A global banking institution uses Amazon S3 to store transaction logs. Due to compliance requirements, these logs must be retained for 5 years in an immutable state, meaning they cannot be deleted or modified. After the 5-year period, the logs must be automatically moved to a lower-cost archival storage class and then deleted after an additional 2 years. Which solution effectively combines S3 features to meet these requirements?
- AEnable S3 Versioning, configure S3 Object Lock in Governance mode for 5 years, and use S3 Lifecycle rules to transition to S3 Glacier after 5 years and expire after 7 years.
- BUse S3 bucket policies to deny 's3:DeleteObject' for 5 years, and then S3 Lifecycle rules to transition to S3 Glacier and expire after 7 years.
- CEnable S3 Versioning, configure S3 Object Lock in Compliance mode for 5 years, and use S3 Lifecycle rules to transition to S3 Glacier after 5 years and expire after 7 years.
- DStore logs directly in S3 Glacier Deep Archive, set a vault lock for 5 years, and then use S3 Lifecycle rules to expire after 7 years.
Show answer & explanationAnswer & explanation
Correct answer: C. Enable S3 Versioning, configure S3 Object Lock in Compliance mode for 5 years, and use S3 Lifecycle rules to transition to S3 Glacier after 5 years and expire after 7 years.
S3 Object Lock in Compliance mode ensures immutability for 5 years, preventing deletion or modification by any user, including the root user. S3 Versioning is a prerequisite for Object Lock. S3 Lifecycle rules can then be configured to transition the objects to a lower-cost archival class (like S3 Glacier) after the 5-year retention period and finally expire them after a total of 7 years, fulfilling all requirements.
Why the other options are wrong
- A. Governance mode does not guarantee immutability against the root user, failing the 'cannot be deleted or modified' by anyone requirement.
- B. Bucket policies can be modified by privileged users, thus not guaranteeing true immutability against all users, including root.
- D. S3 Glacier Deep Archive is a storage class, not a direct immutability mechanism for S3 objects, and vault locks apply to Glacier vaults, not S3 buckets directly for object lock purposes. Also, it implies storing directly in Glacier, not transitioning after 5 years in S3.
S3 Object Lock Compliance + Lifecycle
Combining S3 Object Lock in Compliance mode for strict immutability with S3 Lifecycle rules to manage data transitions to lower-cost storage classes and eventual expiration after the retention period.
- Object Lock Compliance ensures WORM for a defined period.
- S3 Versioning must be enabled for Object Lock.
- Lifecycle rules automate cost optimization and deletion post-retention.
Memory trick: Lock it tight with compliance, then lifecycle for less expense.