AWS Certified Security – SpecialtyDomain 5: Data ProtectionHard
A global banking institution uses Amazon S3 to store transaction logs. Due to compliance regulations, these logs must be immutable for 7 years and then automatically deleted. Additionally, the institution needs to ensure that the immutability period cannot be shortened or bypassed by any user, including the root account. Which combination of S3 features should be used?
- AApply an S3 bucket policy that denies `s3:DeleteObject` and `s3:PutObject` operations for all users for 7 years, then remove the policy.
- BEnable S3 Versioning and configure a lifecycle rule to transition old versions to S3 Glacier Deep Archive after 7 years, then delete.
- CEnable S3 Object Lock in Governance mode with a retention period of 7 years, and configure S3 lifecycle rules for automatic deletion.
- DEnable S3 Object Lock in Compliance mode with a retention period of 7 years, and configure S3 lifecycle rules for automatic deletion.
Show answer & explanationAnswer & explanation
Correct answer: D. Enable S3 Object Lock in Compliance mode with a retention period of 7 years, and configure S3 lifecycle rules for automatic deletion.
S3 Object Lock in Compliance mode provides the strongest immutability, preventing any user (including the root account) from deleting or altering objects for the specified retention period. Combining this with S3 lifecycle rules ensures automatic deletion after the 7-year period, meeting both requirements.
Why the other options are wrong
- A. A bucket policy can restrict deletions, but it can be modified or removed by the root account or an authorized administrator, thus not guaranteeing immutability against all users, particularly the root account, over a fixed period.
- B. S3 Versioning helps recover from accidental deletions but does not prevent intentional deletion of all versions by a privileged user, failing the immutability requirement. Also, Glacier Deep Archive is for archival, not direct immutability enforcement.
- C. Governance mode allows privileged users to override the retention period, which does not meet the requirement that the immutability period 'cannot be shortened or bypassed by any user, including the root account'.
S3 Object Lock Compliance + Lifecycle
Combining Amazon S3 Object Lock in Compliance mode with S3 lifecycle rules to enforce strict data immutability for a defined period (WORM storage) and then automatically delete the data after the retention period expires.
- Compliance mode prevents deletion/overwriting by any user, including root.
- Retention period is fixed and cannot be reduced.
- Lifecycle rules automate deletion of objects once their retention period is over.
- Ideal for regulatory compliance requiring WORM storage and automated data retention policies.
Memory trick: Compliance Locks, Lifecycle Deletes.