CHFI Application, Email and Cloud Forensics Practice Question
During a cloud forensics investigation, an analyst examines AWS CloudTrail logs and finds an event with "userIdentity":{"type":"AssumedRole","arn":"arn:aws:sts::123456789012:assumed-role/AdminRole/i-0abcd1234efgh5678"}. What does the 'i-0abcd1234efgh5678' portion most likely represent?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The session name, which is typically the EC2 instance ID
In CloudTrail, when an EC2 instance assumes a role, the session name is often the instance ID. The 'i-' prefix and alphanumeric string indicate an EC2 instance ID.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The AWS account ID of the role's trusted entity
Why it's wrong here
The AWS account ID of the role's trusted entity is shown as the numeric accountId in the CloudTrail userIdentity, and it merely identifies the AWS account that owns the role. It never holds the EC2 instance ID; the session name is a separate component embedded in the principalId and in the assumed-role ARN. Reading the account ID would let you confirm the owning account, but it cannot tell you which EC2 instance assumed the role.
- ✗
The role's unique identifier assigned by IAM
Why it's wrong here
A role's unique IAM identifier is the prefix such as AROA..., not the text after the colon in CloudTrail's principalId. In an AssumedRole userIdentity, the full principalId is formatted as AROAROLEID:sessionName, so the role ID isolates the role definition while the suffix is the session name. The IAM role ID alone tells you only which role was used, not which particular EC2 instance invoked it.
- ✗
The unique ID of the IAM user who assumed the role
Why it's wrong here
The unique ID of an IAM user (AIDA...) does not appear when a role is assumed, because an EC2 instance cannot authenticate as an IAM user. In the sessionContext, the sessionIssuer block lists the role's ARN, and the userName field contains the role name rather than any user identifier. Therefore, trying to read the session name as an IAM user's unique ID would be incorrect and would hide the instance ID that is actually embedded in the session name suffix.
- ✓
The session name, which is typically the EC2 instance ID
Why this is correct
The session name is the correct field because, when an EC2 instance obtains temporary credentials through an instance profile, CloudTrail records that session name as the EC2 instance ID. It appears after the colon in the principalId, for example AROAI... : i-1234567890abcdef0, and as the final segment of the assumed-role ARN. Correlating this suffix with EC2 instance IDs enables the analyst to identify the exact instance that made the API call. This is why the session name, and not the role ID or account ID, is the key forensic attribute in this scenario.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.