An education technology company is preparing for an independent audit to verify its compliance with international security standards. The compliance team needs to obtain official documentation regarding the security of the AWS physical infrastructure and understand which compliance tasks remain the responsibility of the company. Which of the following actions should the company take to meet these requirements? (Select TWO.)
- Download the AWS ISO 27001 certification directly from AWS ArtifactCevap
- Configure and document the security settings of guest operating systems running on Amazon EC2 instancesCevap
- CUse Amazon Inspector to retrieve and download AWS System Organization Control (SOC) reports
- DSubmit a request to AWS Support to configure security groups and patch the guest operating systems on the company's EC2 instances
- EAnalyze AWS CloudTrail logs to audit physical visitor logs and access records of the AWS data centers
Cevap
The company should download the AWS ISO 27001 certification directly from AWS Artifact and configure and document the security settings of guest operating systems running on Amazon EC2 instances.
The correct answers identify downloading the compliance documents from AWS Artifact and managing guest operating system security as customer responsibilities. Under the Shared Responsibility Model, AWS maintains compliance and security audits of the physical infrastructure and virtualization layer, which customers can verify by downloading reports from AWS Artifact. Meanwhile, customers are fully responsible for the compliance, security configurations, and updates of the operating systems they run on their EC2 instances.
Adım Adım Çözüm
Anahtar Kavram
AWS Compliance and the Shared Responsibility Model