AWS Certified Security – SpecialtyDomain 5: Data ProtectionHard

A global banking institution uses Amazon S3 to store transaction logs. Due to compliance regulations, these logs must be retained for 7 years and remain immutable, meaning they cannot be deleted or modified by any user, including the root account. After the 7-year retention period, the logs can be automatically deleted to manage storage costs. Which S3 configuration should be implemented?

  1. AApply S3 Object Lock in Compliance mode with a retention period of 7 years and a lifecycle rule to expire objects.
  2. BEnable S3 Versioning on the bucket and configure a lifecycle rule to expire current versions after 7 years.
  3. CApply S3 Object Lock in Governance mode with a retention period of 7 years and a lifecycle rule to expire objects.
  4. DImplement an S3 bucket policy denying all `s3:DeleteObject` and `s3:PutObject` actions for 7 years, then remove the policy.
Show answer & explanation

Correct answer: A. Apply S3 Object Lock in Compliance mode with a retention period of 7 years and a lifecycle rule to expire objects.

S3 Object Lock in Compliance mode provides the strongest immutability, preventing deletion or modification by any user, including the root account, for the specified 7-year retention period. A lifecycle rule will then automatically delete the objects upon expiration.

Why the other options are wrong

  • B. S3 Versioning keeps multiple versions but does not prevent the root user from deleting all versions or the bucket. It also doesn't enforce immutability against overwrites by all users.
  • C. S3 Object Lock in Governance mode allows users with appropriate IAM permissions (including the root account) to bypass or remove the retention settings, which violates the 'no user, including root' requirement.
  • D. An S3 bucket policy can be modified or deleted by the root user, meaning it does not guarantee immutability against the root account, nor does it provide a robust, automated expiration mechanism after 7 years.

S3 Object Lock Compliance Mode for WORM

Amazon S3 Object Lock, specifically in Compliance mode, enforces a Write Once, Read Many (WORM) model, making data immutable for a specified retention period against any user, including the root account. It's crucial for regulatory compliance requiring tamper-proof storage.

  • Prevents objects from being overwritten or deleted by *any* user during the retention period.
  • Ideal for regulatory compliance (e.g., FINRA, HIPAA, SEC Rule 17a-4).
  • Can be combined with S3 Lifecycle policies for automatic object expiration after the retention period.

Memory trick: Compliance Mode Confirms Complete Content Control, Can't be Deleted.

More Domain 5: Data Protection questions