AnswerCorrect answer: A — GuardDuty InstanceCredentialExfiltration.OutsideAWS findings confirm instance credentials were used from an external account.
A company suspects that an attacker has exploited an overly permissive role to export credentials from Amazon EC2 instance metadata. The company uses Amazon GuardDuty and AWS Audit Manager. The company has enabled AWS CloudTrail logging and Amazon CloudWatch logging for all of its AWS accounts. A security engineer must determine if the credentials were used to access the company's resources from an external account. Which solution will provide this information?
Review GuardDuty findings to find InstanceCredentialExfiltration events. Correct Answer
Review assessment reports in the Audit Manager console to find InstanceCredentialExfiltration events.
Review CloudTrail logs for GetSessionToken API calls to AWS Security Token Service (AWS STS) that come from an account ID from outside the company.
Review CloudWatch logs for GetSessionToken API calls to AWS Security Token Service (AWS STS) that come from an account ID from outside the company.
Community Votes
A
60%
C
40%
60% of anonymous learners picked answer A.
Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
GuardDuty ingests CloudTrail and raises InstanceCredentialExfiltration.OutsideAWS when temporary EC2 instance credentials are used from outside AWS (an external IP or account). This managed finding is the purpose-built signal for exactly this exfiltration-and-external-use scenario, so reviewing GuardDuty is the direct way to confirm external-account usage.
A company suspects an attacker used an overly permissive role to export EC2 instance-profile credentials from metadata and then used them from an external account. GuardDuty's UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration.OutsideAWS finding specifically detects instance credentials being used from outside AWS, and its detail shows the external account/IP, directly answering whether the credentials were used from an external account.
Relying only on manual CloudTrail GetSessionToken log searches (option C). Instance credentials are used directly, not always via GetSessionToken, and GuardDuty's managed detection already correlates the metadata-exfiltration pattern; CloudTrail alone is a slower forensic path and can miss the pattern.
Community Discussion (11 comments)
AWSLoverLoverLoverLoverLover👍 1Selected: A
The correct answer is: A. Review GuardDuty findings to find InstanceCredentialExfiltration events. Explanation: AWS GuardDuty provides threat detection and automatically detects suspicious activities, including InstanceCredentialExfiltration events. The InstanceCredentialExfiltration finding in GuardDuty indicates that credentials from the EC2 instance metadata were potentially stolen and used outside of AWS. Since the company already uses GuardDuty, it is the best tool for detecting this type of attack quickly. D. CloudWatch logs store logs, but they do not provide the intelligence to detect credential exfiltration like GuardDuty does.
nznzwell👍 2Selected: C
The InstanceCredentialExfiltration finding is not guaranteed to be raised by GuardDuty. So A can be only used for alerts. For forensics, cloudtrail is the way to go, so C.
IPLogic👍 1Selected: A
The best solution to determine if the credentials were used to access the company’s resources from an external account is Option A: A. Review GuardDuty findings to find InstanceCredentialExfiltration events. Amazon GuardDuty is designed to detect suspicious activity, including the use of EC2 instance credentials from an external account1. It generates findings such as InstanceCredentialExfiltration events, which specifically indicate that instance credentials have been used from an IP address associated with a different AWS account1. This approach leverages GuardDuty’s built-in threat detection capabilities, providing a streamlined and automated way to identify potential security breaches with minimal manual effort. Options B, C, and D involve more manual log analysis and do not directly leverage GuardDuty’s specialized detection capabilities for this type of event.
GirishArora22👍 2Selected: A
Use managed solution instead of custom solution
xekiva3329👍 2Selected: A
My answer is A.
xekiva3329👍 2
My answer is A.
PegasusForever👍 4
My answer is A. https://aws.amazon.com/blogs/aws/amazon-guardduty-enhances-detection-of-ec2-instance-credential-exfiltration/
grekh001👍 3
A UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration.OutsideAWS Credentials that were created exclusively for an EC2 instance through an Instance launch role are being used from an external IP address. Default severity: High Data source: CloudTrail management events or S3 data events This finding informs you that a host outside of AWS has attempted to run AWS API operations using temporary AWS credentials that were created on an EC2 instance in your AWS environment. The listed EC2 instance might be compromised, and the temporary credentials from this instance might have been exfiltrated to a remote host outside of AWS.
aescudero51👍 1Selected: C
My answer is C. By reviewing CloudTrail logs for GetSessionToken calls originating from external accounts, the security engineer can identify attempts to use the stolen credentials to assume temporary roles within the company's AWS environment. This would be a strong indicator of compromised credentials.
5409b91👍 1Selected: C
i think C
Zek👍 4
A https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#unauthorizedaccess-iam-instancecredentialexfiltrationoutsideaws
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Log in to comment, report an error, or add a note about this question.
Expert Analysis
Why the Answer Is Correct
The InstanceCredentialExfiltration.OutsideAWS GuardDuty finding is generated when credentials created for an EC2 instance role are used from outside AWS, and it reports the external account or IP involved. Because the scenario is credentials exported from instance metadata and potentially used from an external account, GuardDuty findings provide the required confirmation with a managed, purpose-built detection.
Why the Other Options Are Wrong
B is wrong because AWS Audit Manager produces compliance assessment reports; it does not surface GuardDuty-style threat detections. C is a manual forensic alternative but instance credentials are often used directly rather than via GetSessionToken, so it can miss the activity and is less direct than the managed GuardDuty signal. D (CloudWatch logs) is wrong because GetSessionToken from STS is not necessarily logged to CloudWatch, and GuardDuty already correlates this from CloudTrail.
Community Comment Notes
Community favored A (60 votes), citing the GuardDuty blog and the finding-type doc showing the OutsideAWS detection. A minority argued C for forensics, noting GuardDuty findings are not guaranteed, but A is the managed, direct answer to the question.