Question

Difficulty: EasyCompliance and Governance

A global travel booking company is preparing for a security audit. The company needs to retrieve AWS compliance documentation, such as SOC reports, and also ensure that their stored customer databases are encrypted. Which of the following actions should the company perform to satisfy these compliance needs? (Select TWO.)

  1. Retrieve the compliance reports directly using the AWS Artifact consoleAnswer
  2. Enable and configure encryption for customer data stored in AWS databasesAnswer
  3. C
    Submit a request to AWS Support to retrieve the required compliance documents
  4. D
    Rely on AWS to automatically configure and manage the encryption of customer databases
  5. E
    Run Amazon Inspector to scan and generate the AWS infrastructure compliance reports

Answer

Retrieve the compliance reports directly using the AWS Artifact console, and enable and configure encryption for customer data stored in AWS databases
To retrieve AWS compliance documents like SOC reports, users must access AWS Artifact. To secure customer database contents, the customer must enable and manage encryption themselves, as data protection is a customer responsibility under the Shared Responsibility Model.

Step-by-Step Solution

1
Identify the AWS service dedicated to providing compliance reports.
AWS Artifact is identified as the portal to download SOC and ISO reports.
This satisfies the requirement to retrieve AWS compliance documentation.
2
Determine the party responsible for data encryption under the AWS Shared Responsibility Model.
Encrypting customer data is a customer responsibility ('security in the cloud').
This satisfies the requirement to ensure the customer databases are encrypted.

Key Concept

AWS Compliance and Shared Responsibility Model
Rate this question