passdrill

S3 & Storage

44 cards · AWS SAA-C03 · answer each one, then read the explanation. Your score tallies below. Looking for S3 storage classes compared: cost, retrieval time & minimum duration? Read the explainer.

0 / 44 answered · 0 correct

AWS SAA-C03 · S3 & Storage · Card 001/044 medium

A hospital must retain scanned records for 10 years to meet compliance rules. Records are almost never accessed, and when auditors do request one, a retrieval time of up to 12 hours is acceptable. Which S3 storage class minimises cost for this archive?

  1. S3 Glacier Deep Archive
  2. S3 Standard
  3. S3 Standard-Infrequent Access
  4. S3 Glacier Flexible Retrieval
AWS SAA-C03 · S3 & Storage · Card 002/044 medium

A team enabled versioning on an S3 bucket last year. A new administrator wants to turn versioning off completely so the bucket returns to its original unversioned state. What can the administrator actually do?

  1. Disable versioning, which deletes all previous object versions
  2. Suspend versioning; existing versions are kept and new uploads stop creating versions
  3. Disable versioning only after emptying the bucket
  4. Nothing; versioning can never be changed once enabled
AWS SAA-C03 · S3 & Storage · Card 003/044 easy

A developer uploads a new object to a freshly created S3 bucket using the default AWS CLI settings, without specifying any encryption headers and without configuring a default encryption setting on the bucket. What happens to the object?

  1. The object is stored unencrypted because no encryption was requested
  2. The upload fails because encryption must be explicitly configured first
  3. The object is automatically encrypted with SSE-KMS using the account's default key
  4. The object is automatically encrypted with SSE-S3 at no additional cost
AWS SAA-C03 · S3 & Storage · Card 004/044 easy

A logistics company uploads a file to an S3 bucket using the PutObject API and does not specify a storage class in the request. Which storage class is the object stored in?

  1. S3 Intelligent-Tiering
  2. S3 Standard-Infrequent Access
  3. S3 Standard
  4. Whichever class was used for the previous object with the same key prefix
AWS SAA-C03 · S3 & Storage · Card 005/044 medium

A media company moves a 2 GB video file to S3 Standard-IA to reduce storage cost. After only 10 days, a producer requests the file be permanently deleted. What should the company expect regarding cost?

  1. No extra charge, since the object is being deleted rather than transitioned
  2. A pro-rated charge for the remaining days of the 30-day minimum storage duration
  3. A one-time early-deletion penalty equal to a full year of storage
  4. The deletion is blocked until the 30-day minimum duration has elapsed
AWS SAA-C03 · S3 & Storage · Card 006/044 easy

A research lab stores reproducible simulation output that is infrequently accessed. If the lab can tolerate the total loss of the data should an entire Availability Zone fail, which infrequent-access storage class minimises cost compared to its multi-AZ equivalent?

  1. S3 One Zone-Infrequent Access
  2. S3 Standard-Infrequent Access
  3. S3 Glacier Instant Retrieval
  4. S3 Intelligent-Tiering
AWS SAA-C03 · S3 & Storage · Card 007/044 medium

A gaming company stores player-generated screenshots in S3 with unpredictable access patterns: some are viewed constantly right after upload, others are never opened again. They move all screenshots to S3 Intelligent-Tiering. Which statement about this storage class is correct?

  1. There are per-GB retrieval fees whenever an object moves back to the Frequent Access tier
  2. Objects must be manually moved between tiers using a lifecycle rule
  3. Every object smaller than 128 KB is rejected by the storage class
  4. There are no retrieval fees, and small monitoring and automation fees apply per object instead
AWS SAA-C03 · S3 & Storage · Card 008/044 medium

A retailer wants to configure Cross-Region Replication (CRR) from its orders bucket in eu-west-1 to a backup bucket in eu-central-1. The source bucket already has versioning enabled. What else must be true for the replication configuration to succeed?

  1. Nothing further is required; only the source bucket needs versioning enabled
  2. The destination bucket must also have versioning enabled
  3. The destination bucket must be in the same AWS account as the source bucket
  4. The source bucket must first be converted to a Requester Pays bucket
AWS SAA-C03 · S3 & Storage · Card 009/044 medium

An analytics team runs EC2 instances in a private subnet with no NAT gateway and no internet gateway. They need the instances to read and write objects in an S3 bucket in the same Region, using only private connectivity, at no additional hourly charge. Which solution meets this requirement?

