SAA-C03 exam dumps

SAA-C03 practice question 493 of 553

AWS Certified Solutions Architect - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAA-C03 Question 493

Select 2

A company needs to store sensitive financial data in Amazon S3 for compliance purposes. Their data retention policy requires that all data be retained for 7 years and automatically deleted after that period without manual intervention. Additionally, they must ensure no one can delete the data before the retention period ends. Which solution should the company implement?

  1. A

    Enable Amazon S3 Object Lock in compliance mode and set a retention period of 7 years.

  2. B

    Use lifecycle policies to move the data to the S3 Glacier storage class and set a delete marker for 7 years.

  3. C

    Set up an Amazon S3 bucket policy that denies delete operations for all objects older than 7 years.

  4. D

    Enable versioning on the S3 bucket and configure an S3 lifecycle policy to delete expired object versions after 7 years.

  5. E

    Enable Amazon S3 Object Lock in governance mode and set a retention period of 7 years.

Show answer and explanation

Correct answers: A, E

Explanation

To enforce a 7-year retention policy with no manual intervention and ensure the data cannot be deleted before the retention period ends, Amazon S3 Object Lock is the appropriate solution. Compliance mode provides the highest level of protection, as even AWS account administrators cannot delete the data. Governance mode offers retention enforcement but allows account administrators to override the lock if necessary.

  • A. Correct.

    This is correct. Enabling S3 Object Lock in compliance mode ensures that no one, including AWS account administrators, can override the retention settings. Setting a retention period of 7 years satisfies the requirement.

  • B. Incorrect.

    This is incorrect. While lifecycle policies can transition data to Glacier and apply delete markers, they do not enforce an immutable retention policy and cannot prevent deletions during the retention period.

  • C. Incorrect.

    This is incorrect. Bucket policies cannot enforce time-based retention or immutability and do not fulfill the company's requirement to automatically delete data after 7 years.

  • D. Incorrect.

    This is incorrect. While versioning and lifecycle policies allow for management of object versions, they do not provide immutability or enforce a strict retention policy.

  • E. Correct.

    This is correct. Enabling S3 Object Lock in governance mode can enforce a retention period of 7 years. However, governance mode allows AWS account administrators to modify or delete objects if necessary, so it is slightly less restrictive than compliance mode.

Timed practice exam

Take a SAA-C03 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam