AWS Certified DevOps Engineer – ProfessionalResilient Cloud SolutionsMedium

A financial services company is building a new application that will store highly sensitive customer data. The application must meet stringent regulatory compliance requirements for data immutability and long-term retention, preventing any modification or deletion of records for seven years, even by privileged users. Which AWS storage solution and configuration should be used to meet these requirements with the highest level of assurance?

  1. AAmazon EBS volumes for EC2 instances, with regular snapshots stored in S3 Intelligent-Tiering.
  2. BAmazon S3 One Zone-Infrequent Access with bucket policies restricting delete operations for 7 years.
  3. CAmazon S3 Standard with versioning enabled and a lifecycle policy to transition objects to S3 Glacier after 90 days.
  4. DAmazon S3 Glacier Deep Archive with S3 Object Lock in Compliance mode configured for a 7-year retention period.
Show answer & explanation

Correct answer: D. Amazon S3 Glacier Deep Archive with S3 Object Lock in Compliance mode configured for a 7-year retention period.

Amazon S3 Glacier Deep Archive provides the most cost-effective long-term storage, and S3 Object Lock in Compliance mode ensures data immutability, even from root users, for the specified retention period, meeting strict regulatory requirements.

Why the other options are wrong

  • A. EBS volumes are block storage for EC2 instances, not primarily for long-term archival of sensitive data, and snapshots in S3 Intelligent-Tiering do not inherently provide immutability.
  • B. S3 One Zone-IA is not designed for the highest durability or immutability, and bucket policies can be modified by privileged users, unlike S3 Object Lock in Compliance mode.
  • C. S3 Standard with versioning and lifecycle policies does not provide the same level of immutability as Object Lock and is not the most cost-effective for deep archives.

S3 Object Lock Compliance Mode

S3 Object Lock in Compliance mode prevents an object version from being overwritten or deleted by any user, including the root user, until a predefined retention period expires. This ensures data immutability for regulatory compliance.

  • Ensures data immutability for a specified retention period.
  • Prevents even the root user from deleting or overwriting objects.
  • Critical for regulatory compliance and audit trails.
  • Can be applied to new objects or existing objects within a bucket.

Memory trick: Compliance Lock ensures your digital scrolls stay safe from even the mightiest delete key.

More Resilient Cloud Solutions questions