A company stores sensitive data in an Amazon S3 bucket encrypted with server-side encryption with Amazon S3 managed keys (SSE-S3). A security engineer must prevent any modifications to the objects. Which solution meets this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable S3 Object Lock in Compliance mode and turn on S3 bucket versioning..
Why this is the answer
Enabling S3 Object Lock in Compliance mode, combined with S3 bucket versioning, makes objects immutable for a specified retention period. In Compliance mode, even the root user cannot delete or overwrite objects until the retention period expires, ensuring no modifications. Versioning is essential because Object Lock protects individual object versions. Using an S3 bucket policy to deny
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed