AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceEasy

A compliance officer needs to download AWS's SOC 2 report to satisfy an internal audit requirement. Which AWS service should the officer use to access this report?

  1. AAWS CloudTrail
  2. BAWS Artifact
  3. CAWS Config
  4. DAWS Security Hub
Show answer & explanation

Correct answer: B. AWS Artifact

AWS Artifact is the self-service portal that provides on-demand access to AWS's compliance reports, including SOC 2, ISO certifications, and PCI reports.

Why the other options are wrong

  • A. CloudTrail logs API activity, unrelated to compliance report downloads.
  • C. AWS Config tracks resource configuration compliance, not third-party audit reports.
  • D. Security Hub aggregates security findings, not compliance reports.

AWS Artifact

A self-service portal for accessing AWS compliance reports and agreements such as SOC, ISO, and PCI documents.

  • Free service available in the AWS Management Console
  • Provides on-demand access to audit artifacts
  • Also used to accept agreements like the BAA for HIPAA

Memory trick: Artifact = Archive of certificates.

More Security and Compliance questions