A global pharmaceutical firm is validating its drug development systems on Amazon EC2 for GxP (Good Practice) regulatory compliance. The auditors require the firm to provide official documentation of AWS's physical security certifications and verify who is responsible for patching the virtualization hypervisor host operating system. Which combination of actions correctly addresses these requirements?
- ARetrieve the compliance reports from AWS Artifact; the customer is responsible for patching the host operating system of the hypervisor.
- BRetrieve the compliance certificates from Amazon CloudWatch Logs; the customer is responsible for patching the guest operating system.
- Retrieve the compliance reports from AWS Artifact; AWS is responsible for patching the host operating system of the hypervisor.Cevap
- DUse Amazon Inspector to run a compliance scan on the physical hypervisors; AWS is responsible for patching the host operating system of the hypervisor.
Cevap
Retrieve the compliance reports from AWS Artifact; AWS is responsible for patching the host operating system of the hypervisor.
The correct action is retrieving the compliance reports from AWS Artifact, with AWS being responsible for patching the host operating system of the hypervisor. AWS Artifact is the central portal for accessing AWS's security and compliance documents on-demand. Under the Shared Responsibility Model, the customer is responsible for security 'in' the cloud (such as the guest OS on EC2), whereas AWS is responsible for security 'of' the cloud, which includes the physical servers, virtualization hypervisors, and host operating systems.
Adım Adım Çözüm
Anahtar Kavram
Retrieving AWS compliance documents using AWS Artifact and distinguishing patching responsibilities for host operating systems under the Shared Responsibility Model.
Tahmini Süre:2m 0s