What feature does S3 Object Lock provide to prevent data deletion?

Disable ads (and more) with a premium pass for a one time $4.99 payment

Prepare for the Amazon Web Services (CISN 74A) Security Test with our interactive quizzes. Use multiple choice questions with detailed hints and explanations to ace your exam.

S3 Object Lock provides a critical feature for protecting data integrity by enabling users to enforce retention periods and legal holds on their objects. Retention periods prevent the deletion of objects during a specified timeframe, ensuring that the data remains immutable and cannot be altered or removed until the designated time has elapsed. This is particularly important in compliance-heavy industries where regulatory requirements dictate that certain records be retained unaltered for specified periods.

Legal holds, on the other hand, are a mechanism that can be applied independently of retention periods to prevent deletion. This feature allows organizations to ensure that certain objects are preserved for legal investigations or audit purposes, regardless of any predefined retention schedule.

The other options, while useful features of Amazon S3, do not directly provide mechanisms for preventing object deletion. Bucket replication and cross-region replication focus on data redundancy and availability across different locations, but they do not enforce retention rules. Versioning allows for the preservation of different versions of objects but does not inherently protect against deletion of the current object since it can still be removed and replaced with a different version. Hence, the primary focus of S3 Object Lock is accurately captured through retention periods and legal holds, which serve to create an environment of data immutability and compliance.