Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 395 discussion

An IAM user made several configuration changes to AWS resources in their company's account during a production deployment last week. A solutions architect learned that a couple of security group rules are not configured as desired. The solutions architect wants to confirm which IAM user was responsible for making changes.

Which service should the solutions architect use to find the desired information?

  • A. Amazon GuardDuty
  • B. Amazon Inspector
  • C. AWS CloudTrail
  • D. AWS Config
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
cegama543
Highly Voted 1 year, 7 months ago
Selected Answer: C
C. AWS CloudTrail The best option is to use AWS CloudTrail to find the desired information. AWS CloudTrail is a service that enables governance, compliance, operational auditing, and risk auditing of AWS account activities. CloudTrail can be used to log all changes made to resources in an AWS account, including changes made by IAM users, EC2 instances, AWS management console, and other AWS services. By using CloudTrail, the solutions architect can identify the IAM user who made the configuration changes to the security group rules.
upvoted 12 times
...
BatVanyo
Most Recent 5 months, 4 weeks ago
Selected Answer: C
I was initially a bit confused on what Config and CloudTrail actually do, as both can be used to track configuration changes. However, this explanation is probably the best one I have come across so far: "Config reports on what has changed, whereas CloudTrail reports on who made the change, when, and from which location" Since the question is which IAM user was responsible for making the changes, the answer is CloudTrail.
upvoted 3 times
...
d401c0d
6 months, 2 weeks ago
Selected Answer: C
CloudTrail = which user made which api calls. This is used for audit purpose.
upvoted 2 times
...
sheq
10 months, 1 week ago
This question is the same with the question 388, isn't it?
upvoted 1 times
...
kambarami
1 year, 1 month ago
This is how you know not to trust the moderators with their answers.
upvoted 1 times
...
Wayne23Fang
1 year, 1 month ago
There is an article "How to use AWS Config and CloudTrail to find who made changes to a resource" in aws blog. Given CloudTrail provided AWS config original info, it seems for this particular one, C is better than AWS config.
upvoted 2 times
...
Guru4Cloud
1 year, 1 month ago
Selected Answer: C
AWS CloudTrail is the correct service to use here to identify which user was responsible for the security group configuration changes
upvoted 1 times
...
TariqKipkemei
1 year, 4 months ago
Selected Answer: C
AWS CloudTrail
upvoted 1 times
...
Bezha
1 year, 7 months ago
Selected Answer: C
AWS CloudTrail
upvoted 1 times
...
[Removed]
1 year, 7 months ago
Selected Answer: C
C. AWS CloudTrail
upvoted 2 times
...
kprakashbehera
1 year, 7 months ago
Selected Answer: C
CloudTrail logs will tell who did that
upvoted 2 times
...
KAUS2
1 year, 7 months ago
Selected Answer: C
Option "C" AWS CloudTrail is correct.
upvoted 2 times
...
Nithin1119
1 year, 7 months ago
cccccc
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...