GCIH Securing Credentials and Data in Cloud Practice Question
An incident responder is analyzing a compromised AWS EC2 instance that was used to exfiltrate data from an S3 bucket. The attacker gained access by exploiting a server-side request forgery (SSRF) vulnerability in a web application running on the instance. The instance had an IAM role attached that allowed s3:GetObject on a sensitive bucket. Which of the following logs would provide the MOST direct evidence of the S3 data access by the attacker?
⚠ Common exam trap
It's easy for candidates to confuse CloudTrail management events with data events, or assuming that VPC Flow Logs can show application-level S3 access, when only data events capture object-level operations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail data events for the S3 bucket.
CloudTrail data events for S3 capture object-level API calls, including the identity of the caller (the IAM role) and the specific objects accessed. This directly evidences the exfiltration. Management events do not include data plane operations, S3 server access logs are less integrated, and VPC Flow Logs lack application-layer detail. Thus, CloudTrail data events are the most direct source.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon S3 server access logs.
Why it's wrong here
S3 server access logs provide detailed records about requests made to a bucket, including the requester, bucket name, request time, and operation. They can show GetObject requests, but they are not enabled by default and must be configured. CloudTrail data events are more integrated with AWS security services and provide a centralized log. However, server access logs could also provide evidence, but they are not as directly integrated with IAM identity information. The question asks for the MOST direct evidence; CloudTrail data events are more direct because they include the IAM role and are part of the CloudTrail audit trail.
- ✗
AWS CloudTrail management events for the S3 service.
Why it's wrong here
CloudTrail management events record control plane operations like CreateBucket, DeleteBucket, and PutBucketPolicy, but not object-level operations like GetObject. They would not show the actual data access. While they might show changes to bucket policies, the scenario involves reading objects, not modifying the bucket. Therefore, management events are insufficient to provide direct evidence of the exfiltration.
- ✓
AWS CloudTrail data events for the S3 bucket.
Why this is correct
CloudTrail data events capture object-level API activity for S3, such as GetObject, PutObject, and DeleteObject. Since the attacker used the instance's IAM role to call s3:GetObject, these events will record the API call, including the identity (the role), the source IP, and the object accessed. This provides direct evidence of the exfiltration. Management events would not capture the object-level access, so data events are essential.
- ✗
VPC Flow Logs for the EC2 instance's network interface.
Why it's wrong here
VPC Flow Logs capture IP traffic information, such as source and destination IP, ports, and protocol. They would show that the instance communicated with S3, but they do not provide application-layer details like the specific S3 API calls or objects accessed. They cannot distinguish between legitimate and malicious S3 access. Therefore, they are not the most direct evidence of the data exfiltration.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.