A global banking institution uses Amazon S3 to store transaction logs. Due to compliance regulations, these logs must be retained for 7 years and remain immutable, meaning they cannot be deleted or modified by any user, including the root account. After the 7-year retention period, the logs can be automatically deleted to manage storage costs. Which S3 configuration should be implemented?
- AApply S3 Object Lock in Compliance mode with a retention period of 7 years and a lifecycle rule to expire objects.
- BEnable S3 Versioning on the bucket and configure a lifecycle rule to expire current versions after 7 years.
- CApply S3 Object Lock in Governance mode with a retention period of 7 years and a lifecycle rule to expire objects.
- DImplement an S3 bucket policy denying all `s3:DeleteObject` and `s3:PutObject` actions for 7 years, then remove the policy.
Show answer & explanationAnswer & explanation
Correct answer: A. Apply S3 Object Lock in Compliance mode with a retention period of 7 years and a lifecycle rule to expire objects.
S3 Object Lock in Compliance mode provides the strongest immutability, preventing deletion or modification by any user, including the root account, for the specified 7-year retention period. A lifecycle rule will then automatically delete the objects upon expiration.
Why the other options are wrong
- B. S3 Versioning keeps multiple versions but does not prevent the root user from deleting all versions or the bucket. It also doesn't enforce immutability against overwrites by all users.
- C. S3 Object Lock in Governance mode allows users with appropriate IAM permissions (including the root account) to bypass or remove the retention settings, which violates the 'no user, including root' requirement.
- D. An S3 bucket policy can be modified or deleted by the root user, meaning it does not guarantee immutability against the root account, nor does it provide a robust, automated expiration mechanism after 7 years.
S3 Object Lock Compliance Mode for WORM
Amazon S3 Object Lock, specifically in Compliance mode, enforces a Write Once, Read Many (WORM) model, making data immutable for a specified retention period against any user, including the root account. It's crucial for regulatory compliance requiring tamper-proof storage.
- Prevents objects from being overwritten or deleted by *any* user during the retention period.
- Ideal for regulatory compliance (e.g., FINRA, HIPAA, SEC Rule 17a-4).
- Can be combined with S3 Lifecycle policies for automatic object expiration after the retention period.
Memory trick: Compliance Mode Confirms Complete Content Control, Can't be Deleted.