Filter CloudTrail for TerminateInstances and review AssumeRoleWithSAML to identify the federated user

Answer Correct answer: B — filter CloudTrail event history for TerminateInstances, then review the AssumeRoleWithSAML call to name the federated user.

A company uses an external identity provider to allow federation into different AWS accounts. A security engineer for the company needs to identify the federated user that terminated a production Amazon EC2 instance a week ago. What is the FASTEST way for the security engineer to identify the federated user?

  1. Review the AWS CloudTrail event history logs in an Amazon S3 bucket and look for the TerminateInstances event to identify the federated user from the role session name.
  2. Filter the AWS CloudTrail event history for the TerminateInstances event and identify the assumed IAM role. Review the AssumeRoleWithSAML event call in CloudTrail to identify the corresponding username. Correct Answer
  3. Search the AWS CloudTrail logs for the TerminateInstances event and note the event time. Review the IAM Access Advisor tab for all federated roles. The last accessed time should match the time when the instance was terminated.
  4. Use Amazon Athena to run a SQL query on the AWS CloudTrail logs stored in an Amazon S3 bucket and filter on the TerminateInstances event. Identify the corresponding role and run another query to filter the AssumeRoleWithWebIdentity event for the user name.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

CloudTrail Event history covers 90 days and is filterable in the console, so a week-old event is in range; the TerminateInstances event shows the assumed role, and the paired AssumeRoleWithSAML event reveals the originating federated identity. S3/Glue/Athena (A/D) and IAM Access Advisor (C) are slower or indirect. Only B is fastest.

The fastest way to find which federated user terminated an EC2 instance a week ago is to filter CloudTrail event history (90-day window) for the TerminateInstances event to get the assumed role, then open the AssumeRoleWithSAML event to read the federated username from the role session name—all from the console without Athena or IAM Access Advisor.

Going to S3 and reading raw CloudTrail logs with Athena (A/D)—works but is slower than the console Event history filter for a 90-day event. Using IAM Access Advisor (C)—it shows last-accessed times, not the specific federated username behind an assumed role.

Community Discussion (4 comments)

jamesf 👍 1 Selected: B
keywords: FASTEST way, a week ago - within 90 days can be filtered on CloudTrail console.
FunkyFresco 👍 1 Selected: B
Option B is the correct answer.
Certified101 👍 2 Selected: B
B is correct
Zek 👍 4
B is correct https://aws.amazon.com/blogs/security/how-to-easily-identify-your-federated-users-by-using-aws-cloudtrail/ https://www.examtopics.com/discussions/amazon/view/47143-exam-aws-certified-security-specialty-topic-1-question-238/

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

CloudTrail Event history retains 90 days and is directly filterable in the console, so a week-old TerminateInstances event is in range. It identifies the assumed IAM role, and the corresponding AssumeRoleWithSAML event exposes the federated username via the role session name—the fastest path with no querying stack.

Why the Other Options Are Wrong

A and D require reading S3-backed logs via Athena, which is slower than the console filter for an event still inside the 90-day window. C relies on IAM Access Advisor last-accessed times, which do not name the specific federated user behind an assumed role. B is the fastest correct method.

Community Comment Notes

Community voted B (100). Commenters keyed on 'FASTEST' and 'a week ago' being inside the 90-day Event history window, and linked the CloudTrail federated-users doc. B was confirmed.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide