CHFI Application, Email and Cloud Forensics Practice Question
An incident responder is analyzing AWS CloudTrail logs to determine if an unauthorized user accessed an S3 bucket. Which of the following CloudTrail event fields should be examined to identify the IAM user or role that made the API call?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
userIdentity
The userIdentity field contains details about the identity that made the request, including ARN, user name, and type (IAM user, role, etc.).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
sourceIPAddress
Why it's wrong here
`sourceIPAddress` records the IP address from which the request was made, but it does not reveal the IAM principal. An IP can be shared by multiple users (e.g., behind NAT, a bastion host, or VPC endpoint) and can be spoofed or represent an AWS service, so it cannot reliably attribute the action to a specific identity.
- ✗
eventSource
Why it's wrong here
`eventSource` identifies the AWS service that the API call targeted (e.g., `ec2.amazonaws.com`, `s3.amazonaws.com`), not the user who invoked it. While useful for understanding which service's APIs were called during an incident, it provides no information about the IAM user, role, or account that performed the action, and thus cannot answer 'who did this?'.
- ✗
requestParameters
Why it's wrong here
`requestParameters` contains the input parameters of the API request (such as bucket names, object keys, or instance IDs), which describe the specific resource acted upon. This helps answer 'what did they access?' but says nothing about the caller's identity. Even a full request body without the principal context leaves the actor unknown, so it is not the field for identity resolution.
- ✓
userIdentity
Why this is correct
`userIdentity` is the correct field because CloudTrail populates it with the identity of the principal that made the request. It includes the type (IAMUser, AssumedRole, Root, etc.), the ARN, the account ID, the access key ID, and—for temporary credentials—the session context. This is the definitive attribute for mapping an event to a specific IAM user or role and is essential for attribution during incident response.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.