Refer to the exhibit. A security analyst is investigating a potential unauthorized key pair creation. The CloudTrail log shows a successful CreateKeyPair event for an admin user. What additional step should the analyst take to determine if this was an authorized action?
Comparing the event's source IP against approved corporate ranges establishes whether the request originated from a trusted network or an external actor, directly addressing the authorisation question. CloudTrail records the sourceIPAddress field for every CreateKeyPair event, so this check reliably distinguishes legitimate administrative activity from credential compromise or misuse.
Why this answer
The first step in verifying whether a CreateKeyPair event was authorized is to check the source IP address against the company's approved IP ranges. CloudTrail logs include the sourceIPAddress field, which can be compared to a whitelist of administrative jump hosts or corporate VPN ranges. If the IP is outside those ranges, it strongly indicates unauthorized access, even if the user credentials were valid.
Exam trap
ISC2 often tests the misconception that the immediate response to a suspicious event should be a punitive action (like revoking privileges or deleting resources) rather than a methodical investigative step to confirm authorization.
How to eliminate wrong answers
Option A is wrong because immediately revoking all admin privileges is a drastic, premature action that could disrupt legitimate operations; the analyst must first gather evidence to confirm unauthorized activity. Option B is wrong because reviewing the key pair's usage to see if it was used to launch instances is a later forensic step, not the immediate action to determine authorization; a key pair can be created and used maliciously within seconds, and the creation event itself must be validated first. Option C is wrong because deleting the key pair immediately could destroy forensic evidence and alert an attacker, and it does not address the root cause of potential credential compromise.