Lesson 120 · AWS Learning Path

AWS 120: Secure, version, lifecycle, replicate, and restore S3 data

· Published · 18 min read

An EC2 instance connects to persistent EBS volumes on one side and fast temporary host-local instance-store disks on the other

The real problem

A team recognizes the name Secure, version, lifecycle, replicate, and restore S3 data but has not connected the feature to a real requirement, identity boundary, network or data path, failure mode, price dimension, and cleanup owner. A plausible configuration could still fail the workload.

Final outcome

The learner will produce a requirement-led artifact for Secure, version, lifecycle, replicate, and restore S3 data, inspect the matching AWS control plane in the Management Console, run a matching CloudShell or AWS CLI query, interpret the output, diagnose one failure, defend one architecture choice, and prove cleanup or approved retained state.

The practical outcome is not a command transcript. It must show what was expected, what happened, what the result proves, what it does not prove, and which evidence would change the decision.

Learning objectives

By the end of this lesson, the learner can:

  • explain exact lab scope;
  • explain lifecycle configuration;
  • explain replication role;
  • explain recovery sequence;
  • explain asynchronous evidence;
  • connect control-plane state to the real data, network, identity, or application behavior;
  • identify cost and cleanup ownership before any optional mutation;
  • troubleshoot from evidence without opening broad access or adding broad permissions.

Relationship model

Requirement
   |
   v
Identity and policy -> AWS configuration -> network or data path -> workload behavior
        |                    |                      |                    |
        +--------------------+----------------------+--------------------+
                                      |
                                      v
                         monitoring, cost, recovery, cleanup

Use this model to separate an AWS object that exists from a result that actually works. Every arrow is a verification boundary.

Prerequisites, permissions, Region, and safety

  • Learning baseline: This sequence assumes practical Linux knowledge but no prior cloud-computing or AWS knowledge. Cloud, networking, security, data, automation, and architecture concepts must come from completed earlier lessons. If a prerequisite checkpoint is incomplete, return to its linked lesson before continuing.
  • Confirm a non-root caller with aws sts get-caller-identity and keep the account number private.
  • Use ap-south-1 unless this lesson explicitly names a second Region.
  • Confirm the intended profile and Region with aws configure list before interpreting an empty result.
  • The live track requires only the named create, describe, tag, test, and delete actions for the lab resources. If the personal-account identity lacks them, use the instructor evidence track. Do not attach AdministratorAccess as a shortcut.
  • The live track can incur small charges or consume credits. Record current prices and use immediate cleanup. Never promise that a personal account is free.
  • Never publish account IDs, public addresses, ARNs containing private account data, session IDs, presigned URLs, object data, credentials, or KMS material.
  • Do not use root, world-open SSH or RDP, disabled TLS verification, unowned resources, or irreversible retention controls in a training exercise.

Core model

ConceptWhat the learner must understand
Exact lab scopeCreate two uniquely named general purpose buckets: source in ap-south-1 and replica in ap-southeast-1. Enable versioning, all four Block Public Access settings, bucket owner enforced, and explicit SSE-S3 default encryption.
Lifecycle configurationConfigure incomplete multipart abort after 7 days plus noncurrent-version transition and expiration using reviewed durations. The lab verifies configuration and does not wait for asynchronous lifecycle execution.
Replication roleCreate one exact service role and least-privilege policy for S3 replication. The source rule covers documents/ and enables delete-marker replication for the controlled exercise.
Recovery sequenceUpload policy.txt version 1 and version 2, record source and replica version evidence, create a source delete marker, verify behavior, remove the source delete marker to restore the current object, and verify the recovered data.
Asynchronous evidenceWait for or poll replication status with a bounded timeout. A source PUT success does not prove the replica arrived, and a destination object does not prove every version or delete action.
Version-aware cleanupDisable and delete replication configuration, delete every source and destination object version and delete marker, delete buckets, then delete the role policy and role. Ordinary recursive deletion is insufficient.

