AWS Certified SysOps Administrator – AssociateSecurity and ComplianceHard

A company is implementing a new data classification scheme for all data stored in Amazon S3. They need to ensure that objects tagged as 'Confidential' cannot be deleted by any user or role for a period of 90 days after creation, even by the root user, to comply with data retention regulations. Which S3 feature should the SysOps administrator configure?

  1. AS3 Object Lock in Governance mode with a retention period.
  2. BS3 Object Lock in Compliance mode with a retention period.
  3. CA bucket policy that denies `s3:DeleteObject` for tagged objects.
  4. DS3 lifecycle policy to prevent deletion based on object tags.
Show answer & explanation

Correct answer: B. S3 Object Lock in Compliance mode with a retention period.

S3 Object Lock in Compliance mode is specifically designed to prevent an object from being overwritten or deleted by any user, including the root user, for a fixed amount of time or indefinitely. This immutability is crucial for regulatory compliance, as it ensures that data cannot be tampered with or accidentally removed. Setting a retention period of 90 days in Compliance mode directly addresses the requirement for immutable storage for 'Confidential' objects.

Why the other options are wrong

  • A. Governance mode prevents deletion by most users but allows users with specific IAM permissions (e.g., `s3:BypassGovernanceRetention`) to override or delete objects, which doesn't meet the requirement of preventing deletion 'even by the root user'.
  • C. A bucket policy can deny `s3:DeleteObject`, but it can always be modified or removed by an administrator or the root user, which does not guarantee immutability 'even by the root user' as required.
  • D. S3 lifecycle policies can manage object transitions and expirations but do not provide immutable WORM (Write Once, Read Many) protection against deletion. They can delete objects, not prevent their deletion by others.

S3 Object Lock Compliance Mode

S3 Object Lock in Compliance mode provides the highest level of data immutability, preventing objects from being overwritten or deleted by any user, including the root user, for a specified retention period.

  • WORM protection for S3 objects.
  • Prevents deletion/modification by all users, including root.
  • Essential for strict regulatory compliance.
  • Retention period cannot be shortened once set.

Memory trick: Compliance Mode means 'Completely Locked' for 'Compliance' – no one can touch it.

More Security and Compliance questions