Courseiva

GCIH Securing Credentials and Data in Cloud Practice Question

An incident responder is analyzing a compromised AWS EC2 instance that was used to exfiltrate data from an S3 bucket. The attacker gained access by exploiting a server-side request forgery (SSRF) vulnerability in a web application running on the instance. The instance had an IAM role attached that allowed s3:GetObject on a sensitive bucket. Which of the following logs would provide the MOST direct evidence of the S3 data access by the attacker?

⚠ Common exam trap

It's easy for candidates to confuse CloudTrail management events with data events, or assuming that VPC Flow Logs can show application-level S3 access, when only data events capture object-level operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail data events for the S3 bucket.

CloudTrail data events for S3 capture object-level API calls, including the identity of the caller (the IAM role) and the specific objects accessed. This directly evidences the exfiltration. Management events do not include data plane operations, S3 server access logs are less integrated, and VPC Flow Logs lack application-layer detail. Thus, CloudTrail data events are the most direct source.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon S3 server access logs.

    Why it's wrong here

    S3 server access logs provide detailed records about requests made to a bucket, including the requester, bucket name, request time, and operation. They can show GetObject requests, but they are not enabled by default and must be configured. CloudTrail data events are more integrated with AWS security services and provide a centralized log. However, server access logs could also provide evidence, but they are not as directly integrated with IAM identity information. The question asks for the MOST direct evidence; CloudTrail data events are more direct because they include the IAM role and are part of the CloudTrail audit trail.

  • ✗

    AWS CloudTrail management events for the S3 service.

    Why it's wrong here

    CloudTrail management events record control plane operations like CreateBucket, DeleteBucket, and PutBucketPolicy, but not object-level operations like GetObject. They would not show the actual data access. While they might show changes to bucket policies, the scenario involves reading objects, not modifying the bucket. Therefore, management events are insufficient to provide direct evidence of the exfiltration.

  • ✓

    AWS CloudTrail data events for the S3 bucket.

    Why this is correct

    CloudTrail data events capture object-level API activity for S3, such as GetObject, PutObject, and DeleteObject. Since the attacker used the instance's IAM role to call s3:GetObject, these events will record the API call, including the identity (the role), the source IP, and the object accessed. This provides direct evidence of the exfiltration. Management events would not capture the object-level access, so data events are essential.

  • ✗

    VPC Flow Logs for the EC2 instance's network interface.

    Why it's wrong here

    VPC Flow Logs capture IP traffic information, such as source and destination IP, ports, and protocol. They would show that the instance communicated with S3, but they do not provide application-layer details like the specific S3 API calls or objects accessed. They cannot distinguish between legitimate and malicious S3 access. Therefore, they are not the most direct evidence of the data exfiltration.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.