AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringEasy
A security engineer is investigating a series of unauthorized API calls originating from an unusual geographic location, targeting an AWS account. The engineer needs to identify the specific API calls made, the IAM principal that made them, and the source IP address. Which AWS service should the engineer consult to gather this information?
- AAmazon GuardDuty
- BAWS CloudTrail
- CVPC Flow Logs
- DAmazon CloudWatch Metrics
Show answer & explanationAnswer & explanation
Correct answer: B. AWS CloudTrail
AWS CloudTrail records all API calls made to AWS services within an account. This includes details such as the specific API call, the IAM principal (user or role) that made the call, the source IP address, the time of the call, and the region. This makes CloudTrail the definitive source for auditing and investigating unauthorized API activities.
Why the other options are wrong
- A. Amazon GuardDuty provides threat detection and findings, but CloudTrail is the underlying log source for API activity that GuardDuty monitors. Consulting CloudTrail directly provides the raw, detailed events.
- C. VPC Flow Logs capture network traffic information (IP addresses, ports, protocols) within a VPC, not API calls made to AWS services.
- D. Amazon CloudWatch Metrics provides aggregated data points for monitoring resource performance and operational health, not detailed API call logs.
AWS CloudTrail
A service that enables governance, compliance, operational auditing, and risk auditing of your AWS account by recording API calls.
- Records API calls made to AWS services.
- Provides event history including identity, time, source IP, and API call.
- Logs to S3 and can integrate with CloudWatch Logs.
Memory trick: CloudTrail is the 'black box recorder' for all AWS API actions, revealing who did what, when, and from where.