Topic 06 Practice Test 1 covers Data Governance, Backup, Replication, Retention, Lifecycle, and Access Controls for AWS SAA-C03. For broader exam preparation, review the AWS SAA-C03 Exam Dumps. Every option includes focused technical reasoning explaining both the AWS architecture concept and its fit to the scenario.
Question 1
Given that records must remain immutable for seven years and no privileged bypass is allowed, which approach most directly lets the team make regulated records non-deletable even by administrators during the retention period? Choose ONE.
- S3 Object Lock governance mode
- AWS Backup Vault Lock compliance mode
- S3 Object Lock legal hold
- S3 Object Lock compliance mode
Correct Answer(s)
D
Rationale
- S3 Object Lock governance mode is intended to apply WORM-style protection with an authorized emergency override. The case hinges on records must remain immutable for seven years and no privileged bypass is allowed. The team must make regulated records non-deletable even by administrators during the retention period. That capability is not the required control.
- AWS Backup Vault Lock compliance mode is designed to enforce WORM retention across AWS Backup recovery points. Limiting condition: records must remain immutable for seven years and no privileged bypass is allowed; solution must make regulated records non-deletable even by administrators during the retention period. That leaves the key constraint unresolved.
- S3 Object Lock legal hold can help a team hold selected S3 versions without choosing an expiration date. Because records must remain immutable for seven years and no privileged bypass is allowed, the team must make regulated records non-deletable even by administrators during the retention period. The scenario calls for another native capability.
- S3 Object Lock compliance mode fits situations that require teams to enforce non-bypassable WORM retention on S3 versions. Requirement: make regulated records non-deletable even by administrators during the retention period; key constraint: records must remain immutable for seven years and no privileged bypass is allowed. That makes this the strongest fit.
Question 2
Which option best supports this requirement: protect operational evidence while retaining a tightly controlled override path? Constraint: security administrators need retention protection but a break-glass role may remove it. Choose ONE.
- S3 Object Lock compliance mode
- S3 Object Lock governance mode
- S3 Object Lock legal hold
- AWS Backup Vault Lock compliance mode
Correct Answer(s)
B
Rationale
- S3 Object Lock compliance mode primarily prevents protected object versions from being overwritten or deleted, including by privileged users, until retention expires. Case: security administrators need retention protection but a break-glass role may remove it; required action: protect operational evidence while retaining a tightly controlled override path. That leaves the key constraint unresolved.
- S3 Object Lock governance mode protects versions while permitting specially authorized users to bypass governance retention. The case hinges on security administrators need retention protection but a break-glass role may remove it. The team must protect operational evidence while retaining a tightly controlled override path. Its native behavior fits this need.
- S3 Object Lock legal hold fits situations that require teams to hold selected S3 versions without choosing an expiration date. Decisive fact: security administrators need retention protection but a break-glass role may remove it; requested action: protect operational evidence while retaining a tightly controlled override path. That mismatch makes it a weaker choice.
- AWS Backup Vault Lock compliance mode addresses the need to enforce WORM retention across AWS Backup recovery points. Given security administrators need retention protection but a break-glass role may remove it, the relevant choice must protect operational evidence while retaining a tightly controlled override path. The scenario calls for another native capability.
Question 3
The release date is unknown and only particular object versions require protection. What should the team do to preserve selected investigation artifacts until counsel releases them? Choose ONE.
- S3 Object Lock legal hold
- AWS Backup Vault Lock compliance mode
- S3 Object Lock governance mode
- S3 Object Lock compliance mode
Correct Answer(s)
A
Rationale
- S3 Object Lock legal hold can help a team hold selected S3 versions without choosing an expiration date. Requirement: preserve selected investigation artifacts until counsel releases them; key constraint: the release date is unknown and only particular object versions require protection. This is the precise capability required.
- AWS Backup Vault Lock compliance mode primarily makes the vault lock immutable after its grace period and prevents early deletion of protected recovery points. Limiting condition: the release date is unknown and only particular object versions require protection; solution must preserve selected investigation artifacts until counsel releases them. That leaves the key constraint unresolved.