  1. An interface VPC endpoint (AWS PrivateLink) for S3
  2. A NAT gateway routed to an internet gateway
  3. A gateway VPC endpoint for S3
  4. A VPC peering connection to a public S3 endpoint
AWS SAA-C03 · S3 & Storage · Card 010/044 easy

An engineer needs to upload a single 6 GB video file to S3 using the AWS CLI. They attempt a single `PUT` operation via `aws s3api put-object`. What happens?

  1. The upload fails because a single PUT operation is limited to 5 GB; multipart upload is required
  2. The upload fails because the AWS CLI never supports single PUT operations
  3. The upload succeeds because S3 accepts objects up to 5 TB in a single PUT
  4. The upload succeeds but S3 automatically splits it into parts behind the scenes
AWS SAA-C03 · S3 & Storage · Card 011/044 easy

A backup application is performing a multipart upload of a large database dump to S3. All parts are 5 MiB except the very last part, which is smaller. Is this multipart upload valid?

  1. No, because every part including the last must be at least 5 MiB
  2. No, because all parts must be exactly the same size
  3. Yes, but only if the smaller last part is uploaded first
  4. Yes, because there is no minimum size limit on the last part of a multipart upload
AWS SAA-C03 · S3 & Storage · Card 012/044 easy

A financial services firm wants to apply write-once-read-many (WORM) protection to trade records stored in S3 using S3 Object Lock. The bucket currently does not have versioning enabled. What must happen first?

  1. Versioning must be enabled on the bucket, since Object Lock only works on versioning-enabled buckets
  2. Nothing; Object Lock can be enabled independently of versioning
  3. The bucket must first be converted into a One Zone-IA bucket
  4. A legal hold must be placed on every existing object before Object Lock can be turned on
AWS SAA-C03 · S3 & Storage · Card 013/044 hard

A pharmaceutical company locks clinical trial records in S3 Object Lock using Compliance mode with a 5-year retention period, to satisfy a regulator's WORM requirement. Two years in, the AWS account's root user attempts to delete one of the locked object versions before its retention period expires. What happens?

  1. The deletion succeeds because the root user can always override any S3 protection
  2. The deletion fails; under Compliance mode, no user including the root user can delete or shorten the retention before it expires
  3. The deletion succeeds only if the root user also supplies the BypassGovernanceRetention header
  4. The deletion fails, but only until a legal hold is manually removed
AWS SAA-C03 · S3 & Storage · Card 014/044 medium

A compliance team applies S3 Object Lock in Governance mode to a set of audit logs with a 1-year retention period. Six months later, an authorized administrator with the `s3:BypassGovernanceRetention` permission needs to delete one of the locked objects early for a legitimate reason. What must the administrator do?

  1. Nothing extra; holding the permission alone silently allows the delete to succeed
  2. Wait for the legal hold on the object to expire first
  3. Include the `x-amz-bypass-governance-retention: true` header on the delete request
  4. Switch the object's retention mode to Compliance before deleting it
AWS SAA-C03 · S3 & Storage · Card 015/044 easy

A mobile app backend needs to let end users upload profile pictures directly to a private S3 bucket without giving them any AWS credentials. A backend service generates a presigned URL for each upload using the AWS SDK with long-term IAM user credentials. What is the maximum expiration time that can be set for this presigned URL?

  1. 15 minutes
  2. 1 hour
  3. 7 days
  4. There is no maximum; it can be set to expire at any future date
AWS SAA-C03 · S3 & Storage · Card 016/044 hard

Company A owns a public dataset bucket and configures it as a Requester Pays bucket so that anyone downloading the data covers the data transfer and request costs instead of Company A. Company B, in a different AWS account, later asks to configure this bucket as the destination for S3 Cross-Region Replication from one of their buckets. What happens?

  1. This is not possible; a Requester Pays bucket cannot be configured as a cross-account replication destination
  2. This works normally; Requester Pays has no effect on replication
  3. This works, but Company A must pay all replication data transfer costs instead of Company B
  4. This works only if versioning is disabled on the Requester Pays bucket
AWS SAA-C03 · S3 & Storage · Card 017/044 medium

A media company's central data-lake bucket is shared by five application teams, each of which should be able to read and write only within its own prefix. Managing this with one large, constantly changing bucket policy has become error-prone as new teams are added. Which S3 feature lets an administrator create a separate named endpoint per team, each carrying its own access policy scoped to that team's prefix, without editing the underlying bucket policy every time?

