A healthcare startup is preparing for an external audit to verify compliance with HIPAA and SOC standards for its platform hosted on AWS. Which of the following actions should the startup take to meet these compliance requirements? (Select TWO.)
- Download official AWS compliance documents, such as SOC reports, using AWS Artifact.Cevap
- Accept the Business Associate Addendum (BAA) with AWS using AWS Artifact.Cevap
- CRequest physical datacenter security audits by submitting a ticket to AWS Support.
- DUtilize Amazon Inspector to automatically apply security patches to the physical hypervisors hosting EC2 instances.
- EConfigure AWS CloudTrail to monitor and block non-compliant API calls in real time.
Cevap
Downloading official AWS compliance documents (such as SOC reports) using AWS Artifact, and accepting the Business Associate Addendum (BAA) with AWS using AWS Artifact.
The correct options are downloading AWS compliance documents like SOC reports through AWS Artifact, and accepting the Business Associate Addendum (BAA) using AWS Artifact. AWS Artifact serves as the direct portal for accessing compliance documentation and formalizing agreements required for regulatory frameworks like HIPAA.
Adım Adım Çözüm
Anahtar Kavram
Using AWS Artifact for compliance report retrieval and agreement management under the Shared Responsibility Model.