SOA-C02 exam dumps

SOA-C02 practice question 190 of 341

AWS Certified SysOps Administrator - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SOA-C02 Question 190

Select 2

Your company handles sensitive healthcare data and must comply with the Health Insurance Portability and Accountability Act (HIPAA). You are tasked with deploying an application on AWS. Which of the following actions should you take to ensure compliance when selecting an AWS Region and services?

  1. A

    Verify that the AWS Region supports the AWS services required by your application and is HIPAA-eligible.

  2. B

    Check if the AWS Region is within the United States, as HIPAA compliance requires data to stay within the country.

  3. C

    Review the AWS Business Associate Addendum (BAA) to confirm that your chosen AWS services are covered under the agreement.

  4. D

    Ensure that the selected AWS services in the Region have been certified as PCI DSS compliant.

  5. E

    Validate that the Region has Availability Zones in at least two physically separate locations.

Show answer and explanation

Correct answers: A, C

Explanation

To ensure HIPAA compliance when selecting an AWS Region and services, you must verify that the required services are eligible for HIPAA compliance in the chosen Region and are covered under the AWS Business Associate Addendum (BAA). This ensures that both the Region and the services meet the specific compliance requirements for handling sensitive healthcare data.

  • A. Correct.

    Correct. HIPAA compliance requires you to ensure that the AWS services used are HIPAA-eligible, which is Region-specific.

  • B. Incorrect.

    Incorrect. HIPAA compliance does not mandate that data must stay within the United States; it depends on the organization's data residency requirements.

  • C. Correct.

    Correct. To address HIPAA compliance, the chosen services must be under the scope of the AWS Business Associate Addendum (BAA).

  • D. Incorrect.

    Incorrect. PCI DSS compliance is unrelated to HIPAA compliance, as they address separate regulatory requirements.

  • E. Incorrect.

    Incorrect. While multi-AZ redundancy is a good practice for fault tolerance, it is not directly tied to HIPAA compliance.

Timed practice exam

Take a SOA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam