CHFI Application, Email and Cloud Forensics Practice Question
A cloud forensics investigator is analyzing an incident in AWS. The suspect is alleged to have deleted an S3 bucket. Which AWS service log would contain the DeleteBucket API call details, including the source IP and user identity?
⚠ Common exam trap
The CHFI exam often tests the distinction between management-plane logs (CloudTrail) and data-plane logs (S3 access logs), so candidates mistakenly choose S3 access logs thinking they capture bucket deletion, when in fact they only log object-level operations within the bucket.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail is the correct service because it records all API calls made to the AWS environment, including management-plane operations like DeleteBucket. Each CloudTrail event contains the source IP address, user identity (IAM user or role ARN), and the exact API action (DeleteBucket), making it the definitive log for investigating S3 bucket deletion incidents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the correct answer because it is the primary service for logging all API activity in AWS, including management events like DeleteBucket. It records the identity of the principal who made the call, the source IP, the timestamp, and the request parameters, providing a complete audit trail for investigating management-plane incidents. Without CloudTrail, you would lack the forensic evidence of who issued the destructive bucket deletion command.
- ✗
VPC Flow Logs
Why it's wrong here
VPC Flow Logs capture network traffic metadata, such as source and destination IP addresses, ports, and packet counts, for traffic flowing through your VPC. They do not log API calls or user actions at the management plane level, so they cannot reveal which principal issued a DeleteBucket command. While they may be useful for analyzing data exfiltration after a breach, they are irrelevant for identifying the API call itself.
- ✗
Amazon S3 access logs
Why it's wrong here
Amazon S3 access logs record object-level requests made to an S3 bucket, such as GET, PUT, and DELETE operations on individual objects. They do not include management API calls like DeleteBucket, which operates on the bucket itself rather than on an object within it. Even if server access logging is enabled, it will not show the bucket deletion event or the identity of the caller; that information resides only in CloudTrail.
- ✗
AWS Config
Why it's wrong here
AWS Config is a service that continuously records and evaluates resource configuration changes, and it can show the resulting state of a resource after a change (for example, that a bucket was removed). However, it does not log the API call that caused the change, nor does it record the identity of the principal who made the call. AWS Config is designed for compliance and configuration tracking, not for providing an audit trail of API activity, so it cannot answer 'who deleted the bucket and when'.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.