A company stores data in Amazon S3 Glacier. A new vault lock policy was applied to 10 TB of data, and the initiate-vault-lock operation was called 12 hours ago. An audit found a typo in the policy that allows unintended access. What is the most cost-effective way to fix this?
Choose an answer
Tap an option to check your answer.
Correct answer: Call abort-vault-lock, update the policy, and then call initiate-vault-lock again..
Why this is the answer
The initiate-vault-lock operation in Amazon S3 Glacier starts a 24-hour lockable state. During this period, the vault lock policy is pending, and you can call abort-vault-lock to cancel the lock before it becomes immutable. Since 12 hours have passed, the lock is still in the pending state, making abort-vault-lock the correct and most cost-effective action. After aborting, you can correct the typo in the policy and then call initiate-vault-lock again. Copying data to a new S3 bucket or vault is expensive and unnecessary. Updating the policy in place is not possible once initiate-vault-lock has been called, as the policy is locked for modification during the pending period. Calling initiate-vault-lock again without aborting the pending lock will result in an error.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed