An online education platform is expanding its services to support medical residency programs and needs to ensure compliance with the Health Insurance Portability and Accountability Act (HIPAA). To do this, the platform's administrator needs to review AWS security documentation and formally accept the AWS Business Associate Addendum (BAA). Which of the following tasks can the administrator perform using AWS Artifact to meet these requirements? (Select TWO.)
- Download AWS compliance reports, such as SOC and PCI-DSS documents, to review the security controls of AWS infrastructureAnswer
- Formally accept agreements with AWS, such as the Business Associate Addendum (BAA) for HIPAA complianceAnswer
- CTrack and log API activity across the AWS account to audit user actions and meet compliance logging requirements
- DRun automated vulnerability scans on Amazon EC2 instances to verify they meet compliance patch standards
- ERequest an on-site physical audit of AWS data centers to verify physical security compliance
Answer
Downloading AWS compliance reports to review security controls of the AWS infrastructure and formally accepting agreements with AWS, such as the Business Associate Addendum (BAA), are correct.
AWS Artifact serves as the self-service portal to download AWS security and compliance reports (such as SOC and PCI reports) and to manage and accept agreements (such as the BAA for HIPAA compliance).
Step-by-Step Solution
Key Concept
AWS Artifact provides on-demand access to AWS compliance reports and allows customers to accept agreements like the Business Associate Addendum (BAA).