- S3 Object Lock governance mode is designed to apply WORM-style protection with an authorized emergency override. Here, the release date is unknown and only particular object versions require protection; design must preserve selected investigation artifacts until counsel releases them. Its primary role differs from this need.
- S3 Object Lock compliance mode supports teams that need to enforce non-bypassable WORM retention on S3 versions. The case hinges on the release date is unknown and only particular object versions require protection. The team must preserve selected investigation artifacts until counsel releases them. That capability is not the required control.
Question 4
The team needs to protect centralized backups from privileged deletion after a cooling-off period, but ransomware resilience requires immutable recovery points managed by AWS Backup. Which option is best? Choose ONE.
- S3 Object Lock legal hold
- AWS Backup Vault Lock compliance mode
- S3 Object Lock compliance mode
- S3 Object Lock governance mode
Correct Answer(s)
B
Rationale
- S3 Object Lock legal hold is intended to hold selected S3 versions without choosing an expiration date. Given ransomware resilience requires immutable recovery points managed by AWS Backup, the relevant choice must protect centralized backups from privileged deletion after a cooling-off period. The scenario calls for another native capability.
- AWS Backup Vault Lock compliance mode is designed to enforce WORM retention across AWS Backup recovery points. The case hinges on ransomware resilience requires immutable recovery points managed by AWS Backup. The team must protect centralized backups from privileged deletion after a cooling-off period. Its native behavior fits this need.
- S3 Object Lock compliance mode prevents protected object versions from being overwritten or deleted, including by privileged users, until retention expires. Because ransomware resilience requires immutable recovery points managed by AWS Backup, the team must protect centralized backups from privileged deletion after a cooling-off period. This would address the wrong decision point.
- S3 Object Lock governance mode fits situations that require teams to apply WORM-style protection with an authorized emergency override. Case: ransomware resilience requires immutable recovery points managed by AWS Backup; required action: protect centralized backups from privileged deletion after a cooling-off period. That leaves the key constraint unresolved.
Question 5
Given that access frequency is predictable and the transition date is known, which approach most directly lets the team move old log objects to an archive class after a fixed number of days? Choose ONE.
- S3 Lifecycle rules
- S3 Replication Time Control
- S3 Intelligent-Tiering
- S3 Cross-Region Replication
Correct Answer(s)
A
Rationale
- S3 Lifecycle rules addresses the need to apply deterministic age-based storage-class and expiration actions. Requirement: move old log objects to an archive class after a fixed number of days; key constraint: access frequency is predictable and the transition date is known. This is the precise capability required.
- S3 Replication Time Control supports teams that need to meet a predictable replication-time requirement for replicated S3 objects. Because access frequency is predictable and the transition date is known, the team must move old log objects to an archive class after a fixed number of days. The scenario calls for another native capability.
- S3 Intelligent-Tiering automatically moves eligible objects among access tiers as access patterns change without retrieval fees for automatic tiers. Given access frequency is predictable and the transition date is known, the relevant choice must move old log objects to an archive class after a fixed number of days. This would address the wrong decision point.
- S3 Cross-Region Replication primarily asynchronously replicates eligible S3 objects and metadata to a bucket in another AWS Region. Here, access frequency is predictable and the transition date is known; design must move old log objects to an archive class after a fixed number of days. Its primary role differs from this need.
Question 6
Which option best supports this requirement: reduce storage cost for a data set whose access pattern changes unpredictably? Constraint: the team cannot reliably forecast which objects will become cold. Choose ONE.
- S3 Replication Time Control
- S3 Intelligent-Tiering
- S3 Lifecycle rules
- S3 Cross-Region Replication
Correct Answer(s)
B
Rationale
- S3 Replication Time Control supports teams that need to meet a predictable replication-time requirement for replicated S3 objects. Given the team cannot reliably forecast which objects will become cold, the relevant choice must reduce storage cost for a data set whose access pattern changes unpredictably. The scenario calls for another native capability.
