A developer is implementing a feature in an application where users can upload files to an S3 bucket. To ensure data integrity, the application needs to verify that the uploaded file has not been altered during transit. The application calculates the MD5 hash of the file client-side before uploading. How can the developer use S3 to verify the integrity of the uploaded file?
- AS3 automatically calculates and stores an ETag for every uploaded object, which for single-part uploads is the MD5 hash of the object. The client can compare its calculated MD5 hash with the ETag returned by S3.
- BCompute the MD5 hash of the file on the server-side after upload and compare it with the client-side hash.
- CUse AWS CloudTrail to monitor S3 PutObject events and check for data integrity issues in the logs.
- DImplement a Lambda function triggered by S3 upload events to calculate the MD5 hash and store it in DynamoDB for comparison.
Show answer & explanationAnswer & explanation
Correct answer: A. S3 automatically calculates and stores an ETag for every uploaded object, which for single-part uploads is the MD5 hash of the object. The client can compare its calculated MD5 hash with the ETag returned by S3.
For single-part uploads, Amazon S3 calculates and returns an ETag that is the MD5 digest of the object data. The client can then compare its pre-calculated MD5 hash with the ETag returned by S3 after a successful upload to verify data integrity without additional compute or services.
Why the other options are wrong
- B. This requires additional server-side compute, which is less efficient than using S3's built-in ETag for single-part uploads.
- C. CloudTrail records API calls and events; it does not calculate or verify data integrity hashes. This is an incorrect use of CloudTrail for this purpose.
- D. While possible, this adds unnecessary complexity and cost (Lambda invocation, DynamoDB storage) when S3 provides the functionality directly via the ETag.
S3 ETag for Data Integrity
The ETag (entity tag) returned by Amazon S3 for an object can be used to verify the integrity of the object. For single-part uploads, the ETag is the MD5 hash of the object data.
- Returned in the response headers of `PutObject`.
- For single-part uploads, ETag is the MD5 hash.
- For multi-part uploads, ETag is not a simple MD5 hash.
- Can be used by clients to verify data integrity.
Memory trick: The ETag is S3's stamp of integrity for your single-part upload.