A financial institution stores critical transaction logs in an Amazon S3 bucket. Due to regulatory compliance (e.g., FINRA, SEC), these logs must be immutable and retained for a minimum of seven years, with no possibility of deletion or modification by any user, including the root account. After seven years, the logs can be automatically deleted. Which S3 feature should the security architect recommend to meet these requirements?
- AS3 Versioning with a lifecycle policy to transition objects to Glacier after seven years.
- BS3 Object Lock in Governance mode with a retention period of seven years.
- CS3 Block Public Access settings configured at the bucket level.
- DS3 Object Lock in Compliance mode with a retention period of seven years and a lifecycle policy.
Show answer & explanationAnswer & explanation
Correct answer: D. S3 Object Lock in Compliance mode with a retention period of seven years and a lifecycle policy.
S3 Object Lock in Compliance mode ensures that an object version cannot be overwritten or deleted by any user, including the root account, until the retention period expires. This meets the immutability and undeletable requirements. A lifecycle policy can then be used to automatically delete the objects after the seven-year retention period, satisfying the automatic deletion requirement.
Why the other options are wrong
- A. Versioning prevents accidental deletion but does not prevent intentional deletion by authorized users (including root) or modification of specific versions. It does not enforce immutability against all users.
- B. Governance mode prevents deletion/overwriting by most users but allows users with specific permissions (e.g., root account) to override or remove the lock, which violates the 'no possibility of deletion by any user' requirement.
- C. S3 Block Public Access prevents public access to the bucket but does not enforce immutability or retention for objects within the bucket against authenticated AWS users.
S3 Object Lock Compliance Mode
S3 Object Lock in Compliance mode provides Write Once Read Many (WORM) storage, preventing an object version from being overwritten or deleted by any user, including the root account, until a specified retention period expires.
- Provides WORM protection
- No user, including root, can delete or modify objects
- Retention period cannot be shortened or removed
- Often used for strict regulatory compliance
Memory trick: Compliance Locks Down Everything, Even Root.