A financial institution is storing sensitive customer transaction data in Amazon S3. Due to regulatory compliance, this data must be retained for 7 years in an immutable state, meaning it cannot be deleted or modified by anyone, including root users, for the duration of the retention period. After 7 years, the data can be automatically deleted. Which combination of S3 features will meet these requirements most effectively?
- AS3 Glacier Deep Archive storage class with a vault lock policy set for 7 years and S3 Lifecycle rules for transition.
- BS3 Versioning enabled and an S3 bucket policy denying 's3:DeleteObject' and 's3:PutObject' for 7 years, then S3 Lifecycle rules.
- CS3 Object Lock in Compliance mode with a retention period of 7 years and S3 Lifecycle rules for expiration.
- DS3 Object Lock in Governance mode with a retention period of 7 years and S3 Lifecycle rules for expiration.
Show answer & explanationAnswer & explanation
Correct answer: C. S3 Object Lock in Compliance mode with a retention period of 7 years and S3 Lifecycle rules for expiration.
S3 Object Lock in Compliance mode prevents any user, including the root user, from deleting or overwriting an object until its retention period expires. Setting a 7-year retention period directly addresses the immutability requirement. S3 Lifecycle rules can then be used to automatically expire and delete the objects after the 7 years.
Why the other options are wrong
- A. S3 Glacier Deep Archive is a storage class for cost-effective archival and doesn't inherently provide immutability against deletion. A vault lock policy is for Glacier vaults, not S3 buckets, and S3 Lifecycle rules for transition would move data, not delete it after retention in S3.
- B. While bucket policies can restrict deletions, they can be modified by privileged users. Also, S3 Versioning itself doesn't guarantee immutability against deletion of all versions or the bucket.
- D. Governance mode prevents most users from deleting or overwriting, but privileged users can still remove the lock. This does not meet the 'immutable by anyone, including root users' requirement.
S3 Object Lock Compliance Mode
An Amazon S3 feature that prevents an object from being deleted or overwritten for a fixed amount of time or indefinitely. In Compliance mode, no user, including the root user, can delete the object version or change its lock settings.
- Provides WORM (Write Once, Read Many) protection.
- Compliance mode offers the strongest protection, even against the root user.
- Used for regulatory compliance and data retention requirements.
Memory trick: To lock data forever, compliance is clever.