Soru

Zorluk: OrtaCompliance and Governance

An education technology company is preparing for an independent audit to verify its compliance with international security standards. The compliance team needs to obtain official documentation regarding the security of the AWS physical infrastructure and understand which compliance tasks remain the responsibility of the company. Which of the following actions should the company take to meet these requirements? (Select TWO.)

  1. Download the AWS ISO 27001 certification directly from AWS ArtifactCevap
  2. Configure and document the security settings of guest operating systems running on Amazon EC2 instancesCevap
  3. C
    Use Amazon Inspector to retrieve and download AWS System Organization Control (SOC) reports
  4. D
    Submit a request to AWS Support to configure security groups and patch the guest operating systems on the company's EC2 instances
  5. E
    Analyze AWS CloudTrail logs to audit physical visitor logs and access records of the AWS data centers

Cevap

The company should download the AWS ISO 27001 certification directly from AWS Artifact and configure and document the security settings of guest operating systems running on Amazon EC2 instances.
The correct answers identify downloading the compliance documents from AWS Artifact and managing guest operating system security as customer responsibilities. Under the Shared Responsibility Model, AWS maintains compliance and security audits of the physical infrastructure and virtualization layer, which customers can verify by downloading reports from AWS Artifact. Meanwhile, customers are fully responsible for the compliance, security configurations, and updates of the operating systems they run on their EC2 instances.

Adım Adım Çözüm

1
Identify where to retrieve AWS's third-party compliance reports.
AWS Artifact is recognized as the correct portal for downloading compliance reports like ISO certifications and SOC reports.
AWS provides on-demand access to its compliance documentation to help customers verify AWS infrastructure security.
2
Determine the customer's responsibilities for compliance under the Shared Responsibility Model.
The customer is responsible for the configuration, maintenance, and security of guest operating systems running on EC2.
AWS manages security of the cloud (infrastructure, physical hosts), whereas customers manage security in the cloud (guest OS, applications, data).

Anahtar Kavram

AWS Compliance and the Shared Responsibility Model
Bu soruyu puanla