You are planning to deploy a PCI-compliant application on AWS. Which of the following steps are MOST CRITICAL to ensure compliance? (Choose 3)

a) Leverage AWS shared responsibility model for security.
b) Implement strong access controls for cardholder data.
c) Regularly update and patch the application and underlying systems.
d) Choose an AWS service that is pre-validated for PCI compliance.
e) Conduct annual penetration testing of the application.