- S3 Intelligent-Tiering can help a team optimize storage when object access frequency is unpredictable. Case: the team cannot reliably forecast which objects will become cold; required action: reduce storage cost for a data set whose access pattern changes unpredictably. This aligns cleanly with the requirement.
- S3 Lifecycle rules is intended to apply deterministic age-based storage-class and expiration actions. Decisive fact: the team cannot reliably forecast which objects will become cold; requested action: reduce storage cost for a data set whose access pattern changes unpredictably. This does not deliver the requested outcome.
- S3 Cross-Region Replication is designed to maintain an S3 replica in a different Region. Because the team cannot reliably forecast which objects will become cold, the team must reduce storage cost for a data set whose access pattern changes unpredictably. This would address the wrong decision point.
Question 7
The destination must be outside the source Region and updates should replicate automatically. What should the team do to copy new protected objects to a bucket in another Region for regional isolation? Choose ONE.
- S3 Replication Time Control
- S3 Lifecycle rules
- S3 Cross-Region Replication
- S3 Intelligent-Tiering
Correct Answer(s)
C
Rationale
- S3 Replication Time Control addresses the need to meet a predictable replication-time requirement for replicated S3 objects. Limiting condition: the destination must be outside the source Region and updates should replicate automatically; solution must copy new protected objects to a bucket in another Region for regional isolation. This solves a neighboring problem instead.
- S3 Lifecycle rules fits situations that require teams to apply deterministic age-based storage-class and expiration actions. Here, the destination must be outside the source Region and updates should replicate automatically; design must copy new protected objects to a bucket in another Region for regional isolation. Its primary role differs from this need.
- S3 Cross-Region Replication asynchronously replicates eligible S3 objects and metadata to a bucket in another AWS Region. Decisive fact: the destination must be outside the source Region and updates should replicate automatically; requested action: copy new protected objects to a bucket in another Region for regional isolation. That makes this the strongest fit.
- S3 Intelligent-Tiering is intended to optimize storage when object access frequency is unpredictable. Requirement: copy new protected objects to a bucket in another Region for regional isolation; key constraint: the destination must be outside the source Region and updates should replicate automatically. This does not deliver the requested outcome.
Question 8
The team needs to provide metrics and an SLA for timely replication of compliance objects, but ordinary asynchronous replication gives no business-required predictable completion window. Which option is best? Choose ONE.
- S3 Lifecycle rules
- S3 Intelligent-Tiering
- S3 Cross-Region Replication
- S3 Replication Time Control
Correct Answer(s)
D
Rationale
- S3 Lifecycle rules addresses the need to apply deterministic age-based storage-class and expiration actions. Case: ordinary asynchronous replication gives no business-required predictable completion window; required action: provide metrics and an SLA for timely replication of compliance objects. This solves a neighboring problem instead.
- S3 Intelligent-Tiering primarily automatically moves eligible objects among access tiers as access patterns change without retrieval fees for automatic tiers. Because ordinary asynchronous replication gives no business-required predictable completion window, the team must provide metrics and an SLA for timely replication of compliance objects. This would address the wrong decision point.
- S3 Cross-Region Replication supports teams that need to maintain an S3 replica in a different Region. Decisive fact: ordinary asynchronous replication gives no business-required predictable completion window; requested action: provide metrics and an SLA for timely replication of compliance objects. This does not deliver the requested outcome.
- S3 Replication Time Control can help a team meet a predictable replication-time requirement for replicated S3 objects. The case hinges on ordinary asynchronous replication gives no business-required predictable completion window. The team must provide metrics and an SLA for timely replication of compliance objects. That capability directly satisfies the constraint.
Question 9
Given that many accounts and services need consistent backup timing and lifecycle, which approach most directly lets the team apply one centrally managed schedule and retention policy to tagged resources? Choose ONE.