How it works

The lab joins identity, policy, encryption, versioning, lifecycle, replication, recovery, Region, cost, and cleanup. The learner must preserve exact version IDs privately and prove both the happy path and an anonymous or unauthorized denial without exposing a bucket publicly.

Read the result in layers:

  1. Scope: account, Region, VPC, bucket, AZ, endpoint, principal, object version, or resource ARN.
  2. Control plane: the requested configuration exists and reached an expected state.
  3. Behavior: the request, connection, health check, replication, restore, or application result meets the requirement.
  4. Operations: monitoring, failure owner, cost, retention, rollback, and cleanup are known.

Control-plane success is necessary but not sufficient. A resource can be available while policy, routing, DNS, health, data, or application behavior remains wrong.

Architecture decision table

RequirementPreferred directionWhy
No permission for cross-Region or IAM role creationUse the instructor evidence trackThe practical outcome remains assessable without broad personal-account permissions.
Need simple training encryptionSSE-S3It avoids KMS policy and request-cost complexity while keeping server-side encryption explicit.
Need production customer-managed keysAdd a separately reviewed SSE-KMS replication designSource, replica, role, key policy, and Region-specific keys must align.
Cleanup query still finds a versionStop bucket deletion and reconcile version IDsDo not hide leftovers by suspending versioning or deleting only current keys.

Professional questions normally contain several valid services. State the requirement that selects one option, why the nearest alternative fails it, and what changed requirement would reverse the choice.

AWS Management Console guided practice

Before opening a service page, write the expected account, Region, starting state, and evidence. Do not choose Create, Save, Purchase, Lock, or Delete unless the lesson explicitly authorizes the live track.

  1. Create the source bucket in ap-south-1 and replica bucket in ap-southeast-1 with globally unique approved names, bucket owner enforced, all BPA settings on, versioning, and SSE-S3.
  2. Configure source lifecycle and one-way documents/ replication with the exact service role. Upload version 1 and version 2, wait for replica status, then create and recover from a delete marker.
  3. Delete the replication rule, empty both buckets with Show versions so every version and marker is selected, delete buckets, remove the role, and verify absence plus delayed billing review.

For each step, capture the field name and value in text. A screenshot may support the record but does not replace the explanation. Console labels can evolve, so use the service search and current documentation if a navigation label differs.

CloudShell and AWS CLI practice

CloudShell is the default browser-based command environment taught in AWS 028. AWS 029 and AWS 030 cover local CLI installation and authentication. This lesson therefore does not assume that an unconfigured local shell is ready.

Start every session with:

set -euo pipefail
export AWS_DEFAULT_REGION="ap-south-1"
aws sts get-caller-identity --query Arn --output text
aws configure list

Redact the account portion of the ARN before sharing. Then perform the topic query:

Verify security, versioning, lifecycle, replication, versions, delete markers, recovery content, and final absence in both Regions.

NW_SOURCE_BUCKET="replace-with-owned-source-bucket-name"
NW_REPLICA_BUCKET="replace-with-owned-replica-bucket-name"
aws s3api get-bucket-versioning --bucket "$NW_SOURCE_BUCKET"
aws s3api get-public-access-block --bucket "$NW_SOURCE_BUCKET"
aws s3api get-bucket-lifecycle-configuration --bucket "$NW_SOURCE_BUCKET"
aws s3api get-bucket-replication --bucket "$NW_SOURCE_BUCKET"
aws s3api list-object-versions --bucket "$NW_SOURCE_BUCKET" --prefix documents/
aws s3api list-object-versions --bucket "$NW_REPLICA_BUCKET" --prefix documents/ --region ap-southeast-1

Expected interpretation:

Before recovery, show two source data versions and a current delete marker plus the configured replica evidence. After removing the source delete marker, GET returns version 2 content. After cleanup, list-buckets no longer includes either exact name and the project role is absent.

Replace every replace-with-... sample value before running its command, and use only an explicitly owned resource. Explain each option first. These queries are read-only; a successful response does not authorize a later create or delete operation.

Practical work

Execute one of two tracks. The live T1 track requires owner approval, unique suffix, current source and destination price evidence, a 120-minute timer, exact JSON artifacts, and p06-resource-ledger.md. The required alternative uses supplied Console, CLI, version, and replication records. In either track submit security configuration, two source versions, replica proof, delete-marker failure, restored version 2 content, one denied anonymous request, version-aware cleanup, role cleanup, and a scheduled cost follow-up.

Exact S3 live-lab runbook

The bucket suffix must be globally unique but must not contain a full account ID, email address, or other personal data.

export AWS_DEFAULT_REGION="ap-south-1"
NW_SOURCE_REGION="ap-south-1"
NW_REPLICA_REGION="ap-southeast-1"
NW_SUFFIX="$(date -u +%Y%m%d%H%M%S)-${RANDOM}"
NW_SOURCE_BUCKET="nw-p06-source-${NW_SUFFIX}"
NW_REPLICA_BUCKET="nw-p06-replica-${NW_SUFFIX}"
NW_ROLE_NAME="nw-p06-repl-${NW_SUFFIX}"

printf 'Source: %s\nReplica: %s\n' "$NW_SOURCE_BUCKET" "$NW_REPLICA_BUCKET"

Record the names privately in p06-resource-ledger.md before creation.

1. Create and secure both buckets

aws s3api create-bucket --bucket "$NW_SOURCE_BUCKET" --region "$NW_SOURCE_REGION" --create-bucket-configuration LocationConstraint="$NW_SOURCE_REGION"
aws s3api create-bucket --bucket "$NW_REPLICA_BUCKET" --region "$NW_REPLICA_REGION" --create-bucket-configuration LocationConstraint="$NW_REPLICA_REGION"

for NW_PAIR in "$NW_SOURCE_BUCKET:$NW_SOURCE_REGION" "$NW_REPLICA_BUCKET:$NW_REPLICA_REGION"; do
  NW_BUCKET="${NW_PAIR%%:*}"
  NW_REGION="${NW_PAIR##*:}"
  aws s3api put-public-access-block --bucket "$NW_BUCKET" --region "$NW_REGION" --public-access-block-configuration BlockPublicAcls=true,IgnorePublicAcls=true,BlockPublicPolicy=true,RestrictPublicBuckets=true
  aws s3api put-bucket-ownership-controls --bucket "$NW_BUCKET" --region "$NW_REGION" --ownership-controls 'Rules=[{ObjectOwnership=BucketOwnerEnforced}]'
  aws s3api put-bucket-versioning --bucket "$NW_BUCKET" --region "$NW_REGION" --versioning-configuration Status=Enabled
  aws s3api put-bucket-encryption --bucket "$NW_BUCKET" --region "$NW_REGION" --server-side-encryption-configuration 'Rules=[{ApplyServerSideEncryptionByDefault={SSEAlgorithm=AES256},BucketKeyEnabled=false}]'
  aws s3api put-bucket-tagging --bucket "$NW_BUCKET" --region "$NW_REGION" --tagging 'TagSet=[{Key=Project,Value=NitWings-P06},{Key=DeleteAfterLesson,Value=AWS120}]'
  cat > nw-p06-tls-policy.json <<JSON
{
  "Version": "2012-10-17",
  "Statement": [{
    "Sid": "DenyInsecureTransport",
    "Effect": "Deny",
    "Principal": "*",
    "Action": "s3:*",
    "Resource": ["arn:aws:s3:::${NW_BUCKET}", "arn:aws:s3:::${NW_BUCKET}/*"],
    "Condition": {"Bool": {"aws:SecureTransport": "false"}}
  }]
}
JSON
  aws s3api put-bucket-policy --bucket "$NW_BUCKET" --region "$NW_REGION" --policy file://nw-p06-tls-policy.json
done

Verify all four BPA booleans, versioning Enabled, ownership BucketOwnerEnforced, and encryption AES256 on both buckets before continuing.

