A software-as-a-service (SaaS) company providing human resources platform services is undergoing an external SOC 2 Type II audit. The audit team requires documentation verifying the security and compliance of the AWS physical infrastructure, and confirmation of how the SaaS company manages encryption keys for its application data. Which of the following actions should the company take to meet these audit requirements? (Select TWO.)
- Download the AWS SOC 2 report directly from AWS Artifact to provide to the auditorsCevap
- Manage customer-managed encryption keys for application data using AWS Key Management Service (AWS KMS)Cevap
- CSubmit a support ticket to schedule an on-site physical audit of the AWS data centers where their resources reside
- DConfigure Amazon GuardDuty to scan AWS hardware and generate the required compliance certifications
- ECreate an AWS CloudTrail trail to log and audit physical facility entry and exit logs of AWS technicians
Cevap
To meet these requirements, the company should download the AWS SOC 2 report directly from AWS Artifact to verify AWS infrastructure compliance, and manage application data encryption keys using AWS Key Management Service (AWS KMS) to fulfill their responsibility under the Shared Responsibility Model.
The correct options are downloading the AWS SOC 2 report from AWS Artifact and managing encryption keys using AWS Key Management Service (AWS KMS). AWS Artifact provides on-demand access to security and compliance reports (such as SOC and PCI reports) which verify the compliance of AWS physical infrastructure. Additionally, under the Shared Responsibility Model, the customer is responsible for data protection, which includes configuring encryption and managing keys using AWS KMS.
Adım Adım Çözüm
Anahtar Kavram
AWS Compliance and Governance and the Shared Responsibility Model
Tahmini Süre:1m 30s