A healthcare startup needs to verify its compliance posture by reviewing official security documentation and accepting a Business Associate Addendum (BAA) with AWS. Which of the following actions can the startup perform using AWS Artifact to meet these requirements? (Select TWO.)
- Download AWS compliance reports, such as ISO certifications and SOC reports.Answer
- Review and accept agreements with AWS, such as the Business Associate Addendum (BAA).Answer
- CPerform automated vulnerability scans on Amazon EC2 instances to check for software patches.
- DAudit and record AWS API activities to track user configuration changes.
- EManage the physical security and access controls of AWS data centers hosting the startup's resources.
Answer
The correct options are downloading AWS compliance reports (such as ISO certifications and SOC reports) and reviewing and accepting agreements with AWS (such as the Business Associate Addendum).
AWS Artifact is a self-service compliance portal. It allows customers to download AWS security and compliance documents (such as ISO certifications and SOC reports) and to review and accept agreements with AWS (such as the Business Associate Addendum needed for HIPAA compliance).
Step-by-Step Solution
Key Concept
AWS Artifact capabilities and compliance reporting