AWS Certified Cloud Practitioner — Question 423

A company is undergoing a security audit. The audit includes security validation and compliance validation of the AWS infrastructure and services that the company uses. The auditor needs to locate compliance-related information and must download AWS security and compliance documents. These documents include the System and Organization Control (SOC) reports.

Which AWS service or group can provide these documents?

Answer options

Correct answer: B

Explanation

AWS Artifact is the primary self-service portal for on-demand access to AWS compliance documentation, including System and Organization Control (SOC) reports and Payment Card Industry (PCI) reports. Other options like AWS Support and the AWS Abuse team do not serve as a repository for compliance documents, while AWS Config is used for monitoring and assessing resource configurations rather than retrieving AWS's own compliance audits.