AWS 120: Secure, version, lifecycle, replicate, and restore S3 data
The real problem
A team recognizes the name Secure, version, lifecycle, replicate, and restore S3 data but has not connected the feature to a real requirement, identity boundary, network or data path, failure mode, price dimension, and cleanup owner. A plausible configuration could still fail the workload.
Final outcome
The learner will produce a requirement-led artifact for Secure, version, lifecycle, replicate, and restore S3 data, inspect the matching AWS control plane in the Management Console, run a matching CloudShell or AWS CLI query, interpret the output, diagnose one failure, defend one architecture choice, and prove cleanup or approved retained state.
The practical outcome is not a command transcript. It must show what was expected, what happened, what the result proves, what it does not prove, and which evidence would change the decision.
Learning objectives
By the end of this lesson, the learner can:
- explain exact lab scope;
- explain lifecycle configuration;
- explain replication role;
- explain recovery sequence;
- explain asynchronous evidence;
- connect control-plane state to the real data, network, identity, or application behavior;
- identify cost and cleanup ownership before any optional mutation;
- troubleshoot from evidence without opening broad access or adding broad permissions.
Relationship model
Requirement
|
v
Identity and policy -> AWS configuration -> network or data path -> workload behavior
| | | |
+--------------------+----------------------+--------------------+
|
v
monitoring, cost, recovery, cleanup
Use this model to separate an AWS object that exists from a result that actually works. Every arrow is a verification boundary.
Prerequisites, permissions, Region, and safety
- Learning baseline: This sequence assumes practical Linux knowledge but no prior cloud-computing or AWS knowledge. Cloud, networking, security, data, automation, and architecture concepts must come from completed earlier lessons. If a prerequisite checkpoint is incomplete, return to its linked lesson before continuing.
- Confirm a non-root caller with
aws sts get-caller-identityand keep the account number private. - Use
ap-south-1unless this lesson explicitly names a second Region. - Confirm the intended profile and Region with
aws configure listbefore interpreting an empty result. - The live track requires only the named create, describe, tag, test, and delete actions for the lab resources. If the personal-account identity lacks them, use the instructor evidence track. Do not attach AdministratorAccess as a shortcut.
- The live track can incur small charges or consume credits. Record current prices and use immediate cleanup. Never promise that a personal account is free.
- Never publish account IDs, public addresses, ARNs containing private account data, session IDs, presigned URLs, object data, credentials, or KMS material.
- Do not use root, world-open SSH or RDP, disabled TLS verification, unowned resources, or irreversible retention controls in a training exercise.
Core model
| Concept | What the learner must understand |
|---|---|
| Exact lab scope | Create two uniquely named general purpose buckets: source in ap-south-1 and replica in ap-southeast-1. Enable versioning, all four Block Public Access settings, bucket owner enforced, and explicit SSE-S3 default encryption. |
| Lifecycle configuration | Configure incomplete multipart abort after 7 days plus noncurrent-version transition and expiration using reviewed durations. The lab verifies configuration and does not wait for asynchronous lifecycle execution. |
| Replication role | Create one exact service role and least-privilege policy for S3 replication. The source rule covers documents/ and enables delete-marker replication for the controlled exercise. |
| Recovery sequence | Upload policy.txt version 1 and version 2, record source and replica version evidence, create a source delete marker, verify behavior, remove the source delete marker to restore the current object, and verify the recovered data. |
| Asynchronous evidence | Wait for or poll replication status with a bounded timeout. A source PUT success does not prove the replica arrived, and a destination object does not prove every version or delete action. |
| Version-aware cleanup | Disable and delete replication configuration, delete every source and destination object version and delete marker, delete buckets, then delete the role policy and role. Ordinary recursive deletion is insufficient. |
How it works
The lab joins identity, policy, encryption, versioning, lifecycle, replication, recovery, Region, cost, and cleanup. The learner must preserve exact version IDs privately and prove both the happy path and an anonymous or unauthorized denial without exposing a bucket publicly.
