AWS Certified Security – SpecialtyDomain 1: Incident ResponseMedium

A global software company maintains sensitive intellectual property in an Amazon S3 bucket. A security team suspects an insider threat attempting to access or exfiltrate data from this S3 bucket using an assumed role. The team needs to quickly identify which IAM roles have been assumed to access the S3 bucket and from which source accounts or external identities. Which AWS service and data source should be used to trace these assumed role activities?

  1. AAWS CloudTrail logs, specifically looking for 'AssumeRole' events and subsequent S3 API calls.
  2. BAWS IAM Access Analyzer findings for external access to the S3 bucket.
  3. CS3 Access Logs, filtered by 'role-session-name' in the request URI.
  4. DAmazon Detective, by reviewing the 'entities' related to the S3 bucket and their activities.
Show answer & explanation

Correct answer: A. AWS CloudTrail logs, specifically looking for 'AssumeRole' events and subsequent S3 API calls.

AWS CloudTrail records all API calls, including 'AssumeRole' events which indicate an IAM role being assumed. Subsequent S3 API calls made by the assumed role will also be logged, linking them back to the temporary credentials issued by the 'AssumeRole' event, providing a clear audit trail of who assumed what role and what they did with it.

Why the other options are wrong

  • B. IAM Access Analyzer helps identify unintended external access to resources but is not designed for tracing specific assumed role *activity* and correlating it with resource access in real-time or forensic context.
  • C. S3 Access Logs record object-level requests but provide limited details about IAM role assumption context compared to CloudTrail.
  • D. Amazon Detective can aggregate and analyze data from CloudTrail, but the direct and most fundamental data source for 'AssumeRole' and API calls is CloudTrail itself. While Detective would use this data, CloudTrail is the direct answer for tracing these specific events.

CloudTrail AssumeRole Tracing

Using AWS CloudTrail logs to trace the assumption of IAM roles and subsequent actions performed with those temporary credentials, vital for identifying insider threats or unauthorized access via roles.

  • CloudTrail logs 'AssumeRole' events.
  • Subsequent API calls link to the assumed role session.
  • Provides a forensic trail for role-based access.

Memory trick: CloudTrail is your detective for role-playing in AWS.

More Domain 1: Incident Response questions