Soru

Zorluk: OrtaCompliance and Governance

An educational technology company is preparing for an audit of its online learning platform. The company needs to obtain official AWS compliance documents, such as SOC and PCI reports, and clarify the division of security responsibilities between the company and AWS for their Amazon EC2 instances. Which of the following actions should the company take to meet these compliance requirements? (Select TWO)

  1. Download the required compliance reports directly from AWS ArtifactCevap
  2. Apply security patches and updates to the guest operating systems of the EC2 instancesCevap
  3. C
    Configure AWS Config to request and download the official AWS SOC 2 audit reports
  4. D
    Contact AWS Support to request physical security access logs for the AWS data centers hosting their EC2 instances
  5. E
    Enable AWS CloudTrail to monitor the performance metrics and CPU utilization of the EC2 instances

Cevap

Downloading the required compliance reports directly from AWS Artifact, and applying security patches and updates to the guest operating systems of the EC2 instances.
AWS Artifact is the self-service portal where customers can download AWS compliance reports. Furthermore, under the AWS Shared Responsibility Model, the customer is responsible for guest operating system patching on Amazon EC2 instances.

Adım Adım Çözüm

1
Identify the service needed to access and retrieve official AWS compliance documentation, such as SOC or PCI reports.
AWS Artifact is the central portal for downloading these reports.
AWS Artifact provides on-demand access to AWS compliance documentation and reports.
2
Determine the division of responsibility under the Shared Responsibility Model for Amazon EC2 instances.
The customer is responsible for the guest operating system patching and configuration, while AWS is responsible for physical security of data centers.
Amazon EC2 is an Infrastructure as a Service (IaaS) offering, giving the customer complete control over the guest OS, including patches.

Anahtar Kavram

AWS Artifact provides access to compliance reports, and the Shared Responsibility Model dictates that customers manage guest OS configuration on EC2.
Bu soruyu puanla