CloudTrail Event Analysis Quiz
Quiz covering Logging and Analysis
CloudTrail Event Analysis Quiz
5 questions | Pass: 70% | Earn 25 points
Questions in this quiz
A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.
- 1
Which of the following fields in a CloudTrail log entry identifies the IAM user or role that performed the API call?
- 2
You notice an 'AccessDenied' error in your CloudTrail logs. Which field should you examine to determine which specific IAM policy or SCP denied the request?
- 3
A security analyst is investigating a suspicious API call. Which field is most useful for determining the geographic origin of the request?
- 4
If a CloudTrail event has 'readOnly' set to 'true', what does this imply about the API call?
- 5
You are auditing CloudTrail logs for potential 'AssumeRole' abuse. You see an event where 'userIdentity.type' is 'AssumedRole', but the 'arn' in 'userIdentity.sessionContext.sessionIssuer' does not match the expected source role. What does this indicate?
- Amazon GuardDuty Configuration
- Amazon GuardDuty Configuration Quiz5q
- GuardDuty Runtime Monitoring
- GuardDuty Runtime Monitoring Quiz5q
- Security Hub Aggregation
- Security Hub Aggregation Quiz5q
- AWS Security Finding Format (ASFF)
- AWS Security Finding Format (ASFF) Quiz5q
- Amazon Inspector Scanning
- Amazon Inspector Scanning Quiz5q
Enjoying the courses?
Everything stays free. Pro shows fewer ads, doubles the points you earn on every lesson and quiz so you progress twice as fast, unlocks half of every practice exam — plus full case studies — with the Learn & Exam study modes, and lets you read each lesson on one page.
- ✓ Fewer advertisements
- ✓ 2× points per lesson & quiz
- ✓ 50% of every exam unlocked
- ✓ Learn & Exam modes
- ✓ Distraction-free lessons