  1. Configure S3 Cross-Region Replication so each team gets its own destination bucket
  2. Create IAM users with AdministratorAccess for each team and let them self-manage
  3. Create an S3 Access Point per team, each with a policy scoped to that team's prefix
  4. Keep adding a new statement to the bucket policy for each team's IAM role ARN
AWS SAA-C03 · S3 & Storage · Card 018/044 easy

A small business wants to host a static marketing site (HTML, CSS, and images) directly from an S3 bucket, serving the content over plain HTTP to anyone on the internet. Which configuration is required, at minimum, to make this work?

  1. Enable static website hosting on the bucket, specify an index document, and allow public read access to the objects
  2. Enable S3 Transfer Acceleration on the bucket so the site loads faster worldwide
  3. Turn on S3 Object Lock so visitors cannot delete pages
  4. Enable S3 Intelligent-Tiering so page assets automatically move between access tiers
AWS SAA-C03 · S3 & Storage · Card 019/044 medium

Account A owns an S3 bucket. A team in Account B needs to be able to run GetObject and PutObject against a specific prefix in that bucket, using their own IAM role in Account B, without Account A creating any IAM users for Account B's team. Which mechanism directly grants this cross-account access?

  1. An S3 Access Control List (ACL) granting Account B's root user FULL_CONTROL over the bucket
  2. An IAM permissions boundary attached to Account B's role
  3. S3 Object Lock configured in Governance mode on the prefix
  4. A bucket policy on Account A's bucket that names Account B's IAM role ARN as principal and allows the required actions on that prefix
AWS SAA-C03 · S3 & Storage · Card 020/044 easy

An e-commerce company wants a Lambda function to run automatically every time a new object is uploaded to a specific prefix in an S3 bucket, so it can generate a thumbnail. Which S3 feature triggers this without the application having to poll the bucket?

  1. S3 Storage Class Analysis
  2. S3 Event Notifications configured to invoke the Lambda function on PutObject events for that prefix
  3. S3 Requester Pays
  4. S3 Batch Operations run manually by an administrator
AWS SAA-C03 · S3 & Storage · Card 021/044 easy

An analytics application needs to pull only a handful of columns from large CSV objects stored in S3, rather than downloading and parsing entire multi-gigabyte files in the application. Which S3 feature lets the application run a SQL-like expression against an object and receive back only the matching data?

  1. S3 Transfer Acceleration
  2. S3 Cross-Region Replication
  3. S3 Select
  4. S3 Glacier Bulk Retrieval
AWS SAA-C03 · S3 & Storage · Card 022/044 easy

A company with hundreds of S3 buckets spread across many AWS accounts wants a single dashboard showing organization-wide metrics on storage usage, activity, and cost-optimisation opportunities, without having to query each bucket individually. Which S3 feature provides this?

  1. S3 Storage Lens
  2. S3 Object Lock
  3. S3 Requester Pays
  4. S3 Same-Region Replication
AWS SAA-C03 · S3 & Storage · Card 023/044 medium

A company has 200 million existing objects in an S3 bucket and needs to invoke a Lambda function against every one of them to redact a specific field, without writing custom code to list and iterate over each object individually. Which S3 feature is designed for this kind of bulk action across a very large number of existing objects?

  1. S3 Event Notifications
  2. S3 Transfer Acceleration
  3. S3 Lifecycle expiration rules
  4. S3 Batch Operations, using a manifest of the objects and invoking the Lambda function as the batch action
AWS SAA-C03 · S3 & Storage · Card 024/044 hard

A company encrypts millions of objects per day in an S3 bucket using SSE-KMS with a customer managed KMS key, and starts hitting AWS KMS request throttling because nearly every PutObject and GetObject call generates a separate request to AWS KMS. Regulatory requirements mandate that objects keep using SSE-KMS with a customer managed key, so switching to a different encryption method is not an option. What should the company do to cut the number of calls reaching AWS KMS?

  1. Switch the bucket to SSE-C so the company manages keys itself instead of KMS
  2. Enable an S3 Bucket Key for SSE-KMS on the bucket, which uses a time-limited bucket-level key to derive data keys instead of calling KMS for every request
  3. Switch to SSE-S3 encryption, which does not use AWS KMS at all
  4. Disable default bucket encryption so PUT requests no longer trigger any encryption workflow
AWS SAA-C03 · S3 & Storage · Card 025/044 medium

A media company has users worldwide uploading large video files directly to a single S3 bucket in one AWS Region, and users far from that Region report slow, inconsistent upload speeds over the public internet. Which S3 feature is designed to speed up these long-distance uploads by routing traffic through the nearest edge location onto AWS's network backbone?

  1. S3 Same-Region Replication
  2. S3 Intelligent-Tiering
  3. S3 Transfer Acceleration, using the bucket's accelerate endpoint which routes traffic through Amazon CloudFront edge locations
  4. S3 Object Lock in Compliance mode
AWS SAA-C03 · S3 & Storage · Card 026/044 easy

An application uploads a new object to S3 with PutObject, and its next line of code immediately issues a GetObject request for that same key. Which statement correctly describes what Amazon S3 guarantees here?

  1. The GetObject request returns the newly written data, because S3 provides strong read-after-write consistency for PUT and DELETE requests in all Regions
  2. The GetObject request may return stale or no data for up to several seconds, because S3 is only eventually consistent
  3. The GetObject request will fail until the object is replicated to at least two Availability Zones
  4. The GetObject request only returns the new data if S3 Versioning is enabled on the bucket
AWS SAA-C03 · S3 & Storage · Card 027/044 medium

A hospital group must keep a second, independent copy of every object written to its records bucket, purely for internal redundancy and faster local access by a separate analytics team in the same country, and has no requirement to store any copy in a different AWS Region. Which S3 Replication configuration fits this requirement without introducing cross-Region data transfer?

  1. Cross-Region Replication (CRR) to a bucket in a neighbouring Region
  2. S3 Transfer Acceleration between the two buckets
  3. S3 Object Lock replication rules, which are Region-independent
  4. Same-Region Replication (SRR) to a second bucket within the same AWS Region
AWS SAA-C03 · S3 & Storage · Card 028/044 hard

A company configures an S3 Lifecycle rule in 2026 on a bucket containing millions of small JSON event files, most only a few KB each, to transition all objects to S3 Glacier Flexible Retrieval after 30 days. After the rule runs, the company notices that the small objects are still in S3 Standard while larger objects transitioned as expected. What is the most likely explanation, given S3's current default lifecycle behaviour?

  1. Lifecycle rules never apply to JSON files regardless of size
  2. By default, S3 Lifecycle does not transition objects smaller than 128 KB to any storage class unless the rule includes an object size filter allowing smaller objects
  3. Objects smaller than 128 KB are automatically deleted instead of transitioned
  4. Lifecycle transitions only work on buckets without versioning enabled
AWS SAA-C03 · S3 & Storage · Card 029/044 medium

A developer creates a brand-new S3 bucket in 2026 without changing any default settings, then has another AWS account upload an object to it using a custom ACL that attempts to grant a third account read access. What happens, given the bucket's default Object Ownership setting?

  1. The upload succeeds and the third account gains read access exactly as the ACL specified
  2. The upload succeeds, but only the bucket owner can read the object because ACLs are silently ignored
  3. The upload fails, because the default Bucket owner enforced setting disables ACLs and rejects PUT requests that specify one other than bucket-owner-full-control
  4. The upload succeeds only if the uploading account first disables S3 Block Public Access
AWS SAA-C03 · S3 & Storage · Card 030/044 easy

A company enables S3 Versioning and wants an extra safeguard so that permanently deleting an object version, or turning versioning off, requires more than just valid IAM credentials. Which S3 feature adds this requirement, and how must it be enabled?

  1. S3 Object Lock in Governance mode, enabled through the AWS Management Console
  2. S3 Access Points, enabled through an IAM policy
  3. S3 Storage Lens, enabled automatically for every bucket
  4. MFA Delete, which can only be enabled by the bucket owner's root account using the AWS CLI or API, not the console
AWS SAA-C03 · S3 & Storage · Card 031/044 easy

A single-page web application hosted on `https://app.example.com` uses JavaScript running in the browser to make PUT and GET requests directly to an S3 bucket in a different domain, `assets-bucket.s3.amazonaws.com`. The browser blocks these requests with cross-origin errors. Which S3 feature must be configured on the bucket to allow this?

  1. A CORS configuration on the bucket listing the allowed origin, methods, and headers
  2. S3 Transfer Acceleration
  3. S3 Object Lock in Governance mode
  4. A gateway VPC endpoint for S3
AWS SAA-C03 · S3 & Storage · Card 032/044 medium

A bucket has S3 Versioning enabled and contains a single object with two versions. An application issues a `DELETE` request for that object's key without specifying a version ID. What happens, and what does a subsequent plain `GET` request (also without a version ID) return?

  1. Both versions are permanently deleted immediately; the GET returns a 404
  2. S3 inserts a new delete marker as the current version; the GET returns a 404 Not Found
  3. The most recent version is permanently deleted, leaving the older version as current; the GET returns that older version's data
  4. The DELETE request is rejected because a version ID must be specified in a versioning-enabled bucket
AWS SAA-C03 · S3 & Storage · Card 033/044 easy

An application frequently starts multipart uploads to an S3 bucket but, due to intermittent network failures, many of these uploads are never completed or explicitly aborted. The company notices its storage bill includes charges for parts that were never assembled into a final object. What should they configure to automatically stop paying for these abandoned parts?

  1. S3 Requester Pays, so the uploading client is billed instead of the bucket owner
  2. S3 Object Lock in Compliance mode on the bucket
  3. An S3 Lifecycle rule that transitions all objects to S3 Glacier Deep Archive after 30 days
  4. An S3 Lifecycle rule using the AbortIncompleteMultipartUpload action to delete incomplete uploads after a set number of days
AWS SAA-C03 · S3 & Storage · Card 034/044 hard

A company has had an S3 bucket in production for two years, containing millions of objects, and today configures Same-Region Replication (SRR) from that bucket to a new backup bucket for the first time. A week later, an engineer notices the backup bucket only contains objects uploaded since the replication rule was created, none of the two years of pre-existing objects. What is the correct explanation and fix?

  1. This is a temporary delay; S3 will eventually replicate all pre-existing objects automatically given enough time
  2. SRR never replicates more than 30 days of historical objects under any configuration
  3. By default, replication only applies to objects created after the replication configuration was added; replicating the pre-existing backlog requires an S3 Batch Replication job
  4. The engineer must delete and re-upload every pre-existing object for it to be picked up by replication
AWS SAA-C03 · S3 & Storage · Card 035/044 easy

Which of the following is a valid, available S3 general purpose bucket name, assuming it has not already been taken by another AWS account?

  1. my-company-logs-2026
  2. logs..backup
  3. 192.168.10.5
  4. My-Company-Logs
AWS SAA-C03 · S3 & Storage · Card 036/044 medium

A global application currently reads and writes to S3 buckets in three separate AWS Regions, with Cross-Region Replication keeping the buckets' contents in sync. Users worldwide connect to whichever bucket's Regional endpoint their client is hardcoded to use, and a Regional outage requires a manual, error-prone DNS change to redirect traffic. Which S3 feature provides a single global endpoint that automatically routes each request to the nearest healthy bucket replica, with controls to shift traffic away from a disrupted Region?

  1. An S3 Access Point scoped to each Region
  2. S3 Transfer Acceleration enabled on each bucket
  3. S3 Storage Lens configured for the organization
  4. An S3 Multi-Region Access Point, which uses AWS Global Accelerator to route requests to the closest bucket with an active routing status and supports failover controls
AWS SAA-C03 · S3 & Storage · Card 037/044 medium

A financial services firm needs to verify, beyond doubt, that a large file was not corrupted during transmission to S3, using a cryptographic-strength check rather than relying only on the object's ETag. Which S3 capability lets the client supply or request a checksum such as SHA-256 that S3 calculates and validates server-side against the uploaded data before storing the object?

  1. S3 Object Lock, which cryptographically signs every object on upload
  2. S3 additional checksums, which support algorithms including SHA-256, SHA-1, CRC32, CRC32C, and the default CRC-64/NVME
  3. S3 Storage Class Analysis, which reports on data corruption trends over time
  4. The object's ETag, which is always a SHA-256 hash of the object's contents
AWS SAA-C03 · S3 & Storage · Card 038/044 easy

A research organisation configures a bucket of open datasets as Requester Pays, so anyone downloading the data covers the transfer cost instead of the organisation. An unauthenticated visitor, with no AWS account and no credentials, tries to download an object directly from the bucket's URL. What happens?

