Courseiva
mediumMultiple Choice

CCSP Using AWS CloudTrail to log API calls Practice Question

A company is using AWS CloudTrail to log API calls. A security analyst needs to be alerted when an IAM user creates a new access key for another user. Which CloudTrail event should be monitored?

⚠ Common exam trap

ISC2 often tests the distinction between API actions that create versus modify versus delete resources, and the trap here is confusing 'CreateAccessKey' with 'UpdateAccessKey' because both involve access keys, but only 'CreateAccessKey' generates a new credential.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CreateAccessKey

The correct event to monitor is 'CreateAccessKey' because this is the CloudTrail event name generated when an IAM user creates a new access key for another user. AWS CloudTrail logs all IAM API calls, and the event name directly corresponds to the API action invoked (CreateAccessKey). Monitoring this event allows the security analyst to detect unauthorized creation of access keys, which is a common privilege escalation or persistence technique.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    CreateAccessKey

    Why this is correct

    CreateAccessKey is the CloudTrail management event logged when an IAM user generates a new access key, including for another user. Monitoring this event name detects the exact activity described, since CloudTrail records the API call with its parameters and identity.

  • ✗

    DeleteAccessKey

    Why it's wrong here

    DeleteAccessKey records removal of an existing access key, so it cannot detect the creation event the analyst needs. It is tempting because key lifecycle monitoring often pairs creation with deletion, and DeleteAccessKey would be the right event when auditing credential revocation or investigating keys removed after suspected compromise.

  • ✗

    CreateUser

    Why it's wrong here

    CreateUser records creation of a new IAM user, not an access key for an existing one. It is the right event when alerting on new identities being provisioned, but the scenario concerns credentials issued to another user.

  • ✗

    UpdateAccessKey

    Why it's wrong here

    UpdateAccessKey fires when an existing key's status changes, such as activating or deactivating it, so it never records key creation. It is tempting because it is the only other IAM key-management event, and it would be the right choice for alerting on a key being re-enabled after suspected compromise.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.