Question 1 · choose 2
A company backs up Amazon EBS volumes and Amazon RDS databases in a production account with an AWS Backup plan. After a ransomware drill, the security team requires a copy of every backup in a separate backup account of the same organization, and no one, including the root user of either account, may delete or shorten the retention of those copies for 35 days. Which actions should the DevOps engineer take? (Choose TWO.)
- ACreate Amazon Data Lifecycle Manager policies in the production account that take EBS snapshots and keep them for 35 days
- BAttach a vault access policy to the destination vault that denies backup:DeleteRecoveryPoint to every principal in the backup account
- CLock the destination vault with AWS Backup Vault Lock in governance mode and a minimum retention of 35 days
- DAdd a copy action to the backup plan rule that copies each recovery point to a vault in the backup account
- ELock the destination vault with AWS Backup Vault Lock in compliance mode and a minimum retention of 35 days
Show the answer and why
ACreate Amazon Data Lifecycle Manager policies in the production account that take EBS snapshots and keep them for 35 days
Incorrect
Data Lifecycle Manager automates EBS snapshots in the same account, so an administrator there could still delete them, and it does not cover RDS.
BAttach a vault access policy to the destination vault that denies backup:DeleteRecoveryPoint to every principal in the backup account
Incorrect
A vault access policy controls only the AWS Backup APIs; EBS and RDS snapshots can also be reached through those services' own APIs. Vault Lock in compliance mode is what stops every user.
CLock the destination vault with AWS Backup Vault Lock in governance mode and a minimum retention of 35 days
Incorrect
A lock in governance mode can be removed by users with sufficient IAM permissions.
DAdd a copy action to the backup plan rule that copies each recovery point to a vault in the backup account
Correct
AWS Backup can copy backups to other accounts in the organization as part of a scheduled backup plan, with a destination vault and key in that account.
ELock the destination vault with AWS Backup Vault Lock in compliance mode and a minimum retention of 35 days
Correct
After the grace time, a compliance-mode lock cannot be changed or deleted, and AWS Backup denies any user, including the root user, who tries to delete a backup or change its lifecycle.
The copy puts the backups out of reach of the production account, and the compliance-mode lock makes them immutable for their retention period. A governance-mode lock can be removed with enough permissions, and an access policy covers only the AWS Backup APIs.
AWS documentation