Soru

Zorluk: ZorCompliance and Governance

An enterprise client in the financial sector is undergoing an annual Payment Card Industry Data Security Standard (PCI DSS) compliance audit. The external auditors require official proof of compliance for the physical and environmental security controls of the AWS data centers where the client's applications are hosted. Which AWS service should the security team use to obtain the necessary reports, and how is the responsibility for physical security partitioned in this context?

  1. AWS Artifact is used to retrieve the PCI DSS Attestation of Compliance (AoC); AWS is solely responsible for managing the physical security and environmental controls of its data centers.Cevap
  2. B
    AWS Config is used to retrieve the PCI DSS Attestation of Compliance (AoC); the customer is responsible for auditing the physical access controls of the data centers.
  3. C
    AWS CloudTrail is used to retrieve the PCI DSS Attestation of Compliance (AoC); AWS is solely responsible for managing the physical security and environmental controls of its data centers.
  4. D
    AWS Artifact is used to retrieve the PCI DSS Attestation of Compliance (AoC); the customer is responsible for implementing physical and environmental controls within their virtual private cloud (VPC).

Cevap

AWS Artifact is used to retrieve the PCI DSS Attestation of Compliance (AoC); AWS is solely responsible for managing the physical security and environmental controls of its data centers.
The correct option correctly identifies AWS Artifact as the service for downloading compliance documents and accurately maps data center physical security as the sole responsibility of AWS under the Shared Responsibility Model.

Adım Adım Çözüm

1
Identify the service required to retrieve compliance documents.
AWS Artifact is the primary portal for downloading compliance reports and agreements (such as SOC and PCI reports).
The scenario requires official proof of compliance (PCI DSS Attestation of Compliance) which is distributed directly via AWS Artifact.
2
Determine the party responsible for data center physical and environmental security.
AWS is solely responsible for the physical security of data centers.
Under the AWS Shared Responsibility Model, physical infrastructure, hypervisor virtualization, and data center facilities fall under 'security of the cloud' and are the sole responsibility of AWS.

Anahtar Kavram

AWS compliance report retrieval and the division of physical security under the Shared Responsibility Model.
Bu soruyu puanla