Courseiva

AWS CloudTrail to Identify API Calls

In an AWS environment, a security analyst detects unusual API calls that created several IAM users with administrative privileges from an unfamiliar IP address. Which AWS service log should be examined first to identify the specific API calls and the IAM user that made them?

Quick Answer

The answer is AWS CloudTrail. This is the correct choice because CloudTrail is the dedicated AWS service for recording all API activity, including the specific API calls that create IAM users with administrative privileges. Every action taken via the AWS Management Console, CLI, or SDK is logged as an event, capturing critical forensic details such as the source IP address, the identity of the IAM user who made the call, and the exact API action performed (e.g., CreateUser, AttachUserPolicy). On the Computer Hacking Forensic Investigator CHFI exam, this question tests your ability to map cloud forensic artifacts to the appropriate log source, a common scenario in incident response. A frequent trap is confusing CloudTrail with AWS Config or VPC Flow Logs, but remember: CloudTrail is for who did what and when, while Config tracks resource configuration changes. For a quick memory tip, think of CloudTrail as the “call log” for your AWS environment—if an API call was made, CloudTrail has the receipt.

⚠ Common exam trap

EC-CHFI often tests the distinction between CloudTrail (API activity logging) and CloudWatch Logs (monitoring and log aggregation), leading candidates to mistakenly choose CloudWatch Logs because they think 'logs' implies all logging, but CloudTrail is the specific service for API call auditing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail

AWS CloudTrail is the correct service because it records all API calls made to the AWS environment, including the identity of the caller (IAM user or role), the source IP address, and the specific API actions (e.g., CreateUser, AttachUserPolicy). In this scenario, CloudTrail logs will directly show which IAM user made the unusual API calls from the unfamiliar IP address, enabling the analyst to trace the unauthorized activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon S3 access logs

    Why it's wrong here

    S3 access logs record object-level requests against buckets, not IAM API activity, so they cannot reveal who called CreateUser or CreateAccessKey. They are tempting because they do capture requester identity and source IP, but only for data-plane S3 operations — the correct choice, CloudTrail, records the management events in question.

  • ✗

    AWS CloudWatch Logs

    Why it's wrong here

    CloudWatch Logs stores application, system and custom log streams; it does not natively capture IAM management API calls unless CloudTrail is already forwarding them there. It is tempting as a central log repository, but the audit record of who invoked CreateUser lives in CloudTrail, which the scenario requires first.

  • ✓

    AWS CloudTrail

    Why this is correct

    CloudTrail records every AWS API call with the calling identity, source IP and timestamp, so the CreateUser and AttachUserPolicy events reveal both the IAM user and the unfamiliar address. This directly satisfies the stem's need to identify the specific API calls and their originator.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config records resource configuration states and changes over time, so it would show that IAM users exist and when their configuration altered, but not the API caller's identity or source IP. It is tempting for detecting drift, yet CloudTrail is the service that logs the actual CreateUser and CreateAccessKey API events.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CHFI

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. During a cloud forensic investigation, an analyst needs to identify who deleted an S3 bucket in an AWS environment. Which AWS service log should the analyst examine to find the API call and the associated IAM user or role?

medium
  • ✓ A.AWS CloudTrail
  • B.Amazon S3 server access logs
  • C.AWS Config
  • D.Amazon CloudWatch Logs

Why A: AWS CloudTrail records API calls made to AWS services, including S3 bucket deletion, along with the identity of the caller.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.