unauthorized API activity.
- D. CloudWatch Logs aggregates logs, but CloudTrail is the source of the API call logs themselves. You would typically send CloudTrail logs to CloudWatch Logs, but CloudTrail remains the primary source for the API call data.
CloudTrail for Access Key Forensics
AWS CloudTrail records every API call made in an AWS account, providing a detailed audit trail that is critical for forensic investigations into compromised access keys or unauthorized activities.
- Logs all management and data events.
- Captures caller identity, source IP, time, and API operation.
- Essential for tracing actions and identifying the scope of a compromise.
- Helps determine 'who, what, when, where' of an AWS API interaction.
Memory trick: CloudTrail leaves the breadcrumbs of every API call.