RetailHub’s compliance team needs to achieve PCI DSS across 50 AWS accounts. They want to continuously collect evidence (for example, IAM configuration, CloudTrail activity, ELB logging) mapped to PCI controls and generate auditor-ready reports with minimal manual effort. Which service should they use?
Choose an answer
Tap an option to check your answer.
Correct answer: AWS Audit Manager with the PCI DSS framework and a delegated administrator for multi-account evidence collection..
Why this is the answer
AWS Audit Manager is the correct choice because it automates the collection of evidence from various AWS services (like IAM, CloudTrail, and ELB logs) and maps it to controls within predefined frameworks, such as PCI DSS. Using a delegated administrator allows for centralized evidence collection across multiple AWS accounts, significantly reducing manual effort and generating auditor-ready reports. AWS Artifact provides access to AWS compliance reports and certifications, but it doesn't collect evidence from your specific AWS environment. AWS Security Hub aggregates security findings and performs automated security checks against standards like PCI DSS, but it doesn't generate auditor-ready reports for compliance evidence collection. AWS Config conformance packs assess compliance against desired configurations and can export data, but Audit Manager is specifically designed for continuous evidence collection and report generation for compliance frameworks.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed