Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A SysOps administrator is investigating a security breach. An IAM user 'Bob' is suspected of performing unauthorized actions. The administrator needs to determine the source IP addresses from which Bob's access keys were used in the last 30 days. Which AWS service or feature should be used?

⚠ Common exam trap

Watch out — candidates often confuse the IAM credential report (which shows credential metadata) with CloudTrail (which records actual API call details), leading them to choose the credential report for investigating source IPs when it only provides static credential status, not historical usage data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail event history.

AWS CloudTrail event history provides a record of all API calls made by IAM users, including the source IP address from which the request originated. By filtering the event history for the IAM user 'Bob' and the time range of the last 30 days, the administrator can identify the source IP addresses associated with each API call made using Bob's access keys. This directly meets the requirement to determine the source IP addresses of unauthorized actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS CloudTrail event history.

    Why this is correct

    AWS CloudTrail event history retains 90 days of management events, satisfying the 30-day window. Each `sourceIPAddress` field records the originating IP for every API call made with Bob's access keys, letting the administrator trace exactly where those credentials were used.

  • ✗

    VPC Flow Logs.

    Why it's wrong here

    VPC Flow Logs capture IP traffic metadata for network interfaces within a VPC, not API calls made with IAM access keys, and cannot attribute requests to Bob. It is tempting because flow logs reveal source IPs for network connections, and would be correct for tracing traffic to EC2 instances rather than IAM API activity.

  • ✗

    Amazon CloudWatch Logs.

    Why it's wrong here

    CloudWatch Logs stores application and resource telemetry, not IAM credential usage records; it cannot attribute API calls to Bob's access keys. It is tempting because it aggregates logs centrally, and it would be correct for monitoring application errors or Lambda output, but source IP attribution for IAM principals requires CloudTrail event history.

  • ✗

    AWS IAM credential report.

    Why it's wrong here

    The IAM credential report lists users, access key ages, and rotation status, but contains no record of when or from where keys were used. It is tempting because it audits credential hygiene, and would be correct for identifying unused or stale keys, not for tracing source IP addresses over the past 30 days.

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.