Soru

Zorluk: ZorCompliance and Governance

A global pharmaceutical firm is validating its drug development systems on Amazon EC2 for GxP (Good Practice) regulatory compliance. The auditors require the firm to provide official documentation of AWS's physical security certifications and verify who is responsible for patching the virtualization hypervisor host operating system. Which combination of actions correctly addresses these requirements?

  1. A
    Retrieve the compliance reports from AWS Artifact; the customer is responsible for patching the host operating system of the hypervisor.
  2. B
    Retrieve the compliance certificates from Amazon CloudWatch Logs; the customer is responsible for patching the guest operating system.
  3. Retrieve the compliance reports from AWS Artifact; AWS is responsible for patching the host operating system of the hypervisor.Cevap
  4. D
    Use Amazon Inspector to run a compliance scan on the physical hypervisors; AWS is responsible for patching the host operating system of the hypervisor.

Cevap

Retrieve the compliance reports from AWS Artifact; AWS is responsible for patching the host operating system of the hypervisor.
The correct action is retrieving the compliance reports from AWS Artifact, with AWS being responsible for patching the host operating system of the hypervisor. AWS Artifact is the central portal for accessing AWS's security and compliance documents on-demand. Under the Shared Responsibility Model, the customer is responsible for security 'in' the cloud (such as the guest OS on EC2), whereas AWS is responsible for security 'of' the cloud, which includes the physical servers, virtualization hypervisors, and host operating systems.

Adım Adım Çözüm

1
Identify the service for obtaining official AWS compliance certifications and reports.
AWS Artifact is the dedicated self-service portal that provides on-demand access to AWS security and compliance reports (such as ISO certifications and SOC reports).
Auditors require third-party validated reports proving that the physical infrastructure hosting EC2 meets GxP security standards.
2
Determine the boundary of responsibility for patching the host operating system of the hypervisor.
Under the AWS Shared Responsibility Model, AWS is responsible for the infrastructure components, which include physical security, virtualization hypervisors, and the host operating system.
Since customers do not have access to the physical servers or hypervisor layer, AWS must manage and patch the host operating system.

Anahtar Kavram

Retrieving AWS compliance documents using AWS Artifact and distinguishing patching responsibilities for host operating systems under the Shared Responsibility Model.
Tahmini Süre:2m 0s
Bu soruyu puanla