S3 3 Flashcards
Object Lock
What is Object Lock?
Lock an object so it can’t be deleted. Good for security controls.
Object Lock
How do you apply it to an object?
Turn on only for new buckets.
Object Lock
What about old buckets and Object Lock?
Have to create a support ticket to turn it on.
Object Lock
What’s the side-effect to turning on Object Lock?
Bucket Versioning turns on too.
Object Lock
What’s the WORM lock?
Write once, read many: can’t change it or delete it.
Object Lock
What’s the Retention Period Lock?
Pick time, can’t alter the file until period over.
Object Lock
What’s Legal Hold type of Object Lock?
Just an on/off setting. When on, can’t change or delete the object at all.
Object Lock
How long can a Legal Hold lock be set to?
N/A, Legal Hold is just an on/off, no timeline.
Object Lock
Can an object have both types of locks?
Yes
Object Lock
How do you turn on Object Lock for a bucket?
Can’t: just like encryption. Can set a default, but each object is set differently.
Object Lock
How long can a Retention Lock be?
Years
Object Lock
Two types of Retention Locks?
Compliance and Governance
Object Lock
Once set, what in a Compliance Lock can be changed?
Nothing (not duration, not type, it’s cast in stone).
Object Lock
Can the account root user change a Compliance Lock?
No
Object Lock
What’s different about Governance Locks?
Can use s3:BypassGovernanceRetention to change settings