AWS S3 Cross-Region Replication for Multi-Region HA

Answer Correct answer: A, D, F — Configure IAM roles and two-way S3 replication to ensure all objects exist in both regions for failover.

A company deploys an application in two AWS Regions. The application currently uses an Amazon S3 bucket in the primary Region to store data. A DevOps engineer needs to ensure that the application is highly available in both Regions. The DevOps engineer has created a new S3 bucket in the secondary Region. All existing and new objects must be in both S3 buckets. The application must fail over between the Regions with no data loss. Which combination of steps will meet these requirements with the MOST operational efficiency? (Choose three.)

  1. Create a new IAM role that allows the Amazon S3 and S3 Batch Operations service principals to assume the role that has the necessary permissions for S3 replication. Source Reference Answer
  2. Create a new IAM role that allows the AWS Batch service principal to assume the role that has the necessary permissions for S3 replication.
  3. Create an S3 Cross-Region Replication (CRR) rule on the source S3 bucket. Configure the rule to use the IAM role for Amazon S3 to replicate to the target S3 bucket.
  4. Create a two-way replication rule on the source S3 bucket. Configure the rule to use the IAM role for Amazon S3 to replicate to the target S3 bucket. Source Reference Answer
  5. Create an AWS Batch job that has an AWS Fargate orchestration type. Configure the job to use the IAM role for AWS Batch. Specify a Bash command to use the AWS CLI to synchronize the contents of the source S3 bucket and the target S3 bucket

Community Insight

The exam traps candidates who assume standard unidirectional CRR is sufficient; 'fail over with no data loss' in an active-active context requires two-way replication.

This question tests the configuration of bidirectional Amazon S3 replication to ensure zero data loss during multi-region failover, requiring IAM roles and specific replication rules.

Candidates select A and C, failing to realize that unidirectional replication allows data divergence when the application fails over to the secondary region.

Community Discussion (17 comments)

that1guy 👍 6 Selected: AD
ADF, "All existing and new objects must be in BOTH S3 buckets." this requires two-way replication.
d9iceguy 👍 5 Selected: AD
Note: Application deployed to both regions, bi-directional replication will be required
VerRi 👍 2 Selected: AD
Poor wording. An active-active solution is recommended for HA, but bidirectional replication means CRR * 2. 'a two-way replication rule' is quite misleading
aws_god 👍 2 Selected: AC
Not D because it states creating the two-way replication on the source bucket and you need to configure it on both to work: When two-way replication is set up, a replication rule from the source bucket (DOC-EXAMPLE-BUCKET-1) to the bucket containing the replicas (DOC-EXAMPLE-BUCKET-2) is created. Then, a second replication rule from the bucket containing the replicas (DOC-EXAMPLE-BUCKET-2) to the source bucket (DOC-EXAMPLE-BUCKET-1) is created.
[Removed] 👍 2 Selected: AD
ADF here, because there is no mention of two way replication in C
Trex247 👍 3 Selected: AD
I think it's ADF check out this: https://docs.aws.amazon.com/AmazonS3/latest/userguide/mrap-create-two-way-replication-rules.html
everydaysmile 👍 2 Selected: AC
Two-way replication is possible using CRR. "Replication is configured via rules. There is no rule for bi-directional replication. You will however setup a rule to replicate from the S3 bucket in the east AWS region to the west bucket, and you will setup a second rule to replicate going the opposite direction. These two rules will enable bi-directional replication across AWS regions." - https://catalog.workshops.aws/well-architected-reliability/en-US/4-failure-management/1-backup/20-bidirectional-replication-for-s3/2-configure-replication
hzaki 👍 1
there is nothing called (Create a two-way replication rule on the source S3 bucket), the two-way replication is configured separately in each region per each bucket, that's why option D is incorrect.
jamesf 👍 3 Selected: AD
Option D: two-way replication required
auxwww 👍 4 Selected: AD
D - for failover between regions. Any data stored on secondary bucket post failover operations needs to be replicated as well
xdkonorek2 👍 4 Selected: AD
"The application must fail over between the Regions with no data loss." C is not enough, because if we failover to region B and then to A application couldn't access data that was created in region B in the meantime
6ef9a08 👍 2
Two-Way Replication Rule is bidirectional, meaning objects are replicated from bucket A to bucket B and from bucket B to bucket A. This ensures that both buckets always contain the same data. S3 Cross-Region Replication (CRR) is unidirectional, meaning it replicates objects from a source bucket to a destination bucket. Changes made in the destination bucket do not propagate back to the source bucket. So D, not C
seetpt 👍 1 Selected: AC
ACF for me
MalonJay 👍 3
ADF The secondary also needs to replicate to the primary.
dkp 👍 2 Selected: AC
answer acf
fdoxxx 👍 2 Selected: AC
ACF for sure. A - we need a replication role with principles for S3 Batch Operation, replicate job, and S3. C - will replicate all new objects, F - will replicate existing objects
ogerber 👍 2 Selected: AC
its ACF for me

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

To achieve high availability with no data loss across two regions, the solution must support writes from both sides. Option A provides the necessary IAM permissions for S3 Batch Operations (often used for initial bulk sync) and S3 replication itself. Option C sets up the first leg of the replication (Primary to Secondary). Crucially, Option D ('Create a two-way replication rule') addresses the requirement that data created in the secondary region post-failover must also be replicated back to the primary, preventing data loss. While technically this involves creating rules on both buckets, the option phrasing 'two-way replication rule' is the key discriminator here.

Why the Other Options Are Wrong

Option B references AWS Batch, which is irrelevant for S3 replication tasks. Option E suggests using AWS Batch with Fargate to run CLI sync commands, which is operationally inefficient compared to native S3 features like CRR or S3 Batch Operations. Option D is correct because it explicitly mandates the bidirectional flow required by the scenario.

Community Comment Notes

Many learners initially hesitate on 'two-way replication' because they are taught CRR is unidirectional. However, comments like those from 'that1guy' correctly point out that 'All existing and new