A logistics company is preparing for an external audit to verify that its cloud infrastructure meets international compliance standards. The company needs to retrieve AWS security reports and determine which security tasks are managed directly by AWS. Which two of the following actions should the company take to meet these requirements?
- Download AWS compliance documents, such as SOC and PCI reports, using AWS ArtifactCevap
- Identify that physical security and infrastructure virtualization controls are managed by AWSCevap
- CSchedule an on-site physical inspection of the AWS data centers with AWS Support
- DRun Amazon Inspector to scan and generate third-party compliance certificates for AWS data centers
- EEnable AWS CloudTrail to monitor physical visitor access logs at the AWS data center facilities
Cevap
Downloading AWS compliance documents from AWS Artifact and identifying that physical security and infrastructure virtualization controls are managed by AWS.
AWS Artifact provides on-demand access to AWS security and compliance reports (such as SOC and PCI reports). Additionally, under the Shared Responsibility Model, AWS is responsible for 'security of the cloud,' which includes physical security of the data centers and the virtualization layer.
Adım Adım Çözüm
Anahtar Kavram
Retrieving AWS compliance reports and mapping shared responsibility boundaries.