Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

Exhibit

Refer to the exhibit.

{  "sourceIP": "192.0.2.1",  "userIdentity": {    "arn": "arn:aws:iam::111111111111:user/JohnDoe",    "type": "IAMUser"  },  "eventTime": "2024-08-15T12:34:56Z",  "eventSource": "ec2.amazonaws.com",  "eventName": "RunInstances",  "awsRegion": "us-east-1",  "requestParameters": {    "instanceType": "t2.micro",    "imageId": "ami-0abcdef1234567890"  },  "responseElements": {    "instancesSet": {      "items": [        { "instanceId": "i-0a1b2c3d4e5f67890" }      ]    }  }}

Refer to the exhibit. A security engineer is analyzing a CloudTrail log entry for an EC2 RunInstances call. The engineer needs to determine if the instance launch was authorized by an IAM policy. Which field should the engineer check to identify the IAM policy that was used to authorize the action?

⚠ Common exam trap

A common mix-up: candidates think the 'eventType' or 'sourceIP' fields directly reveal authorization details, but CloudTrail does not log the specific policy that was evaluated; instead, the 'userIdentity' field is the critical link to identify the IAM entity whose policies were applied.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The 'userIdentity' field to identify the IAM user or role that made the call.

The 'userIdentity' field in a CloudTrail log entry contains details about the IAM user or role that made the API call, including the ARN and the access key ID. To identify the specific IAM policy that authorized the action, the security engineer must first know the identity (user/role) from the 'userIdentity' field, then cross-reference that identity with the IAM policies attached to it. The policy itself is not directly listed in the log entry, but the identity is the key to tracing authorization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The 'vpcEndpointId' field to see if the call came through a VPC endpoint.

    Why it's wrong here

    The vpcEndpointId field only appears when the request traversed a VPC endpoint, so it describes the network path and which VPC endpoint policy applied, not the IAM authorization decision. A security engineer cannot infer which IAM user or role was evaluated from this field because many different principals could use the same endpoint. It is network context, not identity context, and thus cannot help review the caller's attached policies.

  • ✗

    The 'sourceIP' field to identify the IP address.

    Why it's wrong here

    The sourceIP field shows the network address from which the request arrived, but that address is not tied to a particular IAM user or role, especially when traffic goes through a NAT gateway, a load balancer, or a VPC endpoint. An IP address can even be a private address inside a VPC, making it impossible to map to a unique IAM identity without additional metadata. It can be useful for condition key evaluation such as aws:SourceIp, but it does not identify the principal for authorization review.

  • ✗

    The 'eventType' field to determine the type of event.

    Why it's wrong here

    The eventType field classifies the CloudTrail entry as an AwsApiCall, AwsServiceEvent, AwsConsoleSignIn, or similar event category, and therefore only tells whether this log entry represents a direct AWS API action or an event generated by an AWS service. It gives no information about which IAM user or role was involved, because the same eventType can appear for calls made by any number of principals. Distinguishing event type is useful for log filtering, not for reviewing an identity's authorization policy.

  • ✓

    The 'userIdentity' field to identify the IAM user or role that made the call.

    Why this is correct

    The userIdentity block in a CloudTrail record is the authoritative field for identifying the principal, containing the ARN, type (IAMUser, AssumedRole, Root, etc.), and session context for the call. By inspecting this block, the security engineer can determine the exact IAM user or role and then review the identity-based and attached policies that governed the request. Without userIdentity, there is no reliable way to map an API call to the IAM entity whose permissions should be audited.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.