Q: 4
A company is storing backups in an Amazon S3 bucket. These backups must not be deleted for at
least 3 months after creation.
What should the CloudOps engineer do?
Options
Discussion
Option B
Option B
Yep, B for sure. Compliance mode actually blocks deletion for everyone, even root, for the retention period.
Read about this in the official AWS docs, compliance mode (B) is the strict one that stops deletes for everyone, even root. Labs around S3 Object Lock are helpful if you want hands-on. Pretty sure B fits what the exam wants.
B
Option B
B, not D. I think governance mode (D) only works if the user doesn't have special permissions to bypass it, but with compliance mode (B), even root can't delete the object until the period ends. Tricky because governance sounds secure, but exam questions usually want the stricter setting. Open to other thoughts though if I'm missing something.
D had something like this in a mock where governance mode worked for retention too.
Its D
Probably B since "must not be deleted" covers even root and compliance mode is the only way to enforce that.
Be respectful. No spam.