An Audit company is currently carrying out an audit of your infrastructure.
They want to know if security procedures, compliance, standards and regulations have been correctly followed at the data centres that host the AWS resources.
Which of the following would you, as a SysOps Administrator, use to fulfil this requirement?
Click on the arrows to vote for the correct answer
A. B. C. D.Correct Answer: D.
AWS Artifact provides on-demand downloads of AWS security and compliance documents, such as AWS ISO certifications, Payment Card Industry (PCI), and Service Organization Control (SOC) reports.
You can submit the security and compliance documents (also known as audit artifacts) to your auditors or regulators to demonstrate the security and compliance of the AWS infrastructure and services that you use.
You can also use these documents as guidelines to evaluate your own cloud architecture and assess the effectiveness of your company's internal controls.
Options A, B and C are incorrect.
For more information on AWS Artifact, please visit the following URL-
https://aws.amazon.com/artifact/As a SysOps Administrator, to fulfill the requirement of an audit company verifying that security procedures, compliance, standards and regulations have been correctly followed at the data centers hosting AWS resources, the appropriate choice would be to use a document from the AWS Artifact web service (option D).
AWS Artifact is a service that provides on-demand access to AWS compliance reports, certifications, and other related documents. It provides audit reports and other compliance-related documents that help customers and auditors verify that the proper controls are in place to secure AWS resources.
Using a document from the AWS Artifact web service provides verifiable proof of compliance with security procedures, compliance, standards and regulations. This will help in satisfying the requirements of the audit company without the need for them to physically visit the data centers (option A). Sending a copy of the AWS Security Whitepapers (option B) would not provide adequate proof of compliance with security procedures and regulations. Contacting an AWS Direct Connect partner (option C) is not relevant to this requirement, as the partner provides a network connection between the customer's data center and AWS resources.