- AWS Backup restore testing
- AWS Backup backup plans
- AWS Backup cross-account copy
- Amazon Data Lifecycle Manager
Correct Answer(s)
B
Rationale
- AWS Backup restore testing is designed to verify that protected recovery points can actually be restored. Decisive fact: many accounts and services need consistent backup timing and lifecycle; requested action: apply one centrally managed schedule and retention policy to tagged resources. That mismatch makes it a weaker choice.
- AWS Backup backup plans can help a team standardize policy-driven backups across supported AWS resources. Here, many accounts and services need consistent backup timing and lifecycle; design must apply one centrally managed schedule and retention policy to tagged resources. That capability directly satisfies the constraint.
- AWS Backup cross-account copy fits situations that require teams to place backup copies in a separate account. Given many accounts and services need consistent backup timing and lifecycle, the relevant choice must apply one centrally managed schedule and retention policy to tagged resources. This would address the wrong decision point.
- Amazon Data Lifecycle Manager is intended to manage recurring EBS snapshot or AMI lifecycle policies. Limiting condition: many accounts and services need consistent backup timing and lifecycle; solution must apply one centrally managed schedule and retention policy to tagged resources. This solves a neighboring problem instead.
Question 10
Which option best supports this requirement: isolate recovery points from administrators in the workload account? Constraint: a compromise of the production account must not remove every backup copy. Choose ONE.
- Amazon Data Lifecycle Manager
- AWS Backup restore testing
- AWS Backup cross-account copy
- AWS Backup backup plans
Correct Answer(s)
C
Rationale
- Amazon Data Lifecycle Manager automates creation, retention, and lifecycle management of EBS snapshots and EBS-backed AMIs. Limiting condition: a compromise of the production account must not remove every backup copy; solution must isolate recovery points from administrators in the workload account. That leaves the key constraint unresolved.
- AWS Backup restore testing primarily automates scheduled restore tests and records recovery validation results for supported resources. Requirement: isolate recovery points from administrators in the workload account; key constraint: a compromise of the production account must not remove every backup copy. That mismatch makes it a weaker choice.
- AWS Backup cross-account copy fits situations that require teams to place backup copies in a separate account. Because a compromise of the production account must not remove every backup copy, the team must isolate recovery points from administrators in the workload account. This addresses the decision at the right layer.
- AWS Backup backup plans addresses the need to standardize policy-driven backups across supported AWS resources. The case hinges on a compromise of the production account must not remove every backup copy. The team must isolate recovery points from administrators in the workload account. That capability is not the required control.
Question 11
Audit evidence must show periodic recovery testing. What should the team do to prove on a recurring schedule that backups are recoverable without manually running ad hoc restores? Choose ONE.
- Amazon Data Lifecycle Manager
- AWS Backup restore testing
- AWS Backup backup plans
- AWS Backup cross-account copy
Correct Answer(s)
B
Rationale
- Amazon Data Lifecycle Manager can help a team manage recurring EBS snapshot or AMI lifecycle policies. Given audit evidence must show periodic recovery testing, the relevant choice must prove on a recurring schedule that backups are recoverable without manually running ad hoc restores. The scenario calls for another native capability.
- AWS Backup restore testing primarily automates scheduled restore tests and records recovery validation results for supported resources. Decisive fact: audit evidence must show periodic recovery testing; requested action: prove on a recurring schedule that backups are recoverable without manually running ad hoc restores. That makes this the strongest fit.
- AWS Backup backup plans supports teams that need to standardize policy-driven backups across supported AWS resources. Limiting condition: audit evidence must show periodic recovery testing; solution must prove on a recurring schedule that backups are recoverable without manually running ad hoc restores. This solves a neighboring problem instead.
- AWS Backup cross-account copy is designed to place backup copies in a separate account. Case: audit evidence must show periodic recovery testing; required action: prove on a recurring schedule that backups are recoverable without manually running ad hoc restores. That leaves the key constraint unresolved.
