After noticing a billing anomaly, a security consultant finds that a former employee retained access for the past 30 days. With no prior activity monitoring in place, the consultant must quickly identify which resources this user created or modified. Which solution meets these needs?
Choose an answer
Tap an option to check your answer.
Correct answer: In AWS CloudTrail, filter the event history for the last 30 days. Create an Amazon Athena table with the data and partition it by event source..
Why this is the answer
The correct solution is to use AWS CloudTrail, filter the event history for the last 30 days, and then create an Amazon Athena table with the data, partitioned by event source. CloudTrail records API calls and related events, providing a detailed log of actions taken by users and roles. Filtering by the former employee's user name or access key within the last 30 days would directly reveal the resources they created or modified. Using Athena to query this data allows for efficient analysis of large log files. AWS Cost Explorer and Cost Anomaly Detection focus on billing and cost analysis, not on identifying specific resource creation or modification events by a particular user. AWS Audit Manager is for compliance and auditing, not for ad-hoc investigation of user activity.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed