Locate Source IP and User Agent in CloudTrail Logs
A security engineer is reviewing AWS CloudTrail logs and finds that an IAM user 'developer1' deleted an S3 bucket. The engineer needs to determine the source IP address of the delete operation. Which field in the CloudTrail log record contains this information?
⚠ Common exam trap
A common mix-up: candidates confuse `sourceIPAddress` with `userIdentity` or `requestParameters`, mistakenly thinking the IP address is embedded in the user details or request payload, when in fact it is a separate top-level field in the CloudTrail log record.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
sourceIPAddress
The `sourceIPAddress` field in a CloudTrail log record captures the IP address from which the API call was made. For S3 bucket deletion via the AWS Management Console, AWS CLI, or SDK, this field records the originating IP address, enabling the security engineer to trace the delete operation back to its source.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
userIdentity
Why it's wrong here
userIdentity is a top-level CloudTrail field that describes the IAM principal who made the API call, including the ARN, principal ID, account ID, and access key ID. While it can include session context for assumed roles, it does not contain any network-layer information such as the caller's IP address. The source IP is stored independently in the sourceIPAddress field, so userIdentity alone cannot help identify where the request originated.
- ✗
requestParameters
Why it's wrong here
requestParameters holds the API call's input parameters, such as the bucket name, not the caller's network origin. It is useful for reconstructing what was requested; the source IP address is recorded in sourceIPAddress, which would be the answer if the question asked which parameters were supplied.
- ✗
eventTime
Why it's wrong here
eventTime records the UTC timestamp of the API request, indicating exactly when the event occurred. While it is useful for correlating logs or reconstructing a sequence of actions, it carries no information about the geographic or network source of the request. An IP address is not a temporal attribute, so eventTime cannot provide any insight into the caller's IP address—that data is found in sourceIPAddress.
- ✓
sourceIPAddress
Why this is correct
sourceIPAddress is the dedicated top-level field in CloudTrail log events that holds the IP address from which the API call was made. This is the exact field a security engineer should examine to identify the origin of a request, whether it comes from a user's public IP, a NAT gateway address, or an AWS service's internal IP. For console-session actions, CloudTrail populates this field with the IP of the user's browser, making it the authoritative source for network origin in log review.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.