AWS Certified DevOps Engineer – ProfessionalIncident and Event ResponseMedium

A media company uses Amazon S3 to store large volumes of user-uploaded content. They need to implement a mechanism to automatically scan newly uploaded files for malware and inappropriate content before they are made public. The solution must be event-driven, scalable, and minimize operational overhead. Which architecture should the DevOps team recommend?

  1. AEnable S3 Object Lock on the buckets to prevent unauthorized modifications, and manually review suspicious files.
  2. BSet up an EC2 instance running open-source antivirus software, and use cron jobs to periodically scan all S3 buckets.
  3. CUse AWS DataSync to transfer new S3 objects to an on-premises server for scanning, then re-upload cleaned files to a different S3 bucket.
  4. DConfigure S3 Event Notifications to trigger an AWS Lambda function, which then initiates a scan using a third-party antivirus API and stores results in a database.
Show answer & explanation

Correct answer: D. Configure S3 Event Notifications to trigger an AWS Lambda function, which then initiates a scan using a third-party antivirus API and stores results in a database.

This solution leverages S3 Event Notifications to react immediately to new uploads, triggering a Lambda function. Lambda is ideal for serverless, event-driven processing, allowing the integration with a third-party scanning service without managing servers. This approach is scalable, cost-effective, and fully automated.

Why the other options are wrong

  • A. S3 Object Lock is for data immutability and compliance, not for content scanning. Manual review contradicts the requirement for automation.
  • B. Using an EC2 instance with cron jobs is not event-driven, introduces server management overhead, and periodic scanning means delays in detection.
  • C. DataSync is for large-scale data transfer, not real-time, event-driven scanning. Transferring to on-premises adds latency and operational overhead.

S3 Event-Driven Content Scanning

This pattern uses S3 Event Notifications to automatically trigger serverless functions (e.g., AWS Lambda) upon object creation, enabling immediate processing like malware scanning, content moderation, or data transformation.

  • Reacts to S3 object events in real-time.
  • Leverages serverless compute (Lambda) for scalability.
  • Minimizes operational overhead for event processing.

Memory trick: S3 event arrives, Lambda takes the call, scans the content, then tells one and all.

More Incident and Event Response questions