Amazon
SCS-C02 · Question #160
A company uses an external identity provider to allow federation into different AWS accounts. A security engineer for the company needs to identify the federated user that terminated a production Amaz
Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #160. The question stem and answer options stay visible for context.
Submitted by lukas.cz· Mar 6, 2026Threat Detection and Incident Response
Question
A company uses an external identity provider to allow federation into different AWS accounts. A security engineer for the company needs to identify the federated user that terminated a production Amazon EC2 instance a week ago. What is the FASTEST way for the security engineer to identify the federated user?
Options
- AReview the AWS CloudTrail event history logs in an Amazon S3 bucket and look for the
- BFilter the AWS CloudTrail event history for the TerminateInstances event and identify the
- CSearch the AWS CloudTrail logs for the TerminateInstances event and note the event time.
- DUse Amazon Athena to run a SQL query on the AWS CloudTrail logs stored in an Amazon S3
Unlock SCS-C02 to see the answer
You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#CloudTrail event history#federated user identification#TerminateInstances#incident investigation