Read the result in layers:
- Scope: account, Region, VPC, bucket, AZ, endpoint, principal, object version, or resource ARN.
- Control plane: the requested configuration exists and reached an expected state.
- Behavior: the request, connection, health check, replication, restore, or application result meets the requirement.
- Operations: monitoring, failure owner, cost, retention, rollback, and cleanup are known.
Control-plane success is necessary but not sufficient. A resource can be available while policy, routing, DNS, health, data, or application behavior remains wrong.
Architecture decision table
| Requirement | Preferred direction | Why |
|---|---|---|
| No permission for cross-Region or IAM role creation | Use the instructor evidence track | The practical outcome remains assessable without broad personal-account permissions. |
| Need simple training encryption | SSE-S3 | It avoids KMS policy and request-cost complexity while keeping server-side encryption explicit. |
| Need production customer-managed keys | Add a separately reviewed SSE-KMS replication design | Source, replica, role, key policy, and Region-specific keys must align. |
| Cleanup query still finds a version | Stop bucket deletion and reconcile version IDs | Do not hide leftovers by suspending versioning or deleting only current keys. |
Professional questions normally contain several valid services. State the requirement that selects one option, why the nearest alternative fails it, and what changed requirement would reverse the choice.
AWS Management Console guided practice
Before opening a service page, write the expected account, Region, starting state, and evidence. Do not choose Create, Save, Purchase, Lock, or Delete unless the lesson explicitly authorizes the live track.
- Create the source bucket in ap-south-1 and replica bucket in ap-southeast-1 with globally unique approved names, bucket owner enforced, all BPA settings on, versioning, and SSE-S3.
- Configure source lifecycle and one-way
documents/replication with the exact service role. Upload version 1 and version 2, wait for replica status, then create and recover from a delete marker. - Delete the replication rule, empty both buckets with Show versions so every version and marker is selected, delete buckets, remove the role, and verify absence plus delayed billing review.
For each step, capture the field name and value in text. A screenshot may support the record but does not replace the explanation. Console labels can evolve, so use the service search and current documentation if a navigation label differs.
CloudShell and AWS CLI practice
CloudShell is the default browser-based command environment taught in AWS 028. AWS 029 and AWS 030 cover local CLI installation and authentication. This lesson therefore does not assume that an unconfigured local shell is ready.
Start every session with:
set -euo pipefail
export AWS_DEFAULT_REGION="ap-south-1"
aws sts get-caller-identity --query Arn --output text
aws configure list
Redact the account portion of the ARN before sharing. Then perform the topic query:
Verify security, versioning, lifecycle, replication, versions, delete markers, recovery content, and final absence in both Regions.
NW_SOURCE_BUCKET="replace-with-owned-source-bucket-name"
NW_REPLICA_BUCKET="replace-with-owned-replica-bucket-name"
aws s3api get-bucket-versioning --bucket "$NW_SOURCE_BUCKET"
aws s3api get-public-access-block --bucket "$NW_SOURCE_BUCKET"
aws s3api get-bucket-lifecycle-configuration --bucket "$NW_SOURCE_BUCKET"
aws s3api get-bucket-replication --bucket "$NW_SOURCE_BUCKET"
aws s3api list-object-versions --bucket "$NW_SOURCE_BUCKET" --prefix documents/
aws s3api list-object-versions --bucket "$NW_REPLICA_BUCKET" --prefix documents/ --region ap-southeast-1
Expected interpretation:
Before recovery, show two source data versions and a current delete marker plus the configured replica evidence. After removing the source delete marker, GET returns version 2 content. After cleanup, list-buckets no longer includes either exact name and the project role is absent.
Replace every replace-with-... sample value before running its command, and use only an explicitly owned resource. Explain each option first. These queries are read-only; a successful response does not authorize a later create or delete operation.
Practical work
Execute one of two tracks. The live T1 track requires owner approval, unique suffix, current source and destination price evidence, a 120-minute timer, exact JSON artifacts, and p06-resource-ledger.md. The required alternative uses supplied Console, CLI, version, and replication records. In either track submit security configuration, two source versions, replica proof, delete-marker failure, restored version 2 content, one denied anonymous request, version-aware cleanup, role cleanup, and a scheduled cost follow-up.
Exact S3 live-lab runbook
The bucket suffix must be globally unique but must not contain a full account ID, email address, or other personal data.
export AWS_DEFAULT_REGION="ap-south-1"
NW_SOURCE_REGION="ap-south-1"
NW_REPLICA_REGION="ap-southeast-1"
NW_SUFFIX="$(date -u +%Y%m%d%H%M%S)-${RANDOM}"
NW_SOURCE_BUCKET="nw-p06-source-${NW_SUFFIX}"
NW_REPLICA_BUCKET="nw-p06-replica-${NW_SUFFIX}"
NW_ROLE_NAME="nw-p06-repl-${NW_SUFFIX}"
printf 'Source: %s\nReplica: %s\n' "$NW_SOURCE_BUCKET" "$NW_REPLICA_BUCKET"
Record the names privately in p06-resource-ledger.md before creation.
1. Create and secure both buckets
aws s3api create-bucket --bucket "$NW_SOURCE_BUCKET" --region "$NW_SOURCE_REGION" --create-bucket-configuration LocationConstraint="$NW_SOURCE_REGION"
aws s3api create-bucket --bucket "$NW_REPLICA_BUCKET" --region "$NW_REPLICA_REGION" --create-bucket-configuration LocationConstraint="$NW_REPLICA_REGION"
for NW_PAIR in "$NW_SOURCE_BUCKET:$NW_SOURCE_REGION" "$NW_REPLICA_BUCKET:$NW_REPLICA_REGION"; do
NW_BUCKET="${NW_PAIR%%:*}"
NW_REGION="${NW_PAIR##*:}"
aws s3api put-public-access-block --bucket "$NW_BUCKET" --region "$NW_REGION" --public-access-block-configuration BlockPublicAcls=true,IgnorePublicAcls=true,BlockPublicPolicy=true,RestrictPublicBuckets=true
aws s3api put-bucket-ownership-controls --bucket "$NW_BUCKET" --region "$NW_REGION" --ownership-controls 'Rules=[{ObjectOwnership=BucketOwnerEnforced}]'
aws s3api put-bucket-versioning --bucket "$NW_BUCKET" --region "$NW_REGION" --versioning-configuration Status=Enabled
aws s3api put-bucket-encryption --bucket "$NW_BUCKET" --region "$NW_REGION" --server-side-encryption-configuration 'Rules=[{ApplyServerSideEncryptionByDefault={SSEAlgorithm=AES256},BucketKeyEnabled=false}]'
aws s3api put-bucket-tagging --bucket "$NW_BUCKET" --region "$NW_REGION" --tagging 'TagSet=[{Key=Project,Value=NitWings-P06},{Key=DeleteAfterLesson,Value=AWS120}]'
cat > nw-p06-tls-policy.json <<JSON
{
"Version": "2012-10-17",
"Statement": [{
"Sid": "DenyInsecureTransport",
"Effect": "Deny",
"Principal": "*",
"Action": "s3:*",
"Resource": ["arn:aws:s3:::${NW_BUCKET}", "arn:aws:s3:::${NW_BUCKET}/*"],
"Condition": {"Bool": {"aws:SecureTransport": "false"}}
}]
}
JSON
aws s3api put-bucket-policy --bucket "$NW_BUCKET" --region "$NW_REGION" --policy file://nw-p06-tls-policy.json
done
Verify all four BPA booleans, versioning Enabled, ownership BucketOwnerEnforced, and encryption AES256 on both buckets before continuing.
2. Add the source lifecycle rule
Create nw-p06-lifecycle.json:
{
"Rules": [
{
"ID": "nw-p06-version-cost-control",
"Status": "Enabled",
"Filter": {"Prefix": ""},
"NoncurrentVersionTransitions": [{"NoncurrentDays": 30, "StorageClass": "STANDARD_IA"}],
"NoncurrentVersionExpiration": {"NoncurrentDays": 90},
"AbortIncompleteMultipartUpload": {"DaysAfterInitiation": 7}
}
]
}
Apply and read it back:
aws s3api put-bucket-lifecycle-configuration --bucket "$NW_SOURCE_BUCKET" --region "$NW_SOURCE_REGION" --lifecycle-configuration file://nw-p06-lifecycle.json
aws s3api get-bucket-lifecycle-configuration --bucket "$NW_SOURCE_BUCKET" --region "$NW_SOURCE_REGION"
This proves configuration only. The lab does not wait 30, 90, or 7 days. The tiny sample objects might also be below the current default minimum size for lifecycle transition, which is another reason not to claim that a transition was tested.
3. Create the replication role and least-privilege policy
Create nw-p06-replication-trust.json:
{
"Version": "2012-10-17",
"Statement": [{
"Effect": "Allow",
"Principal": {"Service": "s3.amazonaws.com"},
"Action": "sts:AssumeRole"
}]
}
Create nw-p06-replication-policy.json after replacing the two bucket placeholders with the current shell values:
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "ReadSourceConfiguration",
"Effect": "Allow",
"Action": ["s3:GetReplicationConfiguration", "s3:ListBucket"],
"Resource": "arn:aws:s3:::SOURCE_BUCKET"
},
{
"Sid": "ReadSourceVersions",
"Effect": "Allow",
"Action": ["s3:GetObjectVersionForReplication", "s3:GetObjectVersionAcl", "s3:GetObjectVersionTagging"],
"Resource": "arn:aws:s3:::SOURCE_BUCKET/documents/*"
},
{
"Sid": "WriteReplicaVersions",
"Effect": "Allow",
"Action": ["s3:ReplicateObject", "s3:ReplicateDelete", "s3:ReplicateTags"],
"Resource": "arn:aws:s3:::REPLICA_BUCKET/documents/*"
}
]
}
Use sed only on the local lab JSON, inspect the final file, then create the role:
sed -i "s/SOURCE_BUCKET/${NW_SOURCE_BUCKET}/g; s/REPLICA_BUCKET/${NW_REPLICA_BUCKET}/g" nw-p06-replication-policy.json
aws iam create-role --role-name "$NW_ROLE_NAME" --assume-role-policy-document file://nw-p06-replication-trust.json --tags Key=Project,Value=NitWings-P06 Key=DeleteAfterLesson,Value=AWS120
aws iam put-role-policy --role-name "$NW_ROLE_NAME" --policy-name nw-p06-s3-replication --policy-document file://nw-p06-replication-policy.json
NW_ROLE_ARN="$(aws iam get-role --role-name "$NW_ROLE_NAME" --query Role.Arn --output text)"
Create nw-p06-replication.json:
{
"Role": "ROLE_ARN",
"Rules": [
{
"ID": "nw-p06-documents-to-singapore",
"Priority": 1,
"Status": "Enabled",
"DeleteMarkerReplication": {"Status": "Enabled"},
"Filter": {"Prefix": "documents/"},
"Destination": {
"Bucket": "arn:aws:s3:::REPLICA_BUCKET",
"StorageClass": "STANDARD"
}
}
]
}
sed -i "s|ROLE_ARN|${NW_ROLE_ARN}|g; s/REPLICA_BUCKET/${NW_REPLICA_BUCKET}/g" nw-p06-replication.json
NW_REPLICATION_CONFIGURED="false"
for NW_ATTEMPT in $(seq 1 6); do
if aws s3api put-bucket-replication --bucket "$NW_SOURCE_BUCKET" --region "$NW_SOURCE_REGION" --replication-configuration file://nw-p06-replication.json; then
NW_REPLICATION_CONFIGURED="true"
break
fi
echo "Replication role might still be propagating; retry ${NW_ATTEMPT}/6" >&2
sleep 10
done
if [ "$NW_REPLICATION_CONFIGURED" != "true" ]; then
echo "Stop: replication configuration was not accepted; preserve evidence and run reviewed cleanup" >&2
exit 1
fi
aws s3api get-bucket-replication --bucket "$NW_SOURCE_BUCKET" --region "$NW_SOURCE_REGION"
4. Upload two versions and verify replication
printf 'NitWings P06 policy version 1\n' > policy.txt
NW_V1="$(aws s3api put-object --bucket "$NW_SOURCE_BUCKET" --key documents/policy.txt --body policy.txt --server-side-encryption AES256 --tagging 'Project=NitWings-P06&DataClass=Training' --query VersionId --output text)"
printf 'NitWings P06 policy version 2\n' > policy.txt
NW_V2="$(aws s3api put-object --bucket "$NW_SOURCE_BUCKET" --key documents/policy.txt --body policy.txt --server-side-encryption AES256 --tagging 'Project=NitWings-P06&DataClass=Training' --query VersionId --output text)"
printf 'V1=%s\nV2=%s\n' "$NW_V1" "$NW_V2"
Poll for no more than five minutes. Stop earlier when both source versions show COMPLETED:
for NW_ATTEMPT in $(seq 1 30); do
NW_V1_STATUS="$(aws s3api head-object --bucket "$NW_SOURCE_BUCKET" --key documents/policy.txt --version-id "$NW_V1" --query ReplicationStatus --output text)"
NW_V2_STATUS="$(aws s3api head-object --bucket "$NW_SOURCE_BUCKET" --key documents/policy.txt --version-id "$NW_V2" --query ReplicationStatus --output text)"
printf 'attempt=%s v1=%s v2=%s\n' "$NW_ATTEMPT" "$NW_V1_STATUS" "$NW_V2_STATUS"
if [ "$NW_V1_STATUS" = "COMPLETED" ] && [ "$NW_V2_STATUS" = "COMPLETED" ]; then break; fi
sleep 10
done
aws s3api list-object-versions --bucket "$NW_REPLICA_BUCKET" --region "$NW_REPLICA_REGION" --prefix documents/policy.txt --output table
if [ "$NW_V1_STATUS" != "COMPLETED" ] || [ "$NW_V2_STATUS" != "COMPLETED" ]; then
echo "Stop: replication did not complete inside the five-minute evidence window" >&2
exit 1
fi
If either status remains FAILED or PENDING, preserve the role, bucket, and replication evidence. Diagnose permission and configuration before retrying another PUT.
5. Prove denial, delete marker, and recovery
An anonymous request must fail. A 403 result is expected:
curl --silent --show-error --output /dev/null --write-out '%{http_code}\n' "https://${NW_SOURCE_BUCKET}.s3.${NW_SOURCE_REGION}.amazonaws.com/documents/policy.txt"
Create a delete marker without naming a version:
NW_DELETE_MARKER_ID="$(aws s3api delete-object --bucket "$NW_SOURCE_BUCKET" --key documents/policy.txt --query VersionId --output text)"
aws s3api list-object-versions --bucket "$NW_SOURCE_BUCKET" --prefix documents/policy.txt --output table
if aws s3api get-object --bucket "$NW_SOURCE_BUCKET" --key documents/policy.txt deleted-object.txt; then
echo 'Unexpected: current GET succeeded while delete marker should be current' >&2
exit 1
else
echo 'Expected: current GET failed because the delete marker is current'
fi
Recover by deleting that exact delete-marker version, not a data version:
aws s3api delete-object --bucket "$NW_SOURCE_BUCKET" --key documents/policy.txt --version-id "$NW_DELETE_MARKER_ID"
aws s3api get-object --bucket "$NW_SOURCE_BUCKET" --key documents/policy.txt restored-policy.txt
grep -F 'version 2' restored-policy.txt
This restores the source current view. Deleting a specific source version, including that delete marker, is not replicated as a specific-version deletion. The replica can therefore retain its replicated delete marker until an explicit destination recovery or the version-aware cleanup.
6. Version-aware cleanup
Delete replication configuration first. Empty both versioned buckets by exact version ID. The lab intentionally creates fewer than 1,000 versions, so one delete-objects request per bucket is sufficient. A production cleanup must paginate list-object-versions, submit batches of at most 1,000 identifiers, inventory multipart uploads, account for in-flight replication, and repeat until a stable empty state is proven. Never reuse this bounded lab loop as an unreviewed production deletion script.
aws s3api delete-bucket-replication --bucket "$NW_SOURCE_BUCKET" --region "$NW_SOURCE_REGION"
for NW_PAIR in "$NW_SOURCE_BUCKET:$NW_SOURCE_REGION" "$NW_REPLICA_BUCKET:$NW_REPLICA_REGION"; do
NW_BUCKET="${NW_PAIR%%:*}"
NW_REGION="${NW_PAIR##*:}"
aws s3api list-object-versions --bucket "$NW_BUCKET" --region "$NW_REGION" --output json \
| jq '{Objects: (((.Versions // []) + (.DeleteMarkers // [])) | map({Key: .Key, VersionId: .VersionId})), Quiet: true}' \
> "delete-${NW_REGION}.json"
jq . "delete-${NW_REGION}.json"
if jq -e '.Objects | length > 0' "delete-${NW_REGION}.json" >/dev/null; then
aws s3api delete-objects --bucket "$NW_BUCKET" --region "$NW_REGION" --delete "file://delete-${NW_REGION}.json"
fi
NW_REMAINING="$(aws s3api list-object-versions --bucket "$NW_BUCKET" --region "$NW_REGION" --output json | jq '((.Versions // []) | length) + ((.DeleteMarkers // []) | length)')"
printf 'bucket=%s remaining_versions_and_markers=%s\n' "$NW_BUCKET" "$NW_REMAINING"
if [ "$NW_REMAINING" != "0" ]; then
echo "Stop: bucket is not empty; inspect in-flight replication and version inventory" >&2
exit 1
fi
NW_MULTIPART_COUNT="$(aws s3api list-multipart-uploads --bucket "$NW_BUCKET" --region "$NW_REGION" --query 'length(Uploads || `[]`)' --output text)"
if [ "$NW_MULTIPART_COUNT" != "0" ]; then
echo "Stop: incomplete multipart uploads require explicit inventory and abort" >&2
exit 1
fi
aws s3api delete-bucket --bucket "$NW_BUCKET" --region "$NW_REGION"
done
aws iam delete-role-policy --role-name "$NW_ROLE_NAME" --policy-name nw-p06-s3-replication
aws iam delete-role --role-name "$NW_ROLE_NAME"
rm -f policy.txt restored-policy.txt deleted-object.txt nw-p06-tls-policy.json nw-p06-lifecycle.json nw-p06-replication-trust.json nw-p06-replication-policy.json nw-p06-replication.json delete-ap-south-1.json delete-ap-southeast-1.json
The local rm line removes only the explicitly named CloudShell lab artifacts. It does not prove AWS cleanup. Re-run bucket and IAM queries, inspect both Regions, and schedule the billing review.
The evidence package must contain:
- the problem and final requirement in the learner's own words;
- caller type and Region with private identifiers redacted;
- exact planned values, ownership, and cost class;
- one Console observation and matching CLI or API evidence;
- one behavior result or supplied data-plane record;
- one denied, failed, or counterexample result and evidence-led diagnosis;
- one architecture choice plus the rejected alternative;
- cleanup proof or explicit retained-state owner, expiry, and next lesson.