2. Add the source lifecycle rule

Create nw-p06-lifecycle.json:

{
  "Rules": [
    {
      "ID": "nw-p06-version-cost-control",
      "Status": "Enabled",
      "Filter": {"Prefix": ""},
      "NoncurrentVersionTransitions": [{"NoncurrentDays": 30, "StorageClass": "STANDARD_IA"}],
      "NoncurrentVersionExpiration": {"NoncurrentDays": 90},
      "AbortIncompleteMultipartUpload": {"DaysAfterInitiation": 7}
    }
  ]
}

Apply and read it back:

aws s3api put-bucket-lifecycle-configuration --bucket "$NW_SOURCE_BUCKET" --region "$NW_SOURCE_REGION" --lifecycle-configuration file://nw-p06-lifecycle.json
aws s3api get-bucket-lifecycle-configuration --bucket "$NW_SOURCE_BUCKET" --region "$NW_SOURCE_REGION"

This proves configuration only. The lab does not wait 30, 90, or 7 days. The tiny sample objects might also be below the current default minimum size for lifecycle transition, which is another reason not to claim that a transition was tested.

3. Create the replication role and least-privilege policy

Create nw-p06-replication-trust.json:

{
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Principal": {"Service": "s3.amazonaws.com"},
    "Action": "sts:AssumeRole"
  }]
}

Create nw-p06-replication-policy.json after replacing the two bucket placeholders with the current shell values:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "ReadSourceConfiguration",
      "Effect": "Allow",
      "Action": ["s3:GetReplicationConfiguration", "s3:ListBucket"],
      "Resource": "arn:aws:s3:::SOURCE_BUCKET"
    },
    {
      "Sid": "ReadSourceVersions",
      "Effect": "Allow",
      "Action": ["s3:GetObjectVersionForReplication", "s3:GetObjectVersionAcl", "s3:GetObjectVersionTagging"],
      "Resource": "arn:aws:s3:::SOURCE_BUCKET/documents/*"
    },
    {
      "Sid": "WriteReplicaVersions",
      "Effect": "Allow",
      "Action": ["s3:ReplicateObject", "s3:ReplicateDelete", "s3:ReplicateTags"],
      "Resource": "arn:aws:s3:::REPLICA_BUCKET/documents/*"
    }
  ]
}

Use sed only on the local lab JSON, inspect the final file, then create the role:

sed -i "s/SOURCE_BUCKET/${NW_SOURCE_BUCKET}/g; s/REPLICA_BUCKET/${NW_REPLICA_BUCKET}/g" nw-p06-replication-policy.json
aws iam create-role --role-name "$NW_ROLE_NAME" --assume-role-policy-document file://nw-p06-replication-trust.json --tags Key=Project,Value=NitWings-P06 Key=DeleteAfterLesson,Value=AWS120
aws iam put-role-policy --role-name "$NW_ROLE_NAME" --policy-name nw-p06-s3-replication --policy-document file://nw-p06-replication-policy.json
NW_ROLE_ARN="$(aws iam get-role --role-name "$NW_ROLE_NAME" --query Role.Arn --output text)"

Create nw-p06-replication.json:

