A company must archive sensitive records to Amazon S3 Glacier and ensure that no AWS account can modify the data. The retention policy requires that the vault lock be enforced under the proper validation timeframe. Which approach satisfies the compliance need?
Choose an answer
Tap an option to check your answer.
Correct answer: Apply a vault lock policy to the Glacier vault containing the archives. Validate the vault lock using the lock ID within 24 hours..
Why this is the answer
The correct approach is to apply a vault lock policy to the Amazon S3 Glacier vault and then validate it using the lock ID within 24 hours. When you initiate a vault lock, it enters a InProgress state. During this 24-hour period, you can test the policy and make changes if necessary. To finalize the policy and make it immutable, you must complete the lock process by calling CompleteVaultLock with the lock ID within that 24-hour window. If you do not complete the lock within 24 hours, the policy reverts to an Aborted state. Using S3 Object Lock in Governance mode is incorrect because the question specifically states archiving to Amazon S3 Glacier, not S3 Standard or S3 Intelligent-Tiering. While S3 Object Lock provides immutability, it's a feature of Amazon S3, not S3 Glacier vaults.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed