passdrill
AWS SAA-C03 · S3 & Storage · Card 030/030 easy

A company enables S3 Versioning and wants an extra safeguard so that permanently deleting an object version, or turning versioning off, requires more than just valid IAM credentials. Which S3 feature adds this requirement, and how must it be enabled?

  1. S3 Object Lock in Governance mode, enabled through the AWS Management Console
  2. S3 Access Points, enabled through an IAM policy
  3. S3 Storage Lens, enabled automatically for every bucket
  4. MFA Delete, which can only be enabled by the bucket owner's root account using the AWS CLI or API, not the console
Next card → Shuffle