CHFI Application, Email and Cloud Forensics Practice Question
In cloud forensics, which AWS service provides a centralized log of API calls made by users and services, often used to investigate unauthorized access or configuration changes?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail records all API calls for governance, compliance, and operational auditing, making it essential for forensic investigations in AWS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudWatch
Why it's wrong here
CloudWatch is an operational monitoring service that ingests metrics, logs, and alarms; it does not natively generate or maintain a chronological record of AWS API calls. Although CloudTrail can send API event history to CloudWatch Logs for alerting, CloudWatch itself is a downstream consumer, not the centralized audit source that forensics would rely on.
- ✓
AWS CloudTrail
Why this is correct
CloudTrail is the correct AWS service because it continuously records API activity across your account, capturing each call's identity, source IP, timestamp, request parameters, and response elements. It delivers immutable event history to S3 for long-term retention and enables centralized, cross-region and cross-account trails, making it the primary evidence source for reconstructing attacker actions during forensic investigations.
- ✗
AWS Config
Why it's wrong here
AWS Config tracks resource configuration changes, configuration history, and compliance against rules, but it does not record API calls or the identity of the principal who made them. Its configuration snapshots reveal what changed and when, yet lack the who, how, and request-level detail needed for forensic analysis of API-level abuse, so it complements CloudTrail rather than replacing it.
- ✗
AWS VPC Flow Logs
Why it's wrong here
VPC Flow Logs capture metadata about network traffic at the elastic network interface level, such as source/destination IP, ports, protocol, and packet/byte counts. They do not log control-plane API calls, user identities, or request payloads, so while they can reveal network communication with compromised resources, they cannot answer which API action was invoked or by which IAM principal.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.