ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 293 - CLF-C02 discussion

Report
Export

An auditor is preparing for an annual security audit. The auditor requests certification details for a company's AWS hosted resources across multiple Availability Zones in the us-east-1 Region.

How should the company respond to the auditor's request?

A.
Open an AWS Support ticket to request that the AWS technical account manager (TAM) respond and help the auditor.
Answers
A.
Open an AWS Support ticket to request that the AWS technical account manager (TAM) respond and help the auditor.
B.
Open an AWS Support ticket to request that the auditor receive approval to conduct an onsite assessment of the AWS data centers in which the company operates.
Answers
B.
Open an AWS Support ticket to request that the auditor receive approval to conduct an onsite assessment of the AWS data centers in which the company operates.
C.
Explain to the auditor that AWS does not need to be audited because the company's application is hosted in multiple Availability Zones.
Answers
C.
Explain to the auditor that AWS does not need to be audited because the company's application is hosted in multiple Availability Zones.
D.
Use AWS Artifact to download the applicable report for AWS security controls. Provide the report to the auditor.
Answers
D.
Use AWS Artifact to download the applicable report for AWS security controls. Provide the report to the auditor.
Suggested answer: D

Explanation:

AWS Artifact is your go-to, central resource for compliance-related information that matters to you. It provides on-demand access to AWS' security and compliance reports and select online agreements.

Reports available in AWS Artifact include our Service Organization Control (SOC) reports, Payment Card Industry (PCI) reports, and certifications from accreditation bodies across geographies and compliance verticals that validate the implementation and operating effectiveness of AWS security controls. Agreements available in AWS Artifact include the Business Associate Addendum (BAA) and the Nondisclosure Agreement (NDA). You can use AWS Artifact to download the applicable report for AWS security controls and provide it to the auditor.

asked 16/09/2024
Stefan Duerr
26 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first