AWS Certified Security – SpecialtyDomain 5: Data ProtectionMedium

A global e-commerce company uses Amazon S3 to store customer order data. Due to varying international data privacy regulations, the company must classify its data based on sensitivity (e.g., Public, Internal, Confidential, Restricted) and apply appropriate retention policies and access controls. Public data can be stored indefinitely, Internal data for 5 years, Confidential for 7 years, and Restricted for 10 years. What is the most effective and scalable way to implement this data classification and lifecycle management within AWS, ensuring compliance and minimizing operational overhead?

  1. AManually tag each S3 object with its classification and use S3 Lifecycle rules based on object tags.
  2. BStore data in separate S3 buckets for each classification level and apply bucket-level lifecycle rules.
  3. CImplement a custom application to analyze object content, assign metadata tags, and trigger S3 Glacier Deep Archive for long-term retention.
  4. DUtilize AWS Macie to discover and classify sensitive data, then configure S3 Lifecycle rules based on Macie findings.
Show answer & explanation

Correct answer: A. Manually tag each S3 object with its classification and use S3 Lifecycle rules based on object tags.

Tagging S3 objects with classification metadata and then applying S3 Lifecycle rules based on these object tags is a highly effective and scalable method. It allows for granular control over data retention policies without requiring separate buckets for each classification, simplifying management and enabling flexible transitions between storage classes or deletion.

Why the other options are wrong

  • B. While effective, using separate buckets for each classification can lead to bucket sprawl and increased management complexity, especially as the number of classifications or data types grows. It's less flexible than object tagging for managing data within the same bucket.
  • C. Implementing a custom application increases operational overhead, maintenance burden, and potential for errors. AWS provides native services like S3 Lifecycle rules and object tagging for these purposes, which are more cost-effective and reliable.
  • D. AWS Macie is excellent for discovering and classifying sensitive data. However, Macie's findings are not directly actionable by S3 Lifecycle rules for retention. You would still need to translate Macie findings into object tags or move objects to different buckets to apply lifecycle policies.

S3 Object Tags with Lifecycle Rules

S3 Object Tags are key-value pairs that can be applied to individual S3 objects, enabling granular data classification. S3 Lifecycle rules can then be configured to perform actions (e.g., transition to different storage classes, expire) based on these object tags.

  • Allows up to 10 tags per object.
  • Enables fine-grained control over data lifecycle.
  • Reduces the need for multiple buckets for classification.

Memory trick: Tag your S3 objects to dictate their 'Time' and 'Place' in storage.

More Domain 5: Data Protection questions