A municipal public transit authority is migrating its ticketing database and web applications to the AWS Cloud. During an audit, the compliance officer asks who is responsible for configuring firewall rules (such as security groups) to protect the applications, and how the authority can verify AWS's physical infrastructure compliance. Which of the following statements correctly identifies the responsibility mapping and the service needed to retrieve the necessary AWS compliance reports?
- The customer is responsible for configuring security groups; AWS compliance documents are retrieved using AWS Artifact.Answer
- BAWS is responsible for configuring security groups; AWS compliance documents are retrieved using AWS Artifact.
- CThe customer is responsible for configuring security groups; AWS compliance documents are retrieved using AWS CloudTrail.
- DThe customer is responsible for configuring security groups; AWS compliance documents are retrieved using AWS Trusted Advisor.
Answer
The customer is responsible for configuring security groups, and AWS compliance documents are retrieved using AWS Artifact.
Under the AWS Shared Responsibility Model, the customer is responsible for security 'in' the cloud, which includes defining firewall rules via security groups. To download AWS's official compliance documentation (like ISO and PCI certifications), the customer must use AWS Artifact, which is the central portal for these agreements and reports.
Step-by-Step Solution
Key Concept
Understanding compliance reports retrieval and the Shared Responsibility Model boundaries.
Estimated Time:1m 0s