AWS Certified SysOps Administrator – AssociateReliability and Business ContinuityHard
A SysOps Administrator needs to ensure that critical configuration data stored in an Amazon S3 bucket is replicated to a different AWS account for disaster recovery purposes. The data must be encrypted at rest and in transit. The replication should happen automatically and asynchronously whenever new objects are added to the source bucket. Which S3 feature should be configured?
- AS3 Versioning enabled on both buckets, and S3 Same-Region Replication.
- BS3 Versioning enabled on both buckets, and S3 Cross-Region Replication.
- CS3 Object Lock on the destination bucket, and S3 Lifecycle policies.
- DAWS Backup configured to back up the S3 bucket to the destination account.
Show answer & explanationAnswer & explanation
Correct answer: B. S3 Versioning enabled on both buckets, and S3 Cross-Region Replication.
S3 Cross-Region Replication (CRR) is designed for automatic, asynchronous replication of objects between S3 buckets in different AWS Regions or accounts. Both source and destination buckets must have S3 Versioning enabled for CRR to function. CRR also supports encryption of objects at rest and in transit.
Why the other options are wrong
- A. S3 Same-Region Replication (SRR) replicates objects within the same AWS Region, which does not meet the 'different AWS account for disaster recovery' requirement, implying a different region or at least a different account even if same region.
- C. S3 Object Lock ensures immutability, and Lifecycle policies manage object transitions/expiration, but neither provides automatic cross-account replication.
- D. AWS Backup can back up S3 buckets but typically involves scheduled backups rather than real-time, asynchronous replication as objects are added. CRR is more suited for continuous, automatic replication.
S3 Cross-Region Replication (CRR)
S3 Cross-Region Replication (CRR) automatically and asynchronously copies objects across S3 buckets in different AWS Regions or accounts, enabling disaster recovery and compliance.
- Requires S3 Versioning enabled on both source and destination buckets.
- Replicates new objects, object updates, and object deletions (optional).
- Supports encryption at rest and in transit.
- Can replicate to different accounts and regions for DR.
Memory trick: CRR: Copy, Replicate, Recover.