A global travel booking company is preparing for a security audit. The company needs to retrieve AWS compliance documentation, such as SOC reports, and also ensure that their stored customer databases are encrypted. Which of the following actions should the company perform to satisfy these compliance needs? (Select TWO.)
- Retrieve the compliance reports directly using the AWS Artifact consoleAnswer
- Enable and configure encryption for customer data stored in AWS databasesAnswer
- CSubmit a request to AWS Support to retrieve the required compliance documents
- DRely on AWS to automatically configure and manage the encryption of customer databases
- ERun Amazon Inspector to scan and generate the AWS infrastructure compliance reports
Answer
Retrieve the compliance reports directly using the AWS Artifact console, and enable and configure encryption for customer data stored in AWS databases
To retrieve AWS compliance documents like SOC reports, users must access AWS Artifact. To secure customer database contents, the customer must enable and manage encryption themselves, as data protection is a customer responsibility under the Shared Responsibility Model.
Step-by-Step Solution
Key Concept
AWS Compliance and Shared Responsibility Model