To install a PCI-compliant workload on AWS, which of the following tasks is required?
A. Use any AWS service and implement PCI controls at the application layer
B. Use an AWS service that is in-scope for PCI compliance and raise an AWS support ticket
to enable PCI compliance at the application layer
C. Use any AWS service and raise an AWS support ticket to enable PCI compliance on that
service
D. Use an AWS service that is in scope for PCI compliance and apply PCI controls at the
application layer
Answer: D
✅ Explanation
To install a PCI-compliant workload on AWS, you must:
-Use only AWS services that are "in scope" for PCI DSS compliance.
-AWS publishes a list of PCI-compliant services that are regularly assessed under PCI DSS.
-Services not in scope must not be used for storing, processing, or transmitting cardholder data (CHD).
-Apply the required PCI DSS controls at the application level.
-AWS is responsible for the security of the cloud (physical infrastructure, core services).
-You are responsible for the security in the cloud, such as encryption, access control, logging, and secure coding practices.
-This is part of the shared responsibility model.