During a post-incident review of an AWS serverless workload, you learn that a Lambda function may have been triggered directly through the AWS InvokeFunction API instead of through the public API Gateway. You need a log that shows each invocation and identifies the IAM principal that made the call. Which AWS log source satisfies this requirement?
CloudWatch Logs produced by the Lambda runtime
AWS CloudTrail data event logs for the Lambda function
AWS Trusted Advisor checks
VPC Flow Logs that capture the function's ENI traffic
When you enable AWS CloudTrail data events for Lambda, CloudTrail records every InvokeFunction and Invoke API call. Each entry includes the userIdentity object, revealing the IAM user, role, or session that invoked the function, along with request parameters and timestamps. CloudWatch Logs only contain the function's runtime output, VPC Flow Logs provide network metadata without IAM identity, and Trusted Advisor offers configuration guidance rather than transactional logs.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AWS CloudTrail?
Open an interactive chat with Bash
What are data events in AWS CloudTrail?
Open an interactive chat with Bash
How does IAM relate to AWS CloudTrail logs?
Open an interactive chat with Bash
What is AWS CloudTrail data event logging?
Open an interactive chat with Bash
How does the userIdentity object in CloudTrail logs help in identifying IAM principals?
Open an interactive chat with Bash
What is the difference between CloudTrail and CloudWatch Logs in AWS Lambda monitoring?
Open an interactive chat with Bash
Certified Ethical Hacker (CEH)
Cloud Computing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .