CHFI Application, Email and Cloud Forensics Practice Question
A forensic investigator is analyzing a cloud environment hosted on Amazon Web Services (AWS). A compromised EC2 instance was used to exfiltrate data to an external IP address. The investigator needs to determine which AWS API calls were made to modify security groups to allow outbound traffic to that IP. Which AWS service should the investigator use to obtain this information?
⚠ Common exam trap
The trap here is assuming that VPC Flow Logs or AWS Config capture API call details, when they only show network traffic or resource configurations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail is the service that logs all API activity in an AWS account, including security group modifications. It captures the identity of the caller, the time, the source IP, and the request parameters. CloudWatch Logs, AWS Config, and VPC Flow Logs do not provide this level of API call detail. Therefore, CloudTrail is the correct source.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VPC Flow Logs
Why it's wrong here
VPC Flow Logs capture IP traffic information for network interfaces in a VPC, such as source and destination IP, ports, and protocol. They show that traffic occurred but do not record AWS API calls or security group modifications. Thus, they cannot identify who modified the security group or the API call parameters.
- ✗
AWS Config
Why it's wrong here
AWS Config records resource configurations and changes over time, including security group rules. It can show the state of a security group and changes, but it does not capture the API call details such as the identity of the caller or the source IP address. Therefore, it cannot provide the specific API call information required.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
CloudWatch Logs is used to store and analyze log data from various AWS services and applications, but it does not natively record AWS API calls unless specifically configured to ingest CloudTrail logs. On its own, CloudWatch Logs would not contain the API activity needed to identify security group modifications.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail records API activity in an AWS account, including calls to modify security groups (e.g., AuthorizeSecurityGroupEgress). By analyzing CloudTrail logs, the investigator can identify who made the API call, when, and from which IP address, and the parameters including the allowed IP. This directly answers the question.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.