← AWS Solutions Architect Associate: architecture decisions
03 / 10 · 25 MIN

Data protection and recovery

Choose controls for access, retention, auditing, and recovery.

Concept and mechanism

Data controls solve different problems. OAC supports restricting a regular S3 origin to a CloudFront distribution; it does not automatically authenticate viewers and does not support the S3 website endpoint as that origin. Object Lock protects object versions during configured retention, with differences between governance and compliance. Versioning preserves prior versions and represents simple deletions through delete markers; it does not replace every backup and retention control. CloudTrail management and data events also have different scopes: observing administrative operations does not prove object reads are logged.

Guided application

For a deleted file, identify version and deletion type before recovery. For an incorrect logical change in an RDS database, identify an earlier recoverable point and restore a new instance; validate data and plan client transition. Do not assume a replica or standby preserved a state preceding the change. Include keys, permissions, and dependencies in the plan. For secrets, rotation requires consumers to obtain and use the valid version; updating only the stored value may leave old connections or configurations in use.

IN PRACTICE

A table changed at 14:10. Restoring to 14:09 creates an instance to validate, including later transactions requiring reconciliation, before any service change.

Common pitfalls

Confusing encryption with authorization; treating technical retention as automatic compliance proof; switching clients before validating a restore.

Related topics: Resilience, capacity, and recovery · Storage and content delivery

Take this idea with you

Define what to protect, for how long, and how to demonstrate working recovery.

Create account

Reference: RDS point-in-time restore · SAA-C03