{
  "Role": "ROLE_ARN",
  "Rules": [
    {
      "ID": "nw-p06-documents-to-singapore",
      "Priority": 1,
      "Status": "Enabled",
      "DeleteMarkerReplication": {"Status": "Enabled"},
      "Filter": {"Prefix": "documents/"},
      "Destination": {
        "Bucket": "arn:aws:s3:::REPLICA_BUCKET",
        "StorageClass": "STANDARD"
      }
    }
  ]
}
sed -i "s|ROLE_ARN|${NW_ROLE_ARN}|g; s/REPLICA_BUCKET/${NW_REPLICA_BUCKET}/g" nw-p06-replication.json
NW_REPLICATION_CONFIGURED="false"
for NW_ATTEMPT in $(seq 1 6); do
  if aws s3api put-bucket-replication --bucket "$NW_SOURCE_BUCKET" --region "$NW_SOURCE_REGION" --replication-configuration file://nw-p06-replication.json; then
    NW_REPLICATION_CONFIGURED="true"
    break
  fi
  echo "Replication role might still be propagating; retry ${NW_ATTEMPT}/6" >&2
  sleep 10
done
if [ "$NW_REPLICATION_CONFIGURED" != "true" ]; then
  echo "Stop: replication configuration was not accepted; preserve evidence and run reviewed cleanup" >&2
  exit 1
fi
aws s3api get-bucket-replication --bucket "$NW_SOURCE_BUCKET" --region "$NW_SOURCE_REGION"

4. Upload two versions and verify replication

printf 'NitWings P06 policy version 1\n' > policy.txt
NW_V1="$(aws s3api put-object --bucket "$NW_SOURCE_BUCKET" --key documents/policy.txt --body policy.txt --server-side-encryption AES256 --tagging 'Project=NitWings-P06&DataClass=Training' --query VersionId --output text)"

printf 'NitWings P06 policy version 2\n' > policy.txt
NW_V2="$(aws s3api put-object --bucket "$NW_SOURCE_BUCKET" --key documents/policy.txt --body policy.txt --server-side-encryption AES256 --tagging 'Project=NitWings-P06&DataClass=Training' --query VersionId --output text)"
printf 'V1=%s\nV2=%s\n' "$NW_V1" "$NW_V2"

Poll for no more than five minutes. Stop earlier when both source versions show COMPLETED:

for NW_ATTEMPT in $(seq 1 30); do
  NW_V1_STATUS="$(aws s3api head-object --bucket "$NW_SOURCE_BUCKET" --key documents/policy.txt --version-id "$NW_V1" --query ReplicationStatus --output text)"
  NW_V2_STATUS="$(aws s3api head-object --bucket "$NW_SOURCE_BUCKET" --key documents/policy.txt --version-id "$NW_V2" --query ReplicationStatus --output text)"
  printf 'attempt=%s v1=%s v2=%s\n' "$NW_ATTEMPT" "$NW_V1_STATUS" "$NW_V2_STATUS"
  if [ "$NW_V1_STATUS" = "COMPLETED" ] && [ "$NW_V2_STATUS" = "COMPLETED" ]; then break; fi
  sleep 10
done

aws s3api list-object-versions --bucket "$NW_REPLICA_BUCKET" --region "$NW_REPLICA_REGION" --prefix documents/policy.txt --output table

if [ "$NW_V1_STATUS" != "COMPLETED" ] || [ "$NW_V2_STATUS" != "COMPLETED" ]; then
  echo "Stop: replication did not complete inside the five-minute evidence window" >&2
  exit 1
fi

If either status remains FAILED or PENDING, preserve the role, bucket, and replication evidence. Diagnose permission and configuration before retrying another PUT.

5. Prove denial, delete marker, and recovery

An anonymous request must fail. A 403 result is expected:

curl --silent --show-error --output /dev/null --write-out '%{http_code}\n' "https://${NW_SOURCE_BUCKET}.s3.${NW_SOURCE_REGION}.amazonaws.com/documents/policy.txt"

Create a delete marker without naming a version:

NW_DELETE_MARKER_ID="$(aws s3api delete-object --bucket "$NW_SOURCE_BUCKET" --key documents/policy.txt --query VersionId --output text)"
aws s3api list-object-versions --bucket "$NW_SOURCE_BUCKET" --prefix documents/policy.txt --output table

if aws s3api get-object --bucket "$NW_SOURCE_BUCKET" --key documents/policy.txt deleted-object.txt; then
  echo 'Unexpected: current GET succeeded while delete marker should be current' >&2
  exit 1
else
  echo 'Expected: current GET failed because the delete marker is current'
fi

