Concept and mechanism
Data controls solve different problems. OAC supports restricting a regular S3 origin to a CloudFront distribution; it does not automatically authenticate viewers and does not support the S3 website endpoint as that origin. Object Lock protects object versions during configured retention, with differences between governance and compliance. Versioning preserves prior versions and represents simple deletions through delete markers; it does not replace every backup and retention control. CloudTrail management and data events also have different scopes: observing administrative operations does not prove object reads are logged.
Guided application
For a deleted file, identify version and deletion type before recovery. For an incorrect logical change in an RDS database, identify an earlier recoverable point and restore a new instance; validate data and plan client transition. Do not assume a replica or standby preserved a state preceding the change. Include keys, permissions, and dependencies in the plan. For secrets, rotation requires consumers to obtain and use the valid version; updating only the stored value may leave old connections or configurations in use.
A table changed at 14:10. Restoring to 14:09 creates an instance to validate, including later transactions requiring reconciliation, before any service change.
Common pitfalls
Confusing encryption with authorization; treating technical retention as automatic compliance proof; switching clients before validating a restore.
Related topics: Resilience, capacity, and recovery · Storage and content delivery
Define what to protect, for how long, and how to demonstrate working recovery.
Reference: RDS point-in-time restore · SAA-C03