exam questions

Exam AWS Certified SysOps Administrator - Associate All Questions

View all questions & answers for the AWS Certified SysOps Administrator - Associate exam

Exam AWS Certified SysOps Administrator - Associate topic 1 question 146 discussion

A company wants to archive sensitive data on Amazon S3 Glacier. The company’s regulatory and compliance requirements do not allow any modifications to the data by any account.

Which solution meets these requirements?

  • A. Attach a vault lock policy to an S3 Glacier vault that contains the archived data. Use the lock ID to validate the vault lock policy after 24 hours.
  • B. Attach a vault lock policy to an S3 Glacier vault that contains the archived data. Use the lock ID to validate the vault lock policy within 24 hours.
  • C. Configure S3 Object Lock in governance mode. Upload all files after 24 hours.
  • D. Configure S3 Object Lock in governance mode. Upload all files within 24 hours.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Xelnak
Highly Voted 1 year, 7 months ago
Selected Answer: B
While the policy is in the in-progress state, you have 24 hours to validate your Vault Lock policy before the lock ID expires. To prevent your vault from exiting the in-progress state, you must complete the Vault Lock process within these 24 hours. Otherwise, your Vault Lock policy will be deleted. https://docs.aws.amazon.com/amazonglacier/latest/dev/vault-lock.html#vault-lock-overview
upvoted 10 times
...
Christina666
Most Recent 11 months, 2 weeks ago
Selected Answer: B
Locking a vault takes two steps: Initiate the lock by attaching a Vault Lock policy to your vault, which sets the lock to an in-progress state and returns a lock ID. While the policy is in the in-progress state, you have 24 hours to validate your Vault Lock policy before the lock ID expires. To prevent your vault from exiting the in-progress state, you must complete the Vault Lock process within these 24 hours. Otherwise, your Vault Lock policy will be deleted. Use the lock ID to complete the lock process. If the Vault Lock policy doesn't work as expected, you can stop the Vault Lock process and restart from the beginning. For information about how to use the S3 Glacier API to lock a vault, see Locking a Vault by Using the S3 Glacier API.
upvoted 3 times
...
Gomer
1 year, 2 months ago
Selected Answer: B
Only Glacier Vault Lock Policy can block any user from deleting a file irregardless of age or other circumstance. S3 Object lock: "With governance mode, you protect objects against being deleted by most users, but you can still grant some users permission to alter the retention settings or delete the object if necessary." https://docs.aws.amazon.com/AmazonS3/latest/userguide/object-lock-overview.html S3 Glacier Vault Lock Access policy: "Vault access policy that can be locked. After you lock a Vault Lock policy, the policy can't be changed. You can use a Vault Lock Policy to enforce compliance controls." "Locking a vault takes two steps:" 1. "attaching a Vault Lock policy to your vault, which"... "returns a lock ID"... "you must complete the Vault Lock process within these 24 hours." 2. "Use the lock ID to complete the lock process." https://docs.aws.amazon.com/amazonglacier/latest/dev/vault-lock.html
upvoted 3 times
...
noahsark
1 year, 4 months ago
Selected Answer: B
Attach a vault lock policy to an S3 Glacier vault that contains the archived data. Use the lock ID to validate the vault lock policy within 24 hours. Notes: While the policy is in the in-progress state, you have 24 hours to validate your Vault Lock policy before the lock ID expires. https://docs.aws.amazon.com/amazonglacier/latest/dev/vault-lock.html
upvoted 2 times
...
Fatoch
1 year, 6 months ago
A and B are same answers.
upvoted 2 times
Gomer
1 year, 2 months ago
No they are not. Before and after 24 hours makes all the difference.
upvoted 1 times
...
...
marcelodba
1 year, 7 months ago
Selected Answer: B
https://docs.aws.amazon.com/amazonglacier/latest/dev/vault-lock.html#:~:text=Initiate%20the%20lock,will%20be%20deleted.
upvoted 1 times
...
Beidog
1 year, 7 months ago
Selected Answer: B
Vote for B
upvoted 1 times
...
Raynor
1 year, 7 months ago
B - https://docs.aws.amazon.com/amazonglacier/latest/dev/vault-lock.html#vault-lock-overview
upvoted 2 times
...
Liongeek
1 year, 7 months ago
Ans: A Ref: https://docs.aws.amazon.com/amazonglacier/latest/dev/vault-lock.html#vault-lock-overview
upvoted 1 times
zolthar_z
1 year, 6 months ago
Based on your link the answer is B
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...