A global financial technology (FinTech) company is preparing to launch a payment processing application on AWS. To meet regulatory compliance, the company needs to verify the physical security standards of the AWS data centers and retrieve the latest AWS System and Organization Controls (SOC) 1 report. Which of the following actions should the company take? (Select TWO.)
- Retrieve the AWS SOC 1 report directly from the AWS Artifact console.Cevap
- Rely on AWS to manage the physical security of the data centers under the Shared Responsibility Model.Cevap
- CSubmit a request to AWS Support to manually email the physical security logs and compliance reports.
- DConfigure AWS CloudTrail to monitor and log physical security events at AWS data center facilities.
- ECoordinate with AWS to install customized biometric access controls at the edge locations hosting the application.
Cevap
Retrieve the AWS SOC 1 report directly from the AWS Artifact console, and rely on AWS to manage the physical security of the data centers under the Shared Responsibility Model.
AWS compliance reports, including SOC reports, are retrieved on-demand from the AWS Artifact portal. Additionally, the Shared Responsibility Model outlines that AWS is solely responsible for physical security of its data centers, so the customer relies on AWS's compliance posture for physical infrastructure.
Adım Adım Çözüm
Anahtar Kavram
AWS Artifact is the primary portal for retrieving AWS compliance reports, and physical infrastructure security is managed by AWS under the Shared Responsibility Model.