Question 12
The team needs to create and expire EBS snapshots on a recurring tag-based schedule, but the requirement is limited to EBS volume protection and retention. Which option is best? Choose ONE.
- AWS Backup cross-account copy
- AWS Backup restore testing
- Amazon Data Lifecycle Manager
- AWS Backup backup plans
Correct Answer(s)
C
Rationale
- AWS Backup cross-account copy copies supported recovery points to a vault in another AWS account for isolation. Here, the requirement is limited to EBS volume protection and retention; design must create and expire EBS snapshots on a recurring tag-based schedule. Its primary role differs from this need.
- AWS Backup restore testing is intended to verify that protected recovery points can actually be restored. The case hinges on the requirement is limited to EBS volume protection and retention. The team must create and expire EBS snapshots on a recurring tag-based schedule. That capability is not the required control.
- Amazon Data Lifecycle Manager fits situations that require teams to manage recurring EBS snapshot or AMI lifecycle policies. Requirement: create and expire EBS snapshots on a recurring tag-based schedule; key constraint: the requirement is limited to EBS volume protection and retention. That makes this the strongest fit.
- AWS Backup backup plans is designed to standardize policy-driven backups across supported AWS resources. Limiting condition: the requirement is limited to EBS volume protection and retention; solution must create and expire EBS snapshots on a recurring tag-based schedule. That leaves the key constraint unresolved.
Question 13
Given that the first problem is discovering sensitive content across S3, which approach most directly lets the team find buckets containing personally identifiable information before applying stricter controls? Choose ONE.
- S3 Access Points
- S3 Inventory
- S3 Block Public Access
- Amazon Macie
Correct Answer(s)
D
Rationale
- S3 Access Points addresses the need to separate application-specific access policies to a shared bucket. Given the first problem is discovering sensitive content across S3, the relevant choice must find buckets containing personally identifiable information before applying stricter controls. The scenario calls for another native capability.
- S3 Inventory supports teams that need to audit S3 object metadata at scale. Here, the first problem is discovering sensitive content across S3; design must find buckets containing personally identifiable information before applying stricter controls. That capability is not the required control.
- S3 Block Public Access primarily provides account- or bucket-level controls that override public ACL and policy exposure paths. Case: the first problem is discovering sensitive content across S3; required action: find buckets containing personally identifiable information before applying stricter controls. That leaves the key constraint unresolved.
- Amazon Macie discovers and classifies sensitive data in Amazon S3 using managed data identifiers and findings. The case hinges on the first problem is discovering sensitive content across S3. The team must find buckets containing personally identifiable information before applying stricter controls. Its native behavior fits this need.
Question 14
Which option best supports this requirement: enforce a guardrail that blocks public access even if a bucket policy is later misconfigured? Constraint: public S3 exposure must be prevented broadly rather than reviewed manually. Choose ONE.
- Amazon Macie
- S3 Access Points
- S3 Inventory
- S3 Block Public Access
Correct Answer(s)
D
Rationale
- Amazon Macie can help a team identify sensitive S3 data for governance decisions. Requirement: enforce a guardrail that blocks public access even if a bucket policy is later misconfigured; key constraint: public S3 exposure must be prevented broadly rather than reviewed manually. This does not deliver the requested outcome.
- S3 Access Points is intended to separate application-specific access policies to a shared bucket. Because public S3 exposure must be prevented broadly rather than reviewed manually, the team must enforce a guardrail that blocks public access even if a bucket policy is later misconfigured. The scenario calls for another native capability.
- S3 Inventory supports teams that need to audit S3 object metadata at scale. The case hinges on public S3 exposure must be prevented broadly rather than reviewed manually. The team must enforce a guardrail that blocks public access even if a bucket policy is later misconfigured. That capability is not the required control.
- S3 Block Public Access is designed to prevent accidental public exposure of S3 data. Here, public S3 exposure must be prevented broadly rather than reviewed manually; design must enforce a guardrail that blocks public access even if a bucket policy is later misconfigured. Its native behavior fits this need.
