AWS Certified SysOps Administrator – AssociateReliability and Business ContinuityMedium
A SysOps Administrator needs to ensure that critical application data stored in an Amazon S3 bucket is protected against accidental deletion or modification. The data is accessed frequently and must be recoverable to any previous version. What S3 features should be enabled and configured to meet these requirements with minimal operational overhead?
- AEnable S3 Cross-Region Replication and S3 Object Lock in Compliance mode.
- BEnable S3 Versioning and configure S3 server access logging.
- CEnable S3 Versioning and configure a lifecycle policy to transition old versions to S3 Glacier.
- DEnable S3 Versioning and S3 Object Lock in Governance mode.
Show answer & explanationAnswer & explanation
Correct answer: D. Enable S3 Versioning and S3 Object Lock in Governance mode.
S3 Versioning keeps multiple object versions, allowing recovery from accidental deletion/modification. S3 Object Lock in Governance mode prevents accidental deletion by most users (requiring special permissions to bypass), providing an extra layer of protection while allowing authorized changes if needed.
Why the other options are wrong
- A. Cross-Region Replication is for disaster recovery across regions; Compliance mode Object Lock is stricter and prevents even authorized users from deleting for a set period, which might be too restrictive if modifications are needed.
- B. Server access logging records requests, but does not protect the data itself from deletion or modification.
- C. Lifecycle policies for Glacier are for cost optimization of old versions, not primary protection against accidental deletion/modification of active data.
S3 Versioning & Object Lock
S3 Versioning retains multiple versions of an object, allowing recovery from accidental deletion or modification. S3 Object Lock prevents objects from being deleted or overwritten for a fixed amount of time or indefinitely.
- Versioning is crucial for point-in-time recovery.
- Object Lock has two modes: Governance (most users can't delete, root can) and Compliance (no one, not even root, can delete).
- Together, they provide robust data protection and immutability.
Memory trick: Versioning saves your history, Object Lock guards your treasure.