A global e-commerce corporation is preparing for an annual security audit to verify compliance with payment card industry and international security standards. The compliance team needs to obtain AWS's formal compliance reports and verify the division of security obligations for their hosted databases. Which of the following actions should the team perform to meet these compliance requirements? (Select TWO.)
- Download AWS SOC and PCI-DSS compliance reports directly from AWS ArtifactAnswer
- Review the AWS Shared Responsibility Model to identify which database security controls are managed by AWS versus the customerAnswer
- CSubmit a request to AWS Support to configure and patch the operating systems of the hosted database instances
- DUse Amazon Inspector to retrieve the physical security certifications of AWS data centers
- EConfigure Amazon CloudWatch to generate logs of all AWS API activity for compliance auditing
Answer
Downloading AWS SOC and PCI-DSS compliance reports directly from AWS Artifact, and reviewing the AWS Shared Responsibility Model to identify which database security controls are managed by AWS versus the customer.
AWS Artifact provides on-demand access to AWS security and compliance reports, such as SOC and PCI-DSS documents. Additionally, reviewing the AWS Shared Responsibility Model helps organizations clarify their compliance boundaries by defining which database security controls are AWS's responsibility and which must be managed by the customer.
Step-by-Step Solution
Key Concept
AWS Compliance and Governance via AWS Artifact and the Shared Responsibility Model
Estimated Time:1m 30s