A security engineer must implement a write-once-read-many (WORM) control for data stored in Amazon S3 buckets that use the S3 Standard storage class. The solution must prevent overwriting or deleting objects by any user, including the root user. Which approach meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Create new S3 buckets with S3 Object Lock enabled in compliance mode. Store objects in those buckets..
Why this is the answer
S3 Object Lock in compliance mode prevents an object from being overwritten or deleted by any user, including the root user, for a fixed amount of time or indefinitely. This fulfills the WORM requirement and protects against accidental or malicious deletion. S3 Glacier Vault Lock is for S3 Glacier vaults, not S3 Standard buckets. S3 Object Lock in governance mode allows users with special permissions to override or remove object locks, which does not meet the requirement to prevent deletion by any user, including root. Applying a legal hold in governance mode still doesn't prevent the root user from removing the hold.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed