PAS-C01 · Question #108
A company's SAP basis team is responsible for database backups in Amazon S3. The company frequently needs to restore the last 3 months of backups into the pre-production SAP system to perform tests…
The correct answer is B. Enable versioning and multi-factor authentication (MFA) on the S3 bucket. Enabling S3 Versioning means that when an object is 'deleted,' Amazon S3 inserts a delete marker rather than permanently removing the data; the previous versions remain recoverable. This directly addresses accidental deletion: the files can be restored by removing the delete…
Question
A company's SAP basis team is responsible for database backups in Amazon S3. The company frequently needs to restore the last 3 months of backups into the pre-production SAP system to perform tests and analyze performance. Previously, an employee accidentally deleted backup files from the S3 bucket. The SAP basis team wants to prevent accidental deletion of backup files in the future. Which solution will meet these requirements?
Options
- ACreate a new resource-based policy that prevents deletion of the S3 bucket.
- BEnable versioning and multi-factor authentication (MFA) on the S3 bucket.
- CCreate signed cookies for the backup files in the S3 bucket. Provide the signed cookies to
- DApply an S3 Lifecycle policy to move the backup files immediately to S3 Glacier.
How the community answered
(58 responses)- A14% (8)
- B76% (44)
- C3% (2)
- D7% (4)
Explanation
Enabling S3 Versioning means that when an object is 'deleted,' Amazon S3 inserts a delete marker rather than permanently removing the data; the previous versions remain recoverable. This directly addresses accidental deletion: the files can be restored by removing the delete marker. Enabling MFA Delete adds a second layer of protection by requiring multi-factor authentication before versioned objects can be permanently deleted or versioning can be suspended, preventing even an authorized but careless IAM user from destroying backup data. Together, these two features fulfill both requirements - protecting against accidental deletion and retaining 3 months of restorable backups. A resource-based policy (A) alone can restrict deletion but does not provide recovery if a deletion does occur. Signed cookies (C) control read access, not deletion. An S3 Lifecycle policy moving files to Glacier (D) reduces cost but does not prevent accidental deletion.
Topics
Community Discussion
No community discussion yet for this question.