A company must retain customer records in Amazon S3 for 7 years after each record is created and must prevent any deletions or modifications, even by the root user. Using S3 Object Lock, which solution satisfies these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable compliance mode on the S3 bucket. Use a default retention period of 7 years..
Why this is the answer
The correct solution is to enable compliance mode on the S3 bucket with a default retention period of 7 years. Compliance mode prevents an object version from being overwritten or deleted by any user, including the root user, until the retention period expires. This directly addresses the requirement to prevent deletions or modifications, even by the root user, for 7 years. Governance mode allows users with specific IAM permissions to override or delete an object version, which does not meet the requirement to prevent deletions even by the root user. Placing a legal hold on individual objects is a separate mechanism for indefinite retention, not tied to a specific time period like 7 years, and it needs to be applied per object, which is less efficient for a blanket requirement. Setting the retention period for individual objects is also less efficient than a default bucket-level setting when all objects need the same retention.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed