AWS Certified Security – SpecialtyDomain 5: Data ProtectionHard
A research institution stores highly sensitive genomic data in an Amazon S3 bucket. This data must remain immutable for a minimum of 10 years to comply with regulatory mandates, meaning it cannot be overwritten or deleted by any user, including the root account. After 10 years, the data can be automatically deleted. Which S3 feature should be used to enforce this immutability and automatic deletion?
- AS3 Object Lock in Compliance mode with a retention period of 10 years and an S3 Lifecycle policy for expiration.
- BS3 Versioning combined with an S3 Lifecycle policy to transition to S3 Glacier Deep Archive after 10 years.
- CS3 Object Lock in Governance mode with a retention period of 10 years and an S3 Lifecycle policy for expiration.
- DS3 Bucket Policy that explicitly denies 's3:DeleteObject' and 's3:PutObject' for 10 years.
Show answer & explanationAnswer & explanation
Correct answer: A. S3 Object Lock in Compliance mode with a retention period of 10 years and an S3 Lifecycle policy for expiration.
S3 Object Lock in Compliance mode prevents any user, including the root account, from deleting or overwriting objects for the specified retention period (10 years). An S3 Lifecycle policy can then automatically delete the objects after this period.
Why the other options are wrong
- B. S3 Versioning prevents accidental deletion by keeping old versions, but it does not prevent the root user from deleting all versions or the entire bucket, and it doesn't enforce immutability against overwrites by all users.
- C. S3 Object Lock in Governance mode prevents most users from deleting or overwriting, but it allows users with special permissions (like the root user) to bypass the retention period, which violates the requirement that *no user* can delete it.
- D. An S3 Bucket Policy can deny actions, but it can be modified or deleted by the root user, and it doesn't provide the same level of tamper-proofing as S3 Object Lock in Compliance mode.
S3 Object Lock Compliance Mode
Amazon S3 Object Lock in Compliance mode provides immutable storage, preventing an object version from being overwritten or deleted by any user, including the root account, for a fixed retention period.
- Ensures WORM (Write Once, Read Many) compliance.
- No user, including the root account, can delete or modify objects during the retention period.
- Can be combined with S3 Lifecycle policies for automatic deletion after the retention period ends.
Memory trick: Compliance Mode Confirms Complete Content Control, Can't be Deleted.