Question

Difficulty: EasyCompliance and Governance

A healthcare startup must verify that AWS infrastructure meets compliance regulations for HIPAA and obtain SOC 2 reports for its investors. Which two tasks can the startup perform directly within AWS Artifact?

  1. Download AWS security and compliance documents, such as SOC and PCI reportsAnswer
  2. Review and accept AWS agreements, such as the HIPAA Business Associate Addendum (BAA)Answer
  3. C
    Open a technical support ticket to request copies of AWS compliance certificates
  4. D
    Scan Amazon EC2 instances for software vulnerabilities and regulatory compliance issues
  5. E
    Track and log API calls across AWS resources for auditing purposes

Answer

Downloading AWS compliance documents (such as SOC and PCI reports) and reviewing/accepting AWS agreements (such as the HIPAA Business Associate Addendum)
AWS Artifact is the primary self-service portal for on-demand access to AWS compliance reports, such as SOC and PCI reports, and is also used to review and accept AWS agreements like the HIPAA Business Associate Addendum (BAA) for individual accounts or entire organizations.

Step-by-Step Solution

1
Identify the service designed for retrieving AWS compliance documentation and managing AWS agreements.
AWS Artifact is identified as the central portal for these compliance resources.
AWS Artifact provides self-service access to compliance reports and agreements without requiring support tickets.
2
Filter options to find capabilities provided by AWS Artifact.
Downloading compliance reports and accepting HIPAA agreements are identified as valid AWS Artifact features.
This excludes distractors related to other AWS services like Amazon Inspector and AWS CloudTrail.

Key Concept

AWS Artifact provides self-service access to AWS compliance reports and agreements.
Rate this question