Medium1 markMultiple Choice
Domain 1.3: Data SecurityS3Object LockCompliance

AWS SAA-C03 · Question 16 · Domain 1.3: Data Security

A financial company must store regulatory documents in Amazon S3. Compliance rules dictate that the documents must be stored in a Write-Once-Read-Many (WORM) model and cannot be deleted or modified by anyone, including the AWS account root user, for exactly 7 years.<br/><br/>Which TWO actions should a solutions architect take? (Select TWO.)

Answer options:

A.

Enable S3 Object Lock in Governance mode.

B.

Enable S3 Object Lock in Compliance mode.

C.

Set a retention period of 7 years.

D.

Use an S3 bucket policy to deny the s3:DeleteObject action.

E.

Enable S3 Versioning and MFA Delete.

How to approach this question

Differentiate between Compliance mode and Governance mode in S3 Object Lock.

Full Answer

Enable S3 Object Lock in Compliance mode.<br/>Set a retention period of 7 years.
S3 Object Lock in Compliance mode ensures objects cannot be overwritten or deleted by any user, including the root user, for the duration of the retention period. This is required for strict regulatory WORM compliance.

Common mistakes

Selecting Governance mode or thinking MFA Delete is sufficient for WORM compliance.

Practice the full AWS SAA-C03 Practice Exam 6

65 questions · hints · full answers · grading

More questions from this exam