GCIH • Practice Test 14
Free GCIH practice test — 15 questions with explanations. Set 14. No signup required.
An incident responder is analyzing a compromised AWS EC2 instance that was used to exfiltrate data from an S3 bucket. The attacker gained access by exploiting a server-side request forgery (SSRF) vulnerability in a web application running on the instance. The instance had an IAM role attached that allowed s3:GetObject on a sensitive bucket. Which of the following logs would provide the MOST direct evidence of the S3 data access by the attacker?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.