Verification standard
Use expected state before observed state. Record timestamps in UTC and preserve the original failure before changing anything. A passing submission answers all four questions:
- What exact requirement was tested?
- Which evidence proves the AWS configuration?
- Which evidence proves the workload behavior?
- What remains unproven or requires later monitoring?
If AWS returns no rows, verify account, Region, permission, filters, pagination, resource type, and deletion state before concluding that nothing exists.
Common failures and troubleshooting
| Symptom | Evidence first | Likely boundary | Smallest safe response |
|---|---|---|---|
| object appears missing | caller, Region, filters, pagination, tags | scope or read permission | align scope before creating a duplicate |
| state remains pending or unavailable | service state, events, dependencies, quotas | dependency or capacity | correct the named dependency and wait with a bound |
| AccessDenied | principal, action, resource, explicit-deny context | identity, resource, endpoint, organization, or KMS policy | change only the proven policy layer |
| configuration exists but behavior fails | route, DNS, security, listener, health, logs, object version | data path or application | test the next boundary and change one control |
| bill is higher than expected | hours, bytes, requests, AZs, addresses, retention | cost model or retained resource | stop optional work and reconcile the ledger |
| cleanup is blocked | dependency inventory and owning service | deletion order or immutable state | remove owned dependants in reviewed reverse order |
Do not troubleshoot by attaching administrator access, opening administration ports to the internet, disabling encryption, retrying uncontrolled creation, deleting unknown resources, or weakening retention.
Cost, cleanup, and retained state
No P06 bucket, version, delete marker, replication rule, or IAM role remains after the lesson.
Cleanup evidence requires terminal state and an after-inventory. Search related ENIs, public IPv4 addresses, EBS volumes and snapshots, load balancers, target groups, Auto Scaling instances, endpoints, logs, S3 versions and delete markers, backup recovery points, and global IAM roles when they apply. Billing data can lag, so schedule a later review.
Architecture and certification decisions
- Certification coverage: SAA-C03; SOA-C03; SAP-C02; DOP-C02.
- Exam mapping: SAA D1-D4.
- Explain service scope, failure boundary, consistency, recovery, security, operations, and price rather than matching a keyword.
- Treat availability and durability, encryption and authorization, routing and filtering, health and lifecycle, backup and replication, and discount and capacity as separate concepts.
- Do not reproduce protected certification questions.
Knowledge check
- Why must both buckets have versioning?
Expected direction: It is a replication prerequisite and supplies version-level recovery.
- Does the lifecycle rule execute during the short lab?
Expected direction: Not necessarily. Validate the rule configuration and use explicit cleanup.
- How is a simple delete recovered?
Expected direction: Delete the current delete marker by its version ID to reveal the prior data version.
- Why is recursive bucket deletion insufficient?
Expected direction: Versioned buckets retain noncurrent versions and delete markers.
Completion gate and assessment
| Area | Points | Passing evidence |
|---|---|---|
| Requirement and model | 15 | Correct scope, terminology, and final outcome |
| Console evidence | 15 | Current path and interpreted fields |
| CLI or API evidence | 15 | Scoped command, expected result, and limitations |
| Behavior or decision exercise | 20 | Reproducible result or defensible architecture reasoning |
| Troubleshooting | 15 | Original symptom, hypothesis, one change, retest, rollback |
| Security and cost | 10 | Least privilege, data protection, current price dimensions |
| Cleanup and handoff | 10 | Terminal-state proof or approved retained-state record |
Pass at 80 out of 100 with no critical safety failure. A missing practical artifact, unexplained output, unsafe access, destructive action outside the owned scope, unplanned billed resource, or false cleanup claim requires remediation and a changed retest.