Leadership asks who changed the S3 bucket policy on the municipal data lake. Which telemetry answers that control-plane question?
Select an answer to reveal the explanation.
Short Explanation
Who edited the bucket policy is a cloud control-plane question, not a badge-swipe. Pull AWS CloudTrail or Azure activity logs for that data-lake account—the pump-station gate never signed the API call.
Full Explanation
Cloud control-plane changes such as an S3 bucket-policy update are recorded in provider activity and audit logs (AWS CloudTrail, Azure Activity Log, or equivalent). Those logs identify the principal, API, resource, and time. Physical badge events, DNS queries, and library catalog tables do not capture IAM or storage-policy changes. Civic analysts should match the question to cloud audit telemetry rather than on-prem physical or DNS sources.