A pharmaceutical company is launching a new research database containing proprietary clinical trial data on AWS. To meet strict regulatory standards, the compliance team must download the AWS SOC 2 Type II report and verify that data protection standards are maintained. Which of the following actions must the company take to meet these compliance objectives? (Select TWO.)
- Retrieve the AWS SOC 2 Type II report through the self-service portal in AWS Artifact.Answer
- Enable encryption at rest for the Amazon RDS DB instances storing the clinical trial data.Answer
- CSubmit a request to the AWS Compliance team to email the confidential SOC 2 audit reports.
- DRely on AWS to manage operating system updates and security patches for the EC2 instances that access the database.
- EDeploy Amazon GuardDuty to automatically scan and remediate software licensing compliance issues on the database instances.
Answer
Retrieve the AWS SOC 2 Type II report through the self-service portal in AWS Artifact, and enable encryption at rest for the Amazon RDS DB instances storing the clinical trial data.
Retrieving compliance documents like SOC 2 reports is done via the self-service AWS Artifact console. Additionally, securing data at rest in Amazon RDS DB instances is a customer responsibility under the Shared Responsibility Model.
Step-by-Step Solution
Key Concept
AWS Compliance and the Shared Responsibility Model
Estimated Time:2m 0s