AWS Certified SysOps Administrator – AssociateReliability and Business ContinuityHard

A company uses AWS Backup to manage backups for Amazon RDS databases, Amazon EC2 instances, and Amazon EBS volumes. The compliance team requires that all backups must be retained for 7 years and immutable for the first 3 months to protect against accidental deletion or ransomware. How should the SysOps Administrator configure AWS Backup to meet these requirements?

  1. ASet up a 3-month retention period for immediate backups and a separate 7-year retention for cold storage.
  2. BSet a lifecycle rule for a 7-year retention period and enable 'Vault Lock' with a 3-month compliance mode.
  3. CConfigure a 7-year retention period in the backup plan and use S3 Object Lock for the backup vault.
  4. DSet a lifecycle rule for a 7-year retention period and enable 'Vault Lock' with a 3-month governance mode.
Show answer & explanation

Correct answer: B. Set a lifecycle rule for a 7-year retention period and enable 'Vault Lock' with a 3-month compliance mode.

AWS Backup Vault Lock, when configured in Compliance mode, provides immutability. Setting it for 3 months in Compliance mode prevents anyone, including the root user, from deleting or modifying backups within that period. A lifecycle rule for 7 years ensures the overall retention. This combination meets both the immutability and long-term retention requirements.

Why the other options are wrong

  • A. This only addresses retention periods, not the explicit immutability requirement for the first 3 months.
  • C. AWS Backup Vaults are distinct from S3 buckets, so S3 Object Lock is not directly applicable to AWS Backup Vaults. AWS Backup has its own Vault Lock feature.
  • D. Governance mode for Vault Lock allows users with sufficient permissions (e.g., root, or specific IAM users) to modify or delete backups, which doesn't fully meet the 'immutable to protect against accidental deletion or ransomware' requirement.

AWS Backup Vault Lock

A feature of AWS Backup vaults that enforces an immutable policy on backups stored within the vault. It prevents changes to backup retention periods or deletion of backups for a specified duration.

  • Can be configured in Governance mode (allows authorized users to change/delete) or Compliance mode (no one can change/delete).
  • Compliance mode provides the strongest immutability for regulatory compliance or ransomware protection.
  • Applied at the vault level, affecting all backups within it.
  • Once locked in Compliance mode, the policy cannot be changed or deleted until the lock duration expires.

Memory trick: 7-year retention, 3-month lock in compliance, that's the backup dance!

More Reliability and Business Continuity questions