An external auditor is assessing the company’s AWS-hosted infrastructure for PCI DSS compliance. Which action should a SysOps administrator take to provide the auditors with AWS compliance documentation?
Choose an answer
Tap an option to check your answer.
Correct answer: Download the relevant compliance reports from the AWS Artifact console and give them to the auditors..
Why this is the answer
The correct action is to download relevant compliance reports from the AWS Artifact console. AWS Artifact provides on-demand access to AWS security and compliance reports, such as PCI DSS, ISO certifications, and SOC reports, which are specifically designed for auditors and compliance officers. Exporting CloudTrail logs would provide activity history, not compliance attestations. Exporting CloudWatch logs would provide operational metrics and application logs, which are not the primary documents for demonstrating AWS's compliance posture. Granting administrative access to a production account is a severe security risk and violates the principle of least privilege; auditors should never have direct access to production environments.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed