A company must prevent permanent deletion of critical data stored in Amazon S3 and replicate that data from its primary AWS Region to a secondary Region for disaster recovery. Even users with administrator access must be unable to permanently delete data in the secondary Region. Which solution meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable S3 Object Lock in compliance mode on the primary Region bucket. Configure S3 replication to replicate objects to a bucket in the secondary Region..
Why this is the answer
The correct solution uses S3 Object Lock in compliance mode on the primary bucket. Compliance mode prevents anyone, including the root user, from deleting or altering an object version until its retention period expires. Replicating these objects to a secondary Region ensures disaster recovery. Incorrect options: AWS Backup with Vault Lock in governance mode could protect backups, but the question specifies preventing permanent deletion of critical data stored in Amazon S3, implying direct S3 protection, not just backups. Denying s3:ReplicateDelete prevents deletion markers from being replicated, but doesn't prevent direct deletion of objects in the secondary bucket by an administrator. S3 object versioning alone doesn't prevent permanent deletion; older versions can still be deleted by authorized users.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed