Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

An incident responder is analyzing AWS CloudTrail logs to determine if an unauthorized user accessed an S3 bucket. Which of the following CloudTrail event fields should be examined to identify the IAM user or role that made the API call?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

userIdentity

The userIdentity field contains details about the identity that made the request, including ARN, user name, and type (IAM user, role, etc.).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    sourceIPAddress

    Why it's wrong here

    `sourceIPAddress` records the IP address from which the request was made, but it does not reveal the IAM principal. An IP can be shared by multiple users (e.g., behind NAT, a bastion host, or VPC endpoint) and can be spoofed or represent an AWS service, so it cannot reliably attribute the action to a specific identity.

  • ✗

    eventSource

    Why it's wrong here

    `eventSource` identifies the AWS service that the API call targeted (e.g., `ec2.amazonaws.com`, `s3.amazonaws.com`), not the user who invoked it. While useful for understanding which service's APIs were called during an incident, it provides no information about the IAM user, role, or account that performed the action, and thus cannot answer 'who did this?'.

  • ✗

    requestParameters

    Why it's wrong here

    `requestParameters` contains the input parameters of the API request (such as bucket names, object keys, or instance IDs), which describe the specific resource acted upon. This helps answer 'what did they access?' but says nothing about the caller's identity. Even a full request body without the principal context leaves the actor unknown, so it is not the field for identity resolution.

  • ✓

    userIdentity

    Why this is correct

    `userIdentity` is the correct field because CloudTrail populates it with the identity of the principal that made the request. It includes the type (IAMUser, AssumedRole, Root, etc.), the ARN, the account ID, the access key ID, and—for temporary credentials—the session context. This is the definitive attribute for mapping an event to a specific IAM user or role and is essential for attribution during incident response.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.