What is the FASTEST way for the security engineer to identify the federated user?

2 Comments

  1. Jessica
    Author

    I weigh that the answer is:
    Filter the AWS CloudTrail event history for the TerminateInstances event and identify the assumed IAM role. Review the AssumeRoleWithSAML event call in CloudTrail to identify the corresponding username.

  2. Ryan
    Author

    In my opinion, the answer is:
    Filter the AWS CloudTrail event history for the TerminateInstances event and identify the assumed IAM role. Review the AssumeRoleWithSAML event call in CloudTrail to identify the corresponding username.

Leave a Reply

Your email address will not be published. Required fields are marked *

1 × one =