Compliance Practice Test 2026–2027 |
Compliance Reports, Security &
Governance Questions
1. What is the primary purpose of AWS Artifact?
A. To monitor application performance
B. To provide access to AWS security and compliance documentation
C. To encrypt customer data
D. To configure IAM policies
Answer: To provide access to AWS security and compliance documentation
Rationale: AWS Artifact is a self-service portal that provides customers with on-
demand access to AWS security and compliance reports, certifications, and
agreements.
2. Which AWS service should a customer use to download AWS compliance
reports such as SOC reports?
,A. AWS CloudTrail
B. Amazon Inspector
C. AWS Artifact
D. AWS Config
Answer: AWS Artifact
Rationale: AWS Artifact provides access to AWS compliance reports and
certifications that can be downloaded for auditing and compliance purposes.
3. A company needs evidence that AWS maintains specific security controls
for an external audit. Which AWS resource is most appropriate?
A. AWS Artifact
B. Amazon CloudWatch
C. AWS Systems Manager
D. Amazon GuardDuty
Answer: AWS Artifact
Rationale: AWS Artifact provides official AWS compliance documentation that
organizations can use as evidence during audits and assessments.
4. Which statement best describes AWS Artifact?
A. It is a vulnerability scanning service.
B. It is a compliance-documentation portal.
C. It is an identity federation service.
D. It is a data-loss-prevention service.
Answer: It is a compliance-documentation portal.
,Rationale: AWS Artifact is designed specifically to provide access to AWS security
and compliance documentation rather than performing security monitoring or
vulnerability scanning.
5. Which type of document can commonly be obtained through AWS Artifact?
A. Customer application source code
B. AWS compliance reports
C. EC2 operating-system logs
D. VPC flow logs
Answer: AWS compliance reports
Rationale: AWS Artifact provides compliance reports and certifications relevant
to AWS infrastructure and services.
6. An auditor asks an organization to provide AWS SOC documentation.
Where should the organization obtain the AWS documentation?
A. AWS Artifact
B. Amazon S3
C. AWS CloudFormation
D. AWS Trusted Advisor
Answer: AWS Artifact
Rationale: AWS Artifact is the designated AWS portal for accessing AWS
compliance reports such as SOC documentation.
7. Which responsibility remains with the customer under the AWS shared
responsibility model?
, A. Maintaining AWS data center physical security
B. Maintaining AWS hardware
C. Configuring customer IAM permissions
D. Securing AWS power infrastructure
Answer: Configuring customer IAM permissions
Rationale: AWS secures the underlying cloud infrastructure, while customers
remain responsible for security in the cloud, including IAM configuration and
access control.
8. What is the AWS shared responsibility model primarily intended to define?
A. AWS pricing tiers
B. Responsibilities between AWS and customers for security
C. Availability Zone selection
D. Data transfer costs
Answer: Responsibilities between AWS and customers for security
Rationale: The shared responsibility model establishes which security
responsibilities belong to AWS and which belong to the customer.
9. Which responsibility is generally handled by AWS?
A. Customer application configuration
B. Customer IAM policies
C. Physical security of AWS facilities
D. Customer data classification
Answer: Physical security of AWS facilities