AWS Certified SysOps Administrator – AssociateReliability and Business ContinuityEasy

A financial services company needs to ensure that its critical application data stored in an Amazon S3 bucket is immutable for a period of 7 years to meet regulatory compliance. After the retention period, the data should be automatically deleted. The company also wants to prevent any user, including the root account, from deleting or modifying the objects during this period. Which S3 feature should the SysOps Administrator configure?

  1. AS3 Access Control Lists (ACLs) denying delete permissions to all users.
  2. BS3 Lifecycle policies with a 'Transition to S3 Glacier' action.
  3. CS3 Versioning and MFA Delete enabled on the bucket.
  4. DS3 Object Lock in Compliance mode with a Retention Period.
Show answer & explanation

Correct answer: D. S3 Object Lock in Compliance mode with a Retention Period.

S3 Object Lock in Compliance mode provides the strongest protection, preventing any user, including the root account, from deleting or overwriting an object for the duration of the retention period. Lifecycle policies can then be used to automatically delete objects after this period.

Why the other options are wrong

  • A. ACLs are for access control, not for ensuring immutability or preventing deletion by privileged users like the root account.
  • B. Lifecycle policies can transition data to other storage classes or delete it, but they do not prevent immutability during the retention period.
  • C. Versioning keeps multiple versions and MFA Delete protects against accidental deletion, but neither guarantees immutability from all users, including root, for a set period.

S3 Object Lock Compliance Mode

S3 Object Lock Compliance mode is a WORM (Write Once Read Many) feature that prevents an object from being overwritten or deleted by any user, including the root user, during a defined retention period.

  • Ensures data immutability for regulatory compliance.
  • Prevents deletion/modification by root user.
  • Can be combined with S3 Lifecycle policies for automated deletion after retention.

Memory trick: Compliance Lock: No one deletes the law.

More Reliability and Business Continuity questions