Question

Difficulty: MediumCompliance and Governance

An online retail company is expanding its operations to new regions and must verify that the underlying AWS infrastructure meets both PCI DSS and ISO 27001 standards. Which of the following actions should the company take to verify AWS compliance and clarify security boundaries? (Select TWO.)

  1. Download the AWS ISO 27001 certification and PCI DSS compliance packages from AWS Artifact.Answer
  2. Review the AWS Shared Responsibility Model to identify which security controls are managed by AWS and which are the customer's responsibility.Answer
  3. C
    Use Amazon Inspector to download and review AWS System and Organization Control (SOC) reports.
  4. D
    Schedule a physical audit of the AWS data centers with the AWS Security Team to verify environmental controls.
  5. E
    Deploy AWS CloudTrail to automatically patch guest operating systems on Amazon EC2 instances.

Answer

To verify compliance and understand security boundaries, the company should download the AWS compliance packages from AWS Artifact and review the AWS Shared Responsibility Model.
Verifying AWS compliance is done by retrieving official audit reports and certifications from AWS Artifact. Understanding security boundaries requires reviewing the AWS Shared Responsibility Model, which defines the security obligations of both AWS and the customer.

Step-by-Step Solution

1
Identify the AWS tool used to download official compliance reports and certifications.
AWS Artifact provides on-demand access to compliance reports (like PCI DSS and ISO certifications).
The company needs official documentation of AWS's infrastructure compliance for their expansion.
2
Determine how to clarify the division of security obligations between AWS and the company.
The AWS Shared Responsibility Model outlines which controls are the responsibility of AWS (security of the cloud) and which are the customer's responsibility (security in the cloud).
Understanding security boundaries prevents configuration gaps and misalignments during audits.

Key Concept

AWS Artifact provides compliance reports, while the Shared Responsibility Model defines security boundaries.
Rate this question