AWS Certified Security – SpecialtyDomain 5: Data ProtectionHard

A pharmaceutical company is storing highly sensitive genomic research data in an Amazon S3 bucket. This data is subject to strict regulatory compliance that requires frequent audits to demonstrate that data has not been tampered with and retains its integrity. The company needs a mechanism to prove the immutability of the data and detect any unauthorized modifications over its entire lifecycle. Which AWS service and configuration should the company implement?

  1. AUtilize AWS CloudTrail to log all S3 data events and integrate with Amazon GuardDuty for anomaly detection.
  2. BEnable S3 Object Lock in Governance mode for new objects and configure a retention period.
  3. CEnable S3 Object Lock in Compliance mode for new objects and configure a retention period.
  4. DEnable S3 Versioning on the bucket and configure lifecycle rules to move older versions to S3 Glacier Deep Archive.
Show answer & explanation

Correct answer: C. Enable S3 Object Lock in Compliance mode for new objects and configure a retention period.

S3 Object Lock in Compliance mode provides the strongest write-once-read-many (WORM) protection, preventing any user, including the root account, from deleting or overwriting an object until its retention period expires. This is ideal for regulatory compliance requiring immutability.

Why the other options are wrong

  • A. CloudTrail logs actions and GuardDuty detects anomalies, but neither inherently prevents data tampering or ensures immutability. They are reactive detection mechanisms, not proactive prevention for WORM storage.
  • B. Governance mode allows certain authorized users with specific IAM permissions to override or remove the lock, which does not meet the strict immutability requirement for audit purposes.
  • D. S3 Versioning keeps multiple versions of an object but does not prevent deletion of all versions by a privileged user or prevent overwriting. It primarily helps with accidental deletions or modifications, not strict immutability.

S3 Object Lock Compliance Mode

A feature of Amazon S3 that provides write-once-read-many (WORM) storage, preventing objects from being overwritten or deleted for a fixed amount of time or indefinitely, even by the root user.

  • Offers two modes: Governance and Compliance.
  • Compliance mode provides the highest level of protection for regulatory requirements.
  • Once set, an object in Compliance mode cannot be changed or deleted until its retention period expires.

Memory trick: Compliance Locks Data, Even from Root.

More Domain 5: Data Protection questions