Question

Difficulty: HardCompliance and Governance

An energy technology provider is migrating its financial billing system to AWS. The company's compliance department needs to obtain a confidential AWS System and Organization Controls (SOC) 1 Type II report to prove to their external auditors that the AWS infrastructure controls are operating effectively. Which AWS resource should the company use to locate, accept the terms of, and download this report?

  1. A
    AWS Support
  2. B
    AWS CloudTrail
  3. AWS ArtifactAnswer
  4. D
    AWS Config

Answer

AWS Artifact
AWS Artifact is the go-to portal for downloading AWS compliance documents, such as SOC 1, SOC 2, and PCI DSS reports. It provides a secure, self-service interface where customers can accept the terms of the documents and download them to share with external auditors.

Step-by-Step Solution

1
Determine the user's primary requirement.
The requirement is to retrieve AWS's own third-party security and compliance reports (SOC 1 Type II).
This establishes the scope as compliance report retrieval rather than active resource monitoring or account log auditing.
2
Evaluate the capabilities of the available AWS security and governance services.
AWS Artifact provides on-demand access to AWS compliance reports and agreements. AWS Config monitors resource configurations. AWS CloudTrail records API calls. AWS Support manages customer cases.
This highlights the differences in service purposes to find the correct tool.
3
Select the correct service based on the evaluated capabilities.
AWS Artifact is the specific portal where customers accept agreements and download SOC and PCI reports.
Only AWS Artifact meets the direct, self-service download requirement for the SOC 1 Type II report.

Key Concept

AWS Artifact serves as the central, self-service portal for accessing AWS compliance reports, including SOC, PCI, and ISO certifications.
Rate this question