Question 1 · choose 1
Trade records stored in S3 must be kept for seven years. During that time nobody, including the root user, may delete or overwrite them. The legal team must also be able to keep individual records beyond seven years, with no end date, while litigation is open. Which configuration meets these requirements?
- AObject Lock in governance mode with seven-year default retention, plus legal holds
- BS3 Versioning with MFA delete turned on by the root user
- CAmazon Glacier Vault Lock with a seven-year policy for the bucket
- DObject Lock in compliance mode with seven-year default retention, plus legal holds
Show the answer and why
AObject Lock in governance mode with seven-year default retention, plus legal holds
Incorrect
In governance mode, users with s3:BypassGovernanceRetention can remove the protection, so the records are not safe from everyone.
BS3 Versioning with MFA delete turned on by the root user
Incorrect
MFA delete adds a step for deleting versions, but a user with the MFA device and permissions can still delete them.
CAmazon Glacier Vault Lock with a seven-year policy for the bucket
Incorrect
Vault Lock policies apply to vaults in the standalone Amazon Glacier service, which no longer accepts new customers, not to objects in S3 buckets.
DObject Lock in compliance mode with seven-year default retention, plus legal holds
Correct
Compliance mode stops anyone, including the root user, from deleting or overwriting a version during retention; a legal hold has no expiry until removed.
Compliance mode makes retention unbreakable, and legal holds extend protection for as long as needed. Object Lock requires versioning on the bucket.
AWS documentation