AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceEasy
A compliance officer needs to download AWS's SOC 2 report to satisfy an internal audit requirement. Which AWS service should the officer use to access this report?
- AAWS CloudTrail
- BAWS Artifact
- CAWS Config
- DAWS Security Hub
Show answer & explanationAnswer & explanation
Correct answer: B. AWS Artifact
AWS Artifact is the self-service portal that provides on-demand access to AWS's compliance reports, including SOC 2, ISO certifications, and PCI reports.
Why the other options are wrong
- A. CloudTrail logs API activity, unrelated to compliance report downloads.
- C. AWS Config tracks resource configuration compliance, not third-party audit reports.
- D. Security Hub aggregates security findings, not compliance reports.
AWS Artifact
A self-service portal for accessing AWS compliance reports and agreements such as SOC, ISO, and PCI documents.
- Free service available in the AWS Management Console
- Provides on-demand access to audit artifacts
- Also used to accept agreements like the BAA for HIPAA
Memory trick: Artifact = Archive of certificates.