Chapter 13: AWS Risk and Complia

2018-07-22  本文已影响19人  K1024

Chapter 13: AWS Risk and Compliance

  1. A, B, C. Answers A through C describe valid mechanisms that AWS uses to communicate with customers regarding its security and control environment. AWS does not allow customers’ auditors direct access to AWS data centers, infrastructure, or staff.
  1. C. The shared responsibility model can include IT controls, and it is not just limited to security considerations. Therefore, answer C is correct.
  1. A. AWS provides IT control information to customers through either specific control definitions or general control standard compliance.
  1. A, B, D. There is no such thing as a SOC 4 report, therefore answer C is incorrect.
  1. A. IT governance is still the customer’s responsibility.
  1. D. Any number of components of a workload can be moved into AWS, but it is the customer’s responsibility to ensure that the entire workload remains compliant with various certifications and third-party attestations.
  1. B. An Availability Zone consists of multiple discrete data centers, each with their own redundant power and networking/connectivity, therefore answer B is correct.
  1. A, C. AWS regularly scans public-facing, non-customer endpoint IP addresses and notifies appropriate parties. AWS does not scan customer instances, and customers must request the ability to perform their own scans in advance, therefore answers A and C are correct.
  1. B. AWS publishes information publicly online and directly to customers under NDA, but customers are not required to share their use and configuration information with AWS, therefore answer B is correct.
  1. C. AWS has developed a strategic business plan, and customers should also develop and maintain their own risk management plans, therefore answer C is correct.
  1. B. The collective control environment includes people, processes, and technology necessary to establish and maintain an environment that supports the operating effectiveness of AWS control framework. Energy is not a discretely identified part of the control environment, therefore B is the correct answer.
  1. D. Customers are responsible for ensuring all of their security group configurations are appropriate for their own applications, therefore answer D is correct.
  1. C. Customers should ensure that they implement control objectives that are designed to meet their organization’s own unique compliance requirements, therefore answer C is correct.

知识点总结

上一篇下一篇

猜你喜欢

热点阅读