A company suspects an attacker exploited an overly permissive role to extract credentials from Amazon EC2 instance metadata. The company uses Amazon GuardDuty and AWS Audit Manager, and has AWS CloudTrail and Amazon CloudWatch logging enabled across all accounts. A security engineer must determine whether the stolen credentials were used from outside the company’s accounts to access company resources. Which solution provides this information?
Choose an answer
Tap an option to check your answer.
Correct answer: Review GuardDuty findings for InstanceCredentialExfiltration events..
Why this is the answer
The correct answer is to review GuardDuty findings for InstanceCredentialExfiltration events. GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior. An InstanceCredentialExfiltration finding specifically indicates that temporary AWS credentials from an EC2 instance have been exfiltrated and are being used from an unusual location, which directly addresses the scenario of stolen credentials being used externally. Reviewing assessment reports in AWS Audit Manager is incorrect because Audit Manager helps manage compliance and audit readiness by collecting evidence, but it does not directly detect real-time security threats like credential exfiltration. Examining CloudTrail or CloudWatch logs for GetSessionToken API calls from an external account ID is also incorrect. While CloudTrail logs API calls and CloudWatch can store and analyze these logs, GetSessionToken is used to obtain temporary credentials and doesn't inherently indicate external usage of stolen credentials. GuardDuty's InstanceCredentialExfiltration finding is specifically designed to identify the malicious use of exfiltrated instance credentials.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed