AWS Certified Solutions Architect – Associate (SAA-C03)Design Resilient ArchitecturesMedium

A financial institution needs to store immutable audit logs for regulatory compliance. The logs must be protected from accidental deletion or modification for 7 years. After this period, they can be deleted. Which Amazon S3 feature should be used to meet these requirements?

  1. AS3 Object Lock
  2. BS3 Versioning
  3. CS3 Glacier Deep Archive
  4. DS3 Lifecycle Policies
Show answer & explanation

Correct answer: A. S3 Object Lock

S3 Object Lock provides WORM (Write Once, Read Many) protection, preventing objects from being deleted or overwritten for a fixed amount of time or indefinitely. This directly addresses the requirement for immutable audit logs for a specific duration.

Why the other options are wrong

  • B. S3 Versioning keeps multiple versions of an object but doesn't prevent deletion of all versions by a privileged user.
  • C. S3 Glacier Deep Archive is a storage class for very long-term, infrequently accessed data, but doesn't inherently provide immutability without Object Lock.
  • D. S3 Lifecycle Policies automate object transitions and expiration but don't prevent modification or deletion during their active period.

Amazon S3 Object Lock

An Amazon S3 feature that provides WORM (Write Once, Read Many) protection for objects. It prevents objects from being deleted or overwritten for a fixed retention period or indefinitely.

  • Supports governance mode (most users can't delete) and compliance mode (no user, including root, can delete).
  • Used for regulatory compliance and data retention policies.
  • Works with S3 Versioning to protect individual object versions.

Memory trick: Lock Your S3: Regulations, Retention, Resilience.

More Design Resilient Architectures questions