CHFI Application, Email and Cloud Forensics Practice Question
During a cloud forensic investigation, an analyst needs to identify who deleted an S3 bucket in an AWS environment. Which AWS service log should the analyst examine to find the API call and the associated IAM user or role?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail records API calls made to AWS services, including S3 bucket deletion, along with the identity of the caller.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail is the primary forensic source because it records management events in the S3 control plane, including the DeleteBucket API call that removes a bucket. Each event captures the calling user's IAM identity or federated principal, source IP address, event time, and request parameters, enabling attribution. CloudTrail is enabled by default for management events, preserving this evidence without pre-provisioning.
- ✗
Amazon S3 server access logs
Why it's wrong here
Amazon S3 server access logs capture data-plane requests such as GET, PUT, and DELETE objects, not control-plane operations like the DeleteBucket management API. While these logs include requester details and are useful for object-level forensic analysis, bucket deletion is a management event that S3 server access logging does not reliably record, and it is best attributed using CloudTrail. Additionally, server access logs are disabled by default, so they cannot be assumed available.
- ✗
AWS Config
Why it's wrong here
AWS Config continuously records resource configuration changes and can show that an S3 bucket transitioned to deleted, but its Configuration Items contain only the resource configuration and the recording timestamp, not the principal or session that initiated the deletion. AWS Config does not audit API activity; it only reports state changes. User identity for the change must be determined by correlating with CloudTrail, which has the API-call context.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
Amazon CloudWatch Logs is a log storage and monitoring service that only contains whatever you explicitly send it, such as application logs or CloudTrail events if you configure a destination. By default, it does not capture AWS API-call activity, so it cannot independently identify who deleted an S3 bucket. Only when CloudTrail is configured to deliver events to a log group would the data appear, but CloudWatch itself is not a source of audit trail.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.