Question

Difficulty: MediumCompliance and Governance

A global logistics company needs to evaluate its cloud environment against the Federal Risk and Authorization Management Program (FedRAMP) requirements. The company must obtain official AWS compliance documents and verify which AWS services are compliant under the FedRAMP authorization boundary. Which of the following two actions should the company take to meet these requirements? (Select TWO.)

  1. Download the AWS FedRAMP partner package and authorization documents using AWS Artifact.Answer
  2. Consult the AWS Services in Scope by Compliance Program page to check service eligibility.Answer
  3. C
    Open a technical support ticket to request the official FedRAMP certificate directly from the AWS Support team.
  4. D
    Arrange a site visit to the AWS physical data centers to conduct an independent verification of hardware compliance.
  5. E
    Run an Amazon Inspector assessment on the environment to automatically verify the physical security compliance of the AWS-managed hypervisors.

Answer

The correct actions are to download the AWS FedRAMP partner package and authorization documents using AWS Artifact, and to consult the AWS Services in Scope by Compliance Program page to check service eligibility.
The correct actions are to download the compliance documents using AWS Artifact and to consult the AWS Services in Scope by Compliance Program page. AWS Artifact is the official portal for self-service retrieval of security and compliance reports (such as FedRAMP, SOC, and PCI reports). The AWS Services in Scope by Compliance Program page lists all AWS services that meet specific compliance standards, allowing the customer to verify which services are compliant.

Step-by-Step Solution

1
Identify the requirement to retrieve AWS compliance reports and verify which services are compliant.
Recognize that AWS compliance documents must be obtained securely, and the scope of compliant services must be checked.
To ensure audit readiness and verify that only approved services are used in the compliant workload.
2
Determine the appropriate AWS tools and resources for these tasks.
Identify AWS Artifact as the central portal for security reports and the AWS Services in Scope webpage as the definitive directory for service compliance.
AWS Artifact provides self-service access to compliance reports, and the Services in Scope page details which services comply with specific standards.

Key Concept

Compliance and Governance
Rate this question