A SOC analyst notices an unexpected change to an IAM role in a cloud environment and needs to determine which user created it and from which IP address. Which data source should the analyst query first to reconstruct the control-plane action?
Select an answer to reveal the explanation.
Short Explanation
Think of cloud control-plane activity like a building’s badge-reader log: it tells you who opened what door, not what happened inside the room. If you need the user, IP, and timestamp behind an IAM change, go to the cloud audit log first. Don’t chase endpoint or flow telemetry when the answer is already in the management API record.
Full Explanation
Cloud control-plane actions are recorded by the provider’s audit logs, which capture management API calls such as creating or modifying IAM roles, network configurations, or storage policies. These logs identify the authenticated principal, source IP address, timestamp, and request parameters, making them the appropriate source for reconstructing who performed a suspicious administrative action and where it originated. Endpoint detection and response telemetry focuses on processes, file activity, and command execution inside workloads, so it may reveal post-compromise host behavior but not the cloud management API event itself. NetFlow data summarizes packet or flow metadata across interfaces, which can show communication patterns but does not contain the API actor, action, or request details required for an identity-based control-plane change. Antivirus quarantine events are endpoint file-control records and similarly do not describe cloud identity or configuration API operations. Exam caveat: distinguish control-plane activity, which is management API and identity change, from data-plane activity, which is workload or user traffic behavior. Operational check: query the cloud audit log for the IAM role creation event, then correlate the principal, source IP, timestamp, and request parameters against known administrative baselines.