An online retail company is expanding its operations to new regions and must verify that the underlying AWS infrastructure meets both PCI DSS and ISO 27001 standards. Which of the following actions should the company take to verify AWS compliance and clarify security boundaries? (Select TWO.)
- Download the AWS ISO 27001 certification and PCI DSS compliance packages from AWS Artifact.Cevap
- Review the AWS Shared Responsibility Model to identify which security controls are managed by AWS and which are the customer's responsibility.Cevap
- CUse Amazon Inspector to download and review AWS System and Organization Control (SOC) reports.
- DSchedule a physical audit of the AWS data centers with the AWS Security Team to verify environmental controls.
- EDeploy AWS CloudTrail to automatically patch guest operating systems on Amazon EC2 instances.
Cevap
To verify compliance and understand security boundaries, the company should download the AWS compliance packages from AWS Artifact and review the AWS Shared Responsibility Model.
Verifying AWS compliance is done by retrieving official audit reports and certifications from AWS Artifact. Understanding security boundaries requires reviewing the AWS Shared Responsibility Model, which defines the security obligations of both AWS and the customer.
Adım Adım Çözüm
Anahtar Kavram
AWS Artifact provides compliance reports, while the Shared Responsibility Model defines security boundaries.