Recover by deleting that exact delete-marker version, not a data version:

aws s3api delete-object --bucket "$NW_SOURCE_BUCKET" --key documents/policy.txt --version-id "$NW_DELETE_MARKER_ID"
aws s3api get-object --bucket "$NW_SOURCE_BUCKET" --key documents/policy.txt restored-policy.txt
grep -F 'version 2' restored-policy.txt

This restores the source current view. Deleting a specific source version, including that delete marker, is not replicated as a specific-version deletion. The replica can therefore retain its replicated delete marker until an explicit destination recovery or the version-aware cleanup.

6. Version-aware cleanup

Delete replication configuration first. Empty both versioned buckets by exact version ID. The lab intentionally creates fewer than 1,000 versions, so one delete-objects request per bucket is sufficient. A production cleanup must paginate list-object-versions, submit batches of at most 1,000 identifiers, inventory multipart uploads, account for in-flight replication, and repeat until a stable empty state is proven. Never reuse this bounded lab loop as an unreviewed production deletion script.

aws s3api delete-bucket-replication --bucket "$NW_SOURCE_BUCKET" --region "$NW_SOURCE_REGION"

for NW_PAIR in "$NW_SOURCE_BUCKET:$NW_SOURCE_REGION" "$NW_REPLICA_BUCKET:$NW_REPLICA_REGION"; do
  NW_BUCKET="${NW_PAIR%%:*}"
  NW_REGION="${NW_PAIR##*:}"
  aws s3api list-object-versions --bucket "$NW_BUCKET" --region "$NW_REGION" --output json \
    | jq '{Objects: (((.Versions // []) + (.DeleteMarkers // [])) | map({Key: .Key, VersionId: .VersionId})), Quiet: true}' \
    > "delete-${NW_REGION}.json"
  jq . "delete-${NW_REGION}.json"
  if jq -e '.Objects | length > 0' "delete-${NW_REGION}.json" >/dev/null; then
    aws s3api delete-objects --bucket "$NW_BUCKET" --region "$NW_REGION" --delete "file://delete-${NW_REGION}.json"
  fi
  NW_REMAINING="$(aws s3api list-object-versions --bucket "$NW_BUCKET" --region "$NW_REGION" --output json | jq '((.Versions // []) | length) + ((.DeleteMarkers // []) | length)')"
  printf 'bucket=%s remaining_versions_and_markers=%s\n' "$NW_BUCKET" "$NW_REMAINING"
  if [ "$NW_REMAINING" != "0" ]; then
    echo "Stop: bucket is not empty; inspect in-flight replication and version inventory" >&2
    exit 1
  fi
  NW_MULTIPART_COUNT="$(aws s3api list-multipart-uploads --bucket "$NW_BUCKET" --region "$NW_REGION" --query 'length(Uploads || `[]`)' --output text)"
  if [ "$NW_MULTIPART_COUNT" != "0" ]; then
    echo "Stop: incomplete multipart uploads require explicit inventory and abort" >&2
    exit 1
  fi
  aws s3api delete-bucket --bucket "$NW_BUCKET" --region "$NW_REGION"
done

aws iam delete-role-policy --role-name "$NW_ROLE_NAME" --policy-name nw-p06-s3-replication
aws iam delete-role --role-name "$NW_ROLE_NAME"
rm -f policy.txt restored-policy.txt deleted-object.txt nw-p06-tls-policy.json nw-p06-lifecycle.json nw-p06-replication-trust.json nw-p06-replication-policy.json nw-p06-replication.json delete-ap-south-1.json delete-ap-southeast-1.json

The local rm line removes only the explicitly named CloudShell lab artifacts. It does not prove AWS cleanup. Re-run bucket and IAM queries, inspect both Regions, and schedule the billing review.

