CloudTrail Event Analysis Quiz

5 questions Pass: 70% +25 pts

Quiz covering Logging and Analysis

CloudTrail Event Analysis Quiz

5 questions | Pass: 70% | Earn 25 points

Questions in this quiz

A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.

  1. 1

    Which of the following fields in a CloudTrail log entry identifies the IAM user or role that performed the API call?

  2. 2

    You notice an 'AccessDenied' error in your CloudTrail logs. Which field should you examine to determine which specific IAM policy or SCP denied the request?

  3. 3

    A security analyst is investigating a suspicious API call. Which field is most useful for determining the geographic origin of the request?

  4. 4

    If a CloudTrail event has 'readOnly' set to 'true', what does this imply about the API call?

  5. 5

    You are auditing CloudTrail logs for potential 'AssumeRole' abuse. You see an event where 'userIdentity.type' is 'AssumedRole', but the 'arn' in 'userIdentity.sessionContext.sessionIssuer' does not match the expected source role. What does this indicate?