A security engineer is investigating a series of unauthorized root user API calls detected by AWS CloudTrail. To understand the full scope of the compromise, the engineer needs to reconstruct the sequence of events and identify all actions performed by the root user, including those that might have been immediately reverted or hidden. Which approach provides the most comprehensive forensic timeline of root user activity?
- AReview the CloudTrail Event History in the AWS Management Console, filtering by root user.
- BUse Amazon Athena to query CloudTrail logs stored in S3, specifically looking for 'ConsoleLogin' and 'AssumeRole' events from the root user.
- CQuery CloudTrail Lake for all events where 'userIdentity.type' is 'Root' within the incident timeframe.
- DAnalyze CloudWatch Logs insights queries on the CloudTrail log group for root user events.
Show answer & explanationAnswer & explanation
Correct answer: C. Query CloudTrail Lake for all events where 'userIdentity.type' is 'Root' within the incident timeframe.
CloudTrail Lake is designed for long-term, immutable storage and advanced querying of CloudTrail events. It allows for comprehensive forensic analysis across extended periods and provides powerful SQL-like query capabilities to reconstruct detailed timelines of specific identities like the root user, including all API calls regardless of their effect or subsequent changes.
Why the other options are wrong
- A. CloudTrail Event History is limited to 90 days and provides a console-based view, which is less suitable for comprehensive, deep-dive forensic analysis and timeline reconstruction.
- B. Athena can query CloudTrail logs in S3, but CloudTrail Lake offers a more integrated and optimized experience specifically for forensic and security investigations, with built-in immutability and schema for direct querying without manual table setup.
- D. CloudWatch Logs Insights is good for near real-time analysis but may not offer the same depth or historical coverage as CloudTrail Lake for comprehensive forensic timelines.
CloudTrail Lake for Forensics
A managed data lake for CloudTrail events, providing immutable storage and SQL-like query capabilities for deep forensic analysis and security investigations over extended periods.
- Immutable storage of CloudTrail events.
- Advanced SQL-like querying for detailed analysis.
- Ideal for long-term forensic timelines and security investigations.
Memory trick: CloudTrail Lake is your forensic magnifying glass for root activity.