Solution Architect - Associate 01
S3
What is S3?
S3 (Simple Storage Service) is an object storage service that offers industry-leading durability, data availability, and security.
- S3 Standard: Frequently accessed; short-term/temporary data, typically stored for less than 30 days.
- S3 Intelligent-Tiering: Long-term storage; access frequency is unpredictable or you prefer not to classify data manually; automatic cost optimization is desired.
- S3 Standard-IA: Infrequently accessed, but data must be retrievable within milliseconds; requires multi-AZ high availability
- S3 One Zone-IA: Infrequently accessed and requires immediate retrieval, but only a single replica is needed; AZ-level failure risk is acceptable
- S3 Glacier Instant/Flexible Retrieval: Rarely accessed; retrieval delays from a few minutes to several hours are acceptable; suitable for long-term archiving
- S3 Glacier Deep Archive: Almost never accessed; lowest possible cost is the priority; retrieval delays of several hours to one day are acceptable; suitable for compliance and long-term retention
A company’s log files are accessed frequently for the first 30 days after creation, then almost never accessed. The business requires instant retrieval at any time. How can storage cost be minimized while keeping instant access?
- Configure a lifecycle rule to transition to S3 Standard-IA after 30 days
Standard-IA is suitable for infrequently accessed data that requires millisecond retrieval and multi-AZ high availability. By transitioning the log files to S3 Standard-IA after 30 days, the company can minimize storage costs while still ensuring instant access when needed.
Objects in a bucket have unpredictable access patterns — sometimes frequent, sometimes untouched for long periods. The architect wants cost automatically optimized without extra operational overhead or retrieval delay. What should be done?
- Use S3 Intelligent-Tiering so S3 automatically moves objects between tiers based on access pattern
When objects are stored in S3 Intelligent-Tiering, S3 automatically moves them between the frequent access and infrequent access tiers based on their access patterns. This allows for cost optimization without requiring manual intervention or causing retrieval delays.
Archived data is almost never accessed within a year; a retrieval wait of several hours is acceptable when needed, and the goal is the lowest possible storage cost. Which storage class should be chosen?
- S3 Glacier Flexible Retrieval / Deep Archive
S3 Glacier Flexible Retrieval and S3 Glacier Deep Archive are both suitable for long-term archiving of data that is rarely accessed. S3 Glacier Flexible Retrieval allows for retrieval within a few minutes to several hours, while S3 Glacier Deep Archive is designed for data that is almost never accessed and can tolerate retrieval delays of several hours to one day. Both options provide the lowest possible storage costs for long-term retention.
A company moved a large number of small files (a few KB each), meant to be kept for only about 20 days, into S3 Standard-IA, and found the total bill was actually higher than keeping them in Standard. What is the most likely reason?
- Standard-IA has a minimum storage duration (30 days) and a minimum billable object size (128KB), so small short-lived objects trigger extra charges
S3 Standard-IA has a minimum storage duration of 30 days and a minimum billable object size of 128KB. If the company moved small files (a few KB each) into S3 Standard-IA and kept them for only about 20 days, they would incur extra charges due to the minimum storage duration and the fact that the files are smaller than the minimum billable size. This results in a higher total bill compared to keeping them in S3 Standard, which does not have these limitations.
If companies have a large number of small files that are short-lived, they should consider using S3 Standard or S3 Intelligent-Tiering to avoid unnecessary costs associated with S3 Standard-IA.
A company’s data access pattern is completely unpredictable. Besides wanting automatic switching between frequent and infrequent access tiers, they also want objects that go long-unaccessed to automatically drop further into archive or deep archive tiers, without configuring extra lifecycle rules. What should be done?
- Use S3 Intelligent-Tiering with its optional Archive Access / Deep Archive Access tiers enabled
S3 Intelligent-Tiering with Archive Access and Deep Archive Access tiers enabled allows for automatic movement of objects between frequent access, infrequent access, archive, and deep archive tiers based on their access patterns. This means that objects that go long-unaccessed can automatically drop into the archive or deep archive tiers without the need for additional lifecycle rules, providing cost optimization and convenience for unpredictable data access patterns.
Object Lock
Object Lock is a feature that allows you to store objects using a write-once-read-many (WORM) model. It can help prevent objects from being deleted or overwritten for a fixed amount of time or indefinitely.
- Object Lock – Compliance Mode: A strict compliance mode. During the retention period, no one can delete or modify the object — not even the AWS account root user or AWS itself.
- Object Lock – Governance Mode: A controlled governance mode. Regular users cannot delete or modify protected objects, but users with special permissions can override the protection when necessary.
- Object Lock – Legal Hold: A legal hold flag that is not limited by a retention period. It can be enabled or removed at any time by users with the required permissions.
A financial company must, for regulatory reasons, guarantee that transaction records cannot be deleted or modified by anyone (including account admins) during the retention period, even if credentials are compromised. What should be done?
- Enable Object Lock in Compliance mode on the bucket with a retention period
Enabling Object Lock in Compliance mode on the bucket with a retention period ensures that transaction records cannot be deleted or modified by anyone, including account admins, during the specified retention period. This provides a strict WORM (write-once-read-many) model that meets regulatory requirements and protects against unauthorized changes, even if credentials are compromised.
A company needs to prevent accidental deletion of objects during the retention period, but wants a small set of privileged users to be able to override the retention setting in an emergency. Which Object Lock mode should be used?
- Governance mode
Enabling Object Lock in Governance mode allows the company to prevent accidental deletion of objects during the retention period while still allowing a small set of privileged users to override the retention setting in case of an emergency. This mode provides a balance between data protection and operational flexibility, ensuring that critical data remains secure while allowing for necessary administrative actions when required.
Audit requirements state that certain documents must remain immutable for a legally mandated period once uploaded, to support potential litigation holds. Which S3 feature can lock/unlock an object independently of any retention period?
- Object Lock’s Legal Hold
Object Lock’s Legal Hold feature allows for locking and unlocking an object independently of any retention period. This is particularly useful for audit requirements where certain documents must remain immutable for a legally mandated period to support potential litigation holds. Legal Hold can be enabled or removed at any time by users with the required permissions, providing flexibility while ensuring compliance with legal obligations.
Versioning
S3 Versioning is a feature that allows you to keep multiple versions of an object in the same bucket. It helps protect against accidental deletion or overwriting of objects.
- Versioning: When enabled, S3 Versioning allows you to preserve, retrieve, and restore every version of every object stored in your bucket. This means that if an object is deleted or overwritten, you can still access its previous versions.
- MFA Delete: A security feature that requires additional authentication (multi-factor authentication) to permanently delete an object version. This adds an extra layer of protection against accidental or malicious deletions.
- Noncurrent Versioning: S3 allows you to have multiple versions of an object, and you can retrieve or restore any version as needed. This is useful for maintaining a history of changes and recovering from unintended modifications.
Multiple people on a team collaboratively edit a config file stored in S3. A recent mistake overwrote an important file with stale content, and the team wants to be able to restore the previous version in the future. What should be done?
- Enable Versioning on the bucket
Even with versioning enabled, the company worries someone could still permanently delete a version by mistake, and wants an extra layer of protection requiring a one-time MFA code for deletion. What should be enabled?
- MFA Delete (requires versioning to be enabled first)
An S3 bucket has had versioning enabled for a while, and the company is now worried that accumulating old versions are driving up storage cost. How can cost be controlled while keeping recovery ability?
- Configure a lifecycle rule that transitions or expires noncurrent versions after a set number of days
A company’s on-premises file server holds many files that are accessed frequently and need low latency for the first 7 days, then are rarely accessed. The company wants to extend storage capacity and automatically manage future storage cost, with the least operational overhead. What should be done?
- Deploy an S3 File Gateway to extend storage, with a lifecycle policy transitioning data to S3 Glacier Deep Archive after 7 days
Log objects in a bucket must transition to Standard-IA after 30 days, to Glacier after 90 days, and be permanently deleted after 365 days. What feature configures this once, with no manual repeat work needed?
- S3 Lifecycle Rule, configuring transition and expiration time points
An architect needs a rule that automatically and permanently deletes certain compliance documents 7 years after creation, without relying on any scheduled job or script. How should this be implemented?
- Configure the Expiration action in an S3 lifecycle rule to delete objects 7 years after creation





