Soru

Zorluk: OrtaCompliance and Governance

A media broadcasting company is preparing for an annual governance review of its cloud-based video archiving system. The governance team needs to acquire official AWS ISO 27001 certification documents and clarify how the security of AWS's physical infrastructure is validated. Which two of the following options represent correct actions or concepts that meet these requirements? (Select TWO.)

  1. Retrieve the AWS ISO 27001 certification report directly from AWS Artifact.Cevap
  2. Rely on AWS compliance reports for physical infrastructure security, as AWS is responsible for security of the cloud.Cevap
  3. C
    Run Amazon Inspector to scan and generate official AWS compliance certifications for the physical host servers.
  4. D
    Coordinate with AWS Support to perform an on-site physical security audit of the AWS data centers.
  5. E
    Enable Amazon CloudWatch to automatically download AWS compliance audits and service agreements.

Cevap

To meet the governance requirements, the company should retrieve the AWS ISO 27001 certification report directly from AWS Artifact, and rely on AWS compliance reports for physical infrastructure security, as AWS is responsible for security of the cloud.
Retrieving the AWS ISO 27001 certification report directly from AWS Artifact is correct because AWS Artifact is the self-service portal that provides on-demand access to AWS security and compliance reports. Relying on AWS compliance reports for physical infrastructure security is correct because, under the Shared Responsibility Model, AWS is responsible for security of the cloud (the physical infrastructure), and customers verify this inheritance through these reports.

Adım Adım Çözüm

1
Identify where to retrieve official AWS compliance documents.
AWS Artifact is identified as the portal providing on-demand access to AWS security and compliance reports (such as SOC and ISO certifications).
This resolves the requirement of acquiring the official AWS ISO 27001 certification.
2
Determine the boundary of security responsibility for physical infrastructure under the Shared Responsibility Model.
Under the model, AWS is responsible for security 'of' the cloud, which includes the physical infrastructure of data centers.
This clarifies how physical security is validated without needing custom audits.

Anahtar Kavram

AWS compliance reports retrieval via AWS Artifact and boundaries of physical security under the Shared Responsibility Model.
Bu soruyu puanla