Question

Difficulty: EasyCompliance and Governance

A healthcare startup needs to verify its compliance posture by reviewing official security documentation and accepting a Business Associate Addendum (BAA) with AWS. Which of the following actions can the startup perform using AWS Artifact to meet these requirements? (Select TWO.)

  1. Download AWS compliance reports, such as ISO certifications and SOC reports.Answer
  2. Review and accept agreements with AWS, such as the Business Associate Addendum (BAA).Answer
  3. C
    Perform automated vulnerability scans on Amazon EC2 instances to check for software patches.
  4. D
    Audit and record AWS API activities to track user configuration changes.
  5. E
    Manage the physical security and access controls of AWS data centers hosting the startup's resources.

Answer

The correct options are downloading AWS compliance reports (such as ISO certifications and SOC reports) and reviewing and accepting agreements with AWS (such as the Business Associate Addendum).
AWS Artifact is a self-service compliance portal. It allows customers to download AWS security and compliance documents (such as ISO certifications and SOC reports) and to review and accept agreements with AWS (such as the Business Associate Addendum needed for HIPAA compliance).

Step-by-Step Solution

1
Identify the AWS service that provides on-demand access to compliance documents and agreements.
AWS Artifact is the central portal for AWS compliance reports and agreements.
AWS Artifact is specifically designed to provide access to security documents and to allow accepting agreements like the Business Associate Addendum (BAA).
2
Determine which options correspond to the capabilities of AWS Artifact.
Downloading ISO/SOC reports and accepting agreements (like HIPAA BAA) are core features of AWS Artifact, whereas vulnerability scanning, API auditing, and physical security management are handled by Amazon Inspector, AWS CloudTrail, and AWS respectively.
This isolates the correct AWS Artifact features from other security services and shared responsibility boundaries.

Key Concept

AWS Artifact capabilities and compliance reporting
Rate this question