Question 15
A shared data lake has different consumer permissions. What should the team do to give multiple applications distinct policies without growing one complex bucket policy? Choose ONE.
- S3 Inventory
- Amazon Macie
- S3 Access Points
- S3 Block Public Access
Correct Answer(s)
C
Rationale
- S3 Inventory is intended to audit S3 object metadata at scale. Given a shared data lake has different consumer permissions, the relevant choice must give multiple applications distinct policies without growing one complex bucket policy. The scenario calls for another native capability.
- Amazon Macie discovers and classifies sensitive data in Amazon S3 using managed data identifiers and findings. Because a shared data lake has different consumer permissions, the team must give multiple applications distinct policies without growing one complex bucket policy. This would address the wrong decision point.
- S3 Access Points fits situations that require teams to separate application-specific access policies to a shared bucket. Case: a shared data lake has different consumer permissions; required action: give multiple applications distinct policies without growing one complex bucket policy. That is the direct functional match.
- S3 Block Public Access addresses the need to prevent accidental public exposure of S3 data. Decisive fact: a shared data lake has different consumer permissions; requested action: give multiple applications distinct policies without growing one complex bucket policy. This does not deliver the requested outcome.
Question 16
The team needs to generate a recurring object-level report for encryption and replication compliance analysis, but millions of objects must be assessed without listing them interactively. Which option is best? Choose ONE.
- S3 Inventory
- S3 Block Public Access
- S3 Access Points
- Amazon Macie
Correct Answer(s)
A
Rationale
- S3 Inventory addresses the need to audit S3 object metadata at scale. Requirement: generate a recurring object-level report for encryption and replication compliance analysis; key constraint: millions of objects must be assessed without listing them interactively. This is the precise capability required.
- S3 Block Public Access primarily provides account- or bucket-level controls that override public ACL and policy exposure paths. Here, millions of objects must be assessed without listing them interactively; design must generate a recurring object-level report for encryption and replication compliance analysis. Its primary role differs from this need.
- S3 Access Points can help a team separate application-specific access policies to a shared bucket. Limiting condition: millions of objects must be assessed without listing them interactively; solution must generate a recurring object-level report for encryption and replication compliance analysis. This solves a neighboring problem instead.
- Amazon Macie supports teams that need to identify sensitive S3 data for governance decisions. Because millions of objects must be assessed without listing them interactively, the team must generate a recurring object-level report for encryption and replication compliance analysis. The scenario calls for another native capability.
Question 17
Given that the table needs time-based recovery without relying on manual snapshots, which approach most directly lets the team restore a table to the moment immediately before a bad bulk update? Choose ONE.
- EFS replication
- RDS automated backups and point-in-time recovery
- EC2 Recycle Bin
- DynamoDB point-in-time recovery
Correct Answer(s)
D
Rationale
- EFS replication can help a team maintain an asynchronously replicated EFS copy. Case: the table needs time-based recovery without relying on manual snapshots; required action: restore a table to the moment immediately before a bad bulk update. This solves a neighboring problem instead.
- RDS automated backups and point-in-time recovery is designed to recover an RDS database to a precise earlier time. Because the table needs time-based recovery without relying on manual snapshots, the team must restore a table to the moment immediately before a bad bulk update. This would address the wrong decision point.
- EC2 Recycle Bin fits situations that require teams to recover accidentally deleted snapshots or AMIs. The case hinges on the table needs time-based recovery without relying on manual snapshots. The team must restore a table to the moment immediately before a bad bulk update. Its primary role differs from this need.
- DynamoDB point-in-time recovery is intended to recover a DynamoDB table to an earlier point after accidental writes. Decisive fact: the table needs time-based recovery without relying on manual snapshots; requested action: restore a table to the moment immediately before a bad bulk update. This is the precise capability required.
Question 18
Which option best supports this requirement: restore a relational database to just before an accidental DELETE statement? Constraint: the recovery target is a specific time within the configured retention period. Choose ONE.