The evidence package must contain:

  • the problem and final requirement in the learner's own words;
  • caller type and Region with private identifiers redacted;
  • exact planned values, ownership, and cost class;
  • one Console observation and matching CLI or API evidence;
  • one behavior result or supplied data-plane record;
  • one denied, failed, or counterexample result and evidence-led diagnosis;
  • one architecture choice plus the rejected alternative;
  • cleanup proof or explicit retained-state owner, expiry, and next lesson.

Verification standard

Use expected state before observed state. Record timestamps in UTC and preserve the original failure before changing anything. A passing submission answers all four questions:

  1. What exact requirement was tested?
  2. Which evidence proves the AWS configuration?
  3. Which evidence proves the workload behavior?
  4. What remains unproven or requires later monitoring?

If AWS returns no rows, verify account, Region, permission, filters, pagination, resource type, and deletion state before concluding that nothing exists.

Common failures and troubleshooting

SymptomEvidence firstLikely boundarySmallest safe response
object appears missingcaller, Region, filters, pagination, tagsscope or read permissionalign scope before creating a duplicate
state remains pending or unavailableservice state, events, dependencies, quotasdependency or capacitycorrect the named dependency and wait with a bound
AccessDeniedprincipal, action, resource, explicit-deny contextidentity, resource, endpoint, organization, or KMS policychange only the proven policy layer
configuration exists but behavior failsroute, DNS, security, listener, health, logs, object versiondata path or applicationtest the next boundary and change one control
bill is higher than expectedhours, bytes, requests, AZs, addresses, retentioncost model or retained resourcestop optional work and reconcile the ledger
cleanup is blockeddependency inventory and owning servicedeletion order or immutable stateremove owned dependants in reviewed reverse order

Do not troubleshoot by attaching administrator access, opening administration ports to the internet, disabling encryption, retrying uncontrolled creation, deleting unknown resources, or weakening retention.

Cost, cleanup, and retained state

No P06 bucket, version, delete marker, replication rule, or IAM role remains after the lesson.

Cleanup evidence requires terminal state and an after-inventory. Search related ENIs, public IPv4 addresses, EBS volumes and snapshots, load balancers, target groups, Auto Scaling instances, endpoints, logs, S3 versions and delete markers, backup recovery points, and global IAM roles when they apply. Billing data can lag, so schedule a later review.

Architecture and certification decisions

  • Certification coverage: SAA-C03; SOA-C03; SAP-C02; DOP-C02.
  • Exam mapping: SAA D1-D4.
  • Explain service scope, failure boundary, consistency, recovery, security, operations, and price rather than matching a keyword.
  • Treat availability and durability, encryption and authorization, routing and filtering, health and lifecycle, backup and replication, and discount and capacity as separate concepts.
  • Do not reproduce protected certification questions.

Knowledge check

  1. Why must both buckets have versioning?

Expected direction: It is a replication prerequisite and supplies version-level recovery.

  1. Does the lifecycle rule execute during the short lab?

Expected direction: Not necessarily. Validate the rule configuration and use explicit cleanup.

  1. How is a simple delete recovered?

Expected direction: Delete the current delete marker by its version ID to reveal the prior data version.

  1. Why is recursive bucket deletion insufficient?

Expected direction: Versioned buckets retain noncurrent versions and delete markers.

Completion gate and assessment

AreaPointsPassing evidence
Requirement and model15Correct scope, terminology, and final outcome
Console evidence15Current path and interpreted fields
CLI or API evidence15Scoped command, expected result, and limitations
Behavior or decision exercise20Reproducible result or defensible architecture reasoning
Troubleshooting15Original symptom, hypothesis, one change, retest, rollback
Security and cost10Least privilege, data protection, current price dimensions
Cleanup and handoff10Terminal-state proof or approved retained-state record

Pass at 80 out of 100 with no critical safety failure. A missing practical artifact, unexplained output, unsafe access, destructive action outside the owned scope, unplanned billed resource, or false cleanup claim requires remediation and a changed retest.

Official sources

Advertisement