Question

Difficulty: MediumCompliance and Governance

A global e-commerce corporation is preparing for an annual security audit to verify compliance with payment card industry and international security standards. The compliance team needs to obtain AWS's formal compliance reports and verify the division of security obligations for their hosted databases. Which of the following actions should the team perform to meet these compliance requirements? (Select TWO.)

  1. Download AWS SOC and PCI-DSS compliance reports directly from AWS ArtifactAnswer
  2. Review the AWS Shared Responsibility Model to identify which database security controls are managed by AWS versus the customerAnswer
  3. C
    Submit a request to AWS Support to configure and patch the operating systems of the hosted database instances
  4. D
    Use Amazon Inspector to retrieve the physical security certifications of AWS data centers
  5. E
    Configure Amazon CloudWatch to generate logs of all AWS API activity for compliance auditing

Answer

Downloading AWS SOC and PCI-DSS compliance reports directly from AWS Artifact, and reviewing the AWS Shared Responsibility Model to identify which database security controls are managed by AWS versus the customer.
AWS Artifact provides on-demand access to AWS security and compliance reports, such as SOC and PCI-DSS documents. Additionally, reviewing the AWS Shared Responsibility Model helps organizations clarify their compliance boundaries by defining which database security controls are AWS's responsibility and which must be managed by the customer.

Step-by-Step Solution

1
Access AWS Artifact to retrieve official compliance documents.
The team obtains the required SOC and PCI-DSS compliance reports directly from the console.
AWS Artifact is the primary portal for retrieving AWS's compliance reports and agreements.
2
Consult the AWS Shared Responsibility Model to determine security boundaries.
The team distinguishes database security controls managed by AWS (like physical hardware security) from customer-managed controls (like database configuration).
The Shared Responsibility Model clearly defines security obligations between AWS and the customer.

Key Concept

AWS Compliance and Governance via AWS Artifact and the Shared Responsibility Model
Estimated Time:1m 30s
Rate this question