Professional Cloud Security EngineerEnsuring data protectionMedium
A media company uses Cloud Storage to archive video footage. They need to ensure that specific video files, once uploaded, are immutable for seven years to meet regulatory requirements and that no user, including administrators, can delete or modify these files during this period. How should they configure their Cloud Storage buckets and objects?
- AApply a bucket-level retention policy of seven years and enable 'Object Lock' for the bucket.
- BApply a bucket-level retention policy of seven years and grant only 'Storage Object Creator' role.
- CApply a bucket-level retention policy of seven years and enable 'Uniform bucket-level access'.
- DUse object versioning and set a lifecycle rule to delete old versions after seven years.
Show answer & explanationAnswer & explanation
Correct answer: A. Apply a bucket-level retention policy of seven years and enable 'Object Lock' for the bucket.
A bucket-level retention policy with Object Lock enabled ensures that objects are immutable and cannot be deleted or modified for the specified duration, even by administrators with 'Owner' roles, thus meeting the strict immutability and regulatory requirements.
Why the other options are wrong
- B. The 'Storage Object Creator' role does not prevent deletion or modification by other users or administrators, and a retention policy alone doesn't enforce immutability against all users (Object Lock is needed).
- C. Uniform bucket-level access simplifies permissions by disabling object ACLs, but it does not enforce immutability or prevent deletion/modification of objects once created by authorized users.
- D. Object versioning keeps old copies but doesn't prevent modification or deletion of the current object. Lifecycle rules are for eventual deletion, not immutability during a period.
Cloud Storage Retention Policy with Object Lock
A Cloud Storage feature that enforces immutability on objects within a bucket for a specified duration, preventing deletion or modification by any user, including administrators, to meet regulatory or compliance requirements.
- Applies to all objects in a bucket (or specific objects if configured).
- Prevents deletion and modification for the retention period.
- Works even for users with 'Owner' permissions.
- Essential for WORM (Write Once, Read Many) compliance.
Memory trick: To Lock your data for good, a Retention Policy and Object Lock are understood!