An IAM user's access key was accidentally published in a public repository. The SysOps administrator must determine what actions the compromised key was used to perform. Which method should be used to identify actions taken with that key during the suspected timeframe?
Choose an answer
Tap an option to check your answer.
Correct answer: Search the AWS CloudTrail event history for events that were initiated using the exposed access key during the relevant period..
Why this is the answer
CloudTrail records API calls and related events made in your AWS account, including the identity of the caller (which would be the compromised access key in this scenario). Searching CloudTrail event history for the specific access key during the suspected timeframe is the most direct and effective way to identify all actions performed with it. Creating an EventBridge rule to forward IAM events to Lambda is proactive for future monitoring but won't help analyze past events. CloudWatch Logs Insights queries EC2 logs, which primarily contain OS-level or application logs, not AWS API calls made by an access key. VPC Flow Logs capture network traffic information, not details about which IAM principal initiated AWS API actions.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed