A logistics enterprise is migrating its supply chain systems to AWS and must verify that the AWS infrastructure aligns with global security standards. The compliance team needs to access AWS's independent third-party audit reports and accept online agreements to meet regulatory requirements. Which of the following actions should the team perform? (Select TWO.)
- Download AWS security and compliance documents, such as SOC and ISO reports, directly from AWS Artifact.Answer
- Accept AWS compliance agreements, such as Business Associate Addendums (BAAs), within the AWS Artifact portal.Answer
- CSubmit a support ticket to the AWS Support team to request manual delivery of the AWS compliance certifications.
- DUse Amazon Inspector to perform a compliance scan on the physical hardware and hypervisors managed by AWS.
- EQuery Amazon CloudWatch logs to retrieve the audit trail of API operations performed by AWS infrastructure engineers.
Answer
To obtain AWS compliance documentation and verify compliance, the team must download security reports directly from AWS Artifact and accept compliance agreements in the AWS Artifact portal.
The correct options are downloading compliance documents from AWS Artifact and accepting compliance agreements directly within the AWS Artifact portal. AWS Artifact is a self-service portal that provides on-demand access to AWS security and compliance reports and select online agreements.
Step-by-Step Solution
Key Concept
AWS Artifact is the central self-service repository for retrieving AWS compliance reports and managing compliance agreements.