Courseiva

SCS-C02 Security Logging and Monitoring Practice Question

Network Topology
$ aws cloudtrail lookup-eventslookup-attributes AttributeKey=EventNamequery 'Events[*].CloudTrailEvent'output textRefer to the exhibit.

A security engineer runs the CLI command above to investigate a console login event. The output shows: {"type":"Root","principalId":"123456789012","arn":"arn:aws:iam::123456789012:root"}. What does this indicate?

⚠ Common exam trap

It's easy for candidates to confuse the `:root` suffix in the ARN with an IAM user named 'root', but AWS reserves the `:root` ARN exclusively for the account root user, and any IAM user would have a distinct ARN with a username after `:user/`.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The AWS account root user performed the console login.

The output shows `"type":"Root"` and `"arn":"arn:aws:iam::123456789012:root"`, which are the exact identifiers AWS CloudTrail uses to record an action performed by the AWS account root user. The root user is the account owner with full administrative access, and its principal ARN always ends with `:root`. This confirms that the console login was performed by the root user, not by any other identity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A federated user performed the console login.

    Why it's wrong here

    A federated user login is recorded in CloudTrail with userIdentity.type set to FederatedUser, and the ARN takes the form arn:aws:sts::123456789012:federated-user/name with a session name in the principalId. The event would also include sessionContext reflecting the originating identity provider. However, the CloudTrail output being investigated identifies the actor as type Root, so a federated authentication cannot be the cause.

  • ✗

    An AWS service performed the console login.

    Why it's wrong here

    An AWS service action appears in CloudTrail with userIdentity.type AssumedRole and usually shows a sessionIssuer, or is flagged by the invokedBy field rather than the actor's own session. AWS services never assume a root-user identity to perform a human console login; the ConsoleLogin event is explicitly generated from the AWS Management console sign-in flow. Since the recorded type is Root, the console login could only be the account owner, not an automated service.

  • ✗

    An IAM user in the account performed the console login.

    Why it's wrong here

    If an IAM user had signed in, the CloudTrail userIdentity would show type IAMUser, an ARN like arn:aws:iam::123456789012:user/username, and a populated userName field that maps to the specific IAM user. The console login event would also contain the user's own credentials in the principalId. Because the event shows no IAMUser identity — instead showing the account-level root type — this IAM-user option is impossible.

  • ✓

    The AWS account root user performed the console login.

    Why this is correct

    The root user is the only IAM principal that CloudTrail identifies with userIdentity.type equal to Root, and its ARN is always arn:aws:iam::123456789012:root with no session context or userName. The presence of a login event with this type proves the AWS account root user directly authenticated using the account's email and password (plus any MFA), bypassing any identity provider or IAM role. This is exactly what the CloudTrail event indicates.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.