An analyst is reviewing a cloud-based incident in Cortex XDR (such as AWS or Azure activity). Which evidence source provides the primary forensic logs for cloud resource modifications?
Cloud API activity logs record who performed what action on cloud resources and when.
Why this answer
Cloud infrastructure logs (like AWS CloudTrail or Azure Activity logs) ingested into Cortex XDR provide the audit trail for cloud resource changes.