AWS CloudTrail to Identify API Calls
In an AWS environment, a security analyst detects unusual API calls that created several IAM users with administrative privileges from an unfamiliar IP address. Which AWS service log should be examined first to identify the specific API calls and the IAM user that made them?
Quick Answer
The answer is AWS CloudTrail. This is the correct choice because CloudTrail is the dedicated AWS service for recording all API activity, including the specific API calls that create IAM users with administrative privileges. Every action taken via the AWS Management Console, CLI, or SDK is logged as an event, capturing critical forensic details such as the source IP address, the identity of the IAM user who made the call, and the exact API action performed (e.g., CreateUser, AttachUserPolicy). On the Computer Hacking Forensic Investigator CHFI exam, this question tests your ability to map cloud forensic artifacts to the appropriate log source, a common scenario in incident response. A frequent trap is confusing CloudTrail with AWS Config or VPC Flow Logs, but remember: CloudTrail is for who did what and when, while Config tracks resource configuration changes. For a quick memory tip, think of CloudTrail as the “call log” for your AWS environment—if an API call was made, CloudTrail has the receipt.
⚠ Common exam trap
EC-CHFI often tests the distinction between CloudTrail (API activity logging) and CloudWatch Logs (monitoring and log aggregation), leading candidates to mistakenly choose CloudWatch Logs because they think 'logs' implies all logging, but CloudTrail is the specific service for API call auditing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail is the correct service because it records all API calls made to the AWS environment, including the identity of the caller (IAM user or role), the source IP address, and the specific API actions (e.g., CreateUser, AttachUserPolicy). In this scenario, CloudTrail logs will directly show which IAM user made the unusual API calls from the unfamiliar IP address, enabling the analyst to trace the unauthorized activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon S3 access logs
Why it's wrong here
S3 access logs record object-level requests against buckets, not IAM API activity, so they cannot reveal who called CreateUser or CreateAccessKey. They are tempting because they do capture requester identity and source IP, but only for data-plane S3 operations — the correct choice, CloudTrail, records the management events in question.
- ✗
AWS CloudWatch Logs
Why it's wrong here
CloudWatch Logs stores application, system and custom log streams; it does not natively capture IAM management API calls unless CloudTrail is already forwarding them there. It is tempting as a central log repository, but the audit record of who invoked CreateUser lives in CloudTrail, which the scenario requires first.
- ✓
AWS CloudTrail
Why this is correct
CloudTrail records every AWS API call with the calling identity, source IP and timestamp, so the CreateUser and AttachUserPolicy events reveal both the IAM user and the unfamiliar address. This directly satisfies the stem's need to identify the specific API calls and their originator.
- ✗
AWS Config
Why it's wrong here
AWS Config records resource configuration states and changes over time, so it would show that IAM users exist and when their configuration altered, but not the API caller's identity or source IP. It is tempting for detecting drift, yet CloudTrail is the service that logs the actual CreateUser and CreateAccessKey API events.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CHFI
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. During a cloud forensic investigation, an analyst needs to identify who deleted an S3 bucket in an AWS environment. Which AWS service log should the analyst examine to find the API call and the associated IAM user or role?
medium- ✓ A.AWS CloudTrail
- B.Amazon S3 server access logs
- C.AWS Config
- D.Amazon CloudWatch Logs
Why A: AWS CloudTrail records API calls made to AWS services, including S3 bucket deletion, along with the identity of the caller.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.