AWS Certified SysOps Administrator – AssociateSecurity and ComplianceHard
A healthcare provider is storing patient records in an Amazon S3 bucket. Due to HIPAA compliance, the data must be protected from accidental deletion or modification for a specific retention period. The solution must ensure that even root users cannot delete or alter the objects during this period. Which S3 feature should be enabled and configured on the bucket?
- AS3 Object Lock in Compliance mode.
- BS3 Object Lock in Governance mode.
- CS3 Versioning with MFA Delete.
- DS3 Lifecycle Policies to transition to S3 Glacier Deep Archive.
Show answer & explanationAnswer & explanation
Correct answer: A. S3 Object Lock in Compliance mode.
S3 Object Lock in Compliance mode prevents an object from being overwritten or deleted by any user, including the root user, for a fixed amount of time or indefinitely. This meets the strict immutability requirements for HIPAA compliance, ensuring protection from accidental or malicious alteration/deletion.
Why the other options are wrong
- B. Governance mode allows users with s3:BypassGovernanceRetention permission (including the root user by default) to remove object lock, thus not providing absolute immutability from all users.
- C. Versioning protects against accidental deletion by keeping old versions, and MFA Delete adds an extra layer of security, but neither prevents the root user from eventually deleting all versions after the MFA challenge.
- D. Lifecycle policies manage object transitions and expiration, but do not provide immutability or protection against deletion/modification by users.
S3 Object Lock Compliance Mode
S3 Object Lock in Compliance mode provides the strongest level of immutability for objects, preventing them from being overwritten or deleted by any user, including the root user, during a specified retention period.
- Once set, retention period cannot be shortened or removed.
- Protects against accidental and malicious deletion/modification.
- Suitable for strict regulatory compliance (e.g., HIPAA, FINRA).
- Applies to new objects uploaded to a bucket with Object Lock enabled.
Memory trick: Compliance Mode: No Deletion, Not Even by Root, for Records.