A global logistics company needs to evaluate its cloud environment against the Federal Risk and Authorization Management Program (FedRAMP) requirements. The company must obtain official AWS compliance documents and verify which AWS services are compliant under the FedRAMP authorization boundary. Which of the following two actions should the company take to meet these requirements? (Select TWO.)
- Download the AWS FedRAMP partner package and authorization documents using AWS Artifact.Answer
- Consult the AWS Services in Scope by Compliance Program page to check service eligibility.Answer
- COpen a technical support ticket to request the official FedRAMP certificate directly from the AWS Support team.
- DArrange a site visit to the AWS physical data centers to conduct an independent verification of hardware compliance.
- ERun an Amazon Inspector assessment on the environment to automatically verify the physical security compliance of the AWS-managed hypervisors.
Answer
The correct actions are to download the AWS FedRAMP partner package and authorization documents using AWS Artifact, and to consult the AWS Services in Scope by Compliance Program page to check service eligibility.
The correct actions are to download the compliance documents using AWS Artifact and to consult the AWS Services in Scope by Compliance Program page. AWS Artifact is the official portal for self-service retrieval of security and compliance reports (such as FedRAMP, SOC, and PCI reports). The AWS Services in Scope by Compliance Program page lists all AWS services that meet specific compliance standards, allowing the customer to verify which services are compliant.
Step-by-Step Solution
Key Concept
Compliance and Governance