SOA-C02 Security and Compliance Practice Question
Network Topology
A SysOps administrator is investigating a security incident where an unauthorized key pair was created. The CloudTrail lookup command output is shown. The administrator wants to find the source IP address of the 'admin' user who created the key pair. Which field in the 'CloudTrailEvent' JSON should the administrator examine?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
sourceIPAddress
The source IP address of the API call is recorded in the 'sourceIPAddress' field within the CloudTrail event JSON. Therefore, option C is correct. Option A (requestParameters) contains the parameters of the request, not the IP. Option B (userIdentity) contains information about the user identity, not the IP. Option D (eventTime) is the timestamp.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
requestParameters
Why it's wrong here
The requestParameters field in a CloudTrail record contains the API parameters that were passed with the request, such as resource identifiers, names, and action-specific inputs. It does not, however, include any information about the network source, so an administrator analyzing a security incident would find no IP address to attribute the activity. For locating the origin of the request, one must consult the sourceIPAddress field.
- ✗
userIdentity
Why it's wrong here
The userIdentity element provides details about the principal who made the request, including the ARN, the type (such as RootUser, IAMUser, AssumedRole), and often the AWS account ID. While this is valuable for determining which identity was used, it does not capture the network address of the caller, and for incident investigation it cannot be used to pinpoint the IP address of the request. The source IP is stored separately in the sourceIPAddress field.
- ✓
sourceIPAddress
Why this is correct
The sourceIPAddress field in an AWS CloudTrail event is the authoritative record of the IP address from which the request was made, whether over the internet or from within a VPC via a VPC endpoint. This field is the primary evidence for tracing the original network source of suspicious API calls, and it is the correct answer for the security incident in question. It may contain a public IPv4/IPv6 address or, in some scenarios, the private IP of a proxy, so it must be interpreted carefully.
- ✗
eventTime
Why it's wrong here
The eventTime field records the exact timestamp, down to milliseconds, of when the request was processed, which is critical for establishing a timeline of events during an incident investigation. However, it provides no information about the origin of the traffic, so it cannot tell you which IP made the request. To identify the source, you must examine the sourceIPAddress field.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.