  1. The download succeeds, and AWS bills the visitor's IP address directly for the transfer
  2. The download succeeds only if the visitor includes the x-amz-request-payer header, even without any credentials
  3. The request is denied; Requester Pays buckets do not support anonymous, unauthenticated requests at all
  4. The download succeeds and the organisation is billed, exactly as if Requester Pays were not configured
AWS SAA-C03 · S3 & Storage · Card 039/044 easy

A company stores customer records in S3 and needs every GET request made by a specific reporting application to receive the records with certain sensitive fields automatically redacted, without maintaining a second, separately stored redacted copy of every object. Which S3 feature is designed for this on-the-fly transformation of GetObject responses?

  1. S3 Select, which permanently rewrites the stored object with sensitive fields removed
  2. S3 Lifecycle rules, configured to delete sensitive fields after a retention period
  3. S3 Same-Region Replication, replicating a redacted copy to a second bucket
  4. S3 Object Lambda, which invokes a Lambda function to process and transform the data returned by a GetObject request in real time
AWS SAA-C03 · S3 & Storage · Card 040/044 hard

Account A wants to replicate SSE-KMS encrypted objects from its bucket to a bucket owned by Account B, encrypting the replicas with a KMS key in Account B. Beyond meeting the general replication requirements, which two additional conditions must be satisfied for this cross-account, KMS-encrypted replication to work?

  1. The replication rule must opt in to replicating KMS-encrypted objects and specify Account B's key; separately, Account B must grant Account A's replication role permission in that key's key policy — and the key must be a customer managed key, since AWS managed keys cannot be used cross-account
  2. Nothing extra is required beyond enabling versioning on both buckets, since KMS-encrypted objects replicate identically to unencrypted ones
  3. Account A must switch the source bucket to SSE-S3 encryption before replication will process any objects
  4. Account B must make its bucket fully public so Account A's replication role can reach it without a key policy grant
AWS SAA-C03 · S3 & Storage · Card 041/044 medium

A company wants data-driven guidance on exactly which age group of objects in a specific prefix of one bucket is infrequently accessed enough to justify a lifecycle transition from S3 Standard to S3 Standard-IA, based on actual observed retrieval patterns over time rather than a guess. Which S3 feature is purpose-built to observe that prefix's access patterns and produce this transition-age recommendation?

  1. S3 Storage Lens, which shows organization-wide dashboards of storage usage and activity metrics
  2. S3 Intelligent-Tiering, which requires switching the objects' storage class before any analysis can occur
  3. S3 Storage Class Analysis, which observes a filtered set of objects over roughly 30 days or more and recommends an object age for transitioning to S3 Standard-IA
  4. S3 Inventory, which only lists object metadata and cannot analyse access frequency
AWS SAA-C03 · S3 & Storage · Card 042/044 easy

An analyst needs to inspect the contents of an object currently stored in the S3 Glacier Deep Archive storage class. They issue a RestoreObject request specifying a 10-day restoration period. Once the restore completes, what is true about the object during and after that 10-day window?

  1. The object's storage class permanently changes to S3 Standard once the restore completes
  2. A temporary, readable copy becomes available for 10 days while the object itself remains in the Deep Archive storage class; after 10 days, the temporary copy is removed
  3. The restore permanently deletes the archived original, replacing it with only the temporary copy
  4. No temporary copy is created; the RestoreObject request instead grants direct real-time reads against the archived data for 10 days
AWS SAA-C03 · S3 & Storage · Card 043/044 medium

A company routes all of its EC2 traffic to a particular S3 bucket through one specific gateway VPC endpoint and wants to deny every request to that bucket that does not arrive through that exact endpoint, including requests made from the AWS Management Console or from outside the VPC entirely. Which bucket policy element achieves this?

  1. A Deny statement using a StringNotEquals condition on the aws:SourceVpce key, matching everything except that endpoint's ID
  2. An Allow statement naming the VPC endpoint's ARN as the policy Principal
  3. An S3 Object Lock configuration referencing the VPC endpoint ID
  4. A CORS rule restricting AllowedOrigins to the VPC endpoint's DNS name
AWS SAA-C03 · S3 & Storage · Card 044/044 easy

A pharmaceutical company keeps long-term clinical trial archives that are rarely accessed, typically about once every three months, but whenever they are needed, results must be returned in milliseconds, not minutes or hours, because they feed a live compliance dashboard. Which storage class fits this exact combination of rare access and millisecond retrieval?

  1. S3 Glacier Flexible Retrieval
  2. S3 Glacier Deep Archive
  3. S3 Glacier Instant Retrieval
  4. S3 One Zone-IA