- EFS replication
- DynamoDB point-in-time recovery
- RDS automated backups and point-in-time recovery
- EC2 Recycle Bin
Correct Answer(s)
C
Rationale
- EFS replication fits situations that require teams to maintain an asynchronously replicated EFS copy. Here, the recovery target is a specific time within the configured retention period; design must restore a relational database to just before an accidental DELETE statement. Its primary role differs from this need.
- DynamoDB point-in-time recovery continuously backs up a DynamoDB table so it can be restored to a selected second within the retention window. Decisive fact: the recovery target is a specific time within the configured retention period; requested action: restore a relational database to just before an accidental DELETE statement. That mismatch makes it a weaker choice.
- RDS automated backups and point-in-time recovery primarily retain transaction logs and backups that support restoring a DB instance to a selected time within the backup window. Given the recovery target is a specific time within the configured retention period, the relevant choice must restore a relational database to just before an accidental DELETE statement. This addresses the decision at the right layer.
- EC2 Recycle Bin addresses the need to recover accidentally deleted snapshots or AMIs. Limiting condition: the recovery target is a specific time within the configured retention period; solution must restore a relational database to just before an accidental DELETE statement. This solves a neighboring problem instead.
Question 19
The workload uses EFS and needs ongoing regional replication. What should the team do to keep a managed copy of shared Linux file data in another Region? Choose ONE.
- EFS replication
- EC2 Recycle Bin
- RDS automated backups and point-in-time recovery
- DynamoDB point-in-time recovery
Correct Answer(s)
A
Rationale
- EFS replication supports teams that need to maintain an asynchronously replicated EFS copy. Decisive fact: the workload uses EFS and needs ongoing regional replication; requested action: keep a managed copy of shared Linux file data in another Region. This is the precise capability required.
- EC2 Recycle Bin can help a team recover accidentally deleted snapshots or AMIs. The case hinges on the workload uses EFS and needs ongoing regional replication. The team must keep a managed copy of shared Linux file data in another Region. That capability is not the required control.
- RDS automated backups and point-in-time recovery is designed to recover an RDS database to a precise earlier time. Requirement: keep a managed copy of shared Linux file data in another Region; key constraint: the workload uses EFS and needs ongoing regional replication. That mismatch makes it a weaker choice.
- DynamoDB point-in-time recovery primarily continuously backs up a DynamoDB table so it can be restored to a selected second within the retention window. Because the workload uses EFS and needs ongoing regional replication, the team must keep a managed copy of shared Linux file data in another Region. This would address the wrong decision point.
Question 20
The team needs to allow recovery of an EBS snapshot that an operator accidentally deletes, but the protection must apply after deletion for a defined retention period. Which option is best? Choose ONE.
- EC2 Recycle Bin
- DynamoDB point-in-time recovery
- RDS automated backups and point-in-time recovery
- EFS replication
Correct Answer(s)
A
Rationale
- EC2 Recycle Bin is intended to recover accidentally deleted snapshots or AMIs. Limiting condition: the protection must apply after deletion for a defined retention period; solution must allow recovery of an EBS snapshot that an operator accidentally deletes. This aligns cleanly with the requirement.
- DynamoDB point-in-time recovery is designed to recover a DynamoDB table to an earlier point after accidental writes. Decisive fact: the protection must apply after deletion for a defined retention period; requested action: allow recovery of an EBS snapshot that an operator accidentally deletes. That mismatch makes it a weaker choice.
- RDS automated backups and point-in-time recovery fits situations that require teams to recover an RDS database to a precise earlier time. Given the protection must apply after deletion for a defined retention period, the relevant choice must allow recovery of an EBS snapshot that an operator accidentally deletes. This would address the wrong decision point.
- EFS replication continuously replicates an Amazon EFS file system to another file system in the same or another Region. Case: the protection must apply after deletion for a defined retention period; required action: allow recovery of an EBS snapshot that an operator accidentally deletes. That leaves the key constraint unresolved.