An educational technology company is preparing for an audit of its online learning platform. The company needs to obtain official AWS compliance documents, such as SOC and PCI reports, and clarify the division of security responsibilities between the company and AWS for their Amazon EC2 instances. Which of the following actions should the company take to meet these compliance requirements? (Select TWO)
- Download the required compliance reports directly from AWS ArtifactCevap
- Apply security patches and updates to the guest operating systems of the EC2 instancesCevap
- CConfigure AWS Config to request and download the official AWS SOC 2 audit reports
- DContact AWS Support to request physical security access logs for the AWS data centers hosting their EC2 instances
- EEnable AWS CloudTrail to monitor the performance metrics and CPU utilization of the EC2 instances
Cevap
Downloading the required compliance reports directly from AWS Artifact, and applying security patches and updates to the guest operating systems of the EC2 instances.
AWS Artifact is the self-service portal where customers can download AWS compliance reports. Furthermore, under the AWS Shared Responsibility Model, the customer is responsible for guest operating system patching on Amazon EC2 instances.
Adım Adım Çözüm
Anahtar Kavram
AWS Artifact provides access to compliance reports, and the Shared Responsibility Model dictates that customers manage guest OS configuration on EC2.