AWS Certified DevOps Engineer – ProfessionalIncident and Event ResponseEasy

A financial services company utilizes AWS for its critical applications and has strict regulatory requirements for data integrity and immutability. They need to ensure that once an object is written to an Amazon S3 bucket, it cannot be altered or deleted for a specific retention period. This requirement applies to all new objects uploaded to a particular S3 bucket. Which S3 feature should the DevOps team implement to meet this requirement with the LEAST operational overhead?

  1. AUse S3 Block Public Access settings to restrict all public write access to the bucket.
  2. BImplement S3 Replication to a different bucket with strict IAM policies preventing deletion.
  3. CEnable S3 Versioning on the bucket and configure a lifecycle policy to transition old versions to S3 Glacier.
  4. DConfigure S3 Object Lock in compliance mode for the bucket with a defined retention period.
Show answer & explanation

Correct answer: D. Configure S3 Object Lock in compliance mode for the bucket with a defined retention period.

S3 Object Lock is specifically designed to prevent objects from being altered or deleted for a fixed amount of time or indefinitely. Compliance mode offers the strongest protection, ensuring that even the root user cannot delete objects during the retention period.

Why the other options are wrong

  • A. S3 Block Public Access prevents public write access but does not prevent authorized users from altering or deleting objects, nor does it enforce immutability.
  • B. S3 Replication creates copies but does not inherently prevent alteration or deletion of the original or replicated objects without additional controls like Object Lock.
  • C. S3 Versioning keeps multiple versions but does not prevent deletion of the current version or alteration of its contents without specific Object Lock configuration.

S3 Object Lock

An Amazon S3 feature that prevents objects from being deleted or overwritten for a fixed amount of time or indefinitely, ensuring data immutability.

  • Supports Write Once, Read Many (WORM) model.
  • Two modes: Governance and Compliance.
  • Requires S3 Versioning to be enabled on the bucket.

Memory trick: Object Lock locks your data like a vault.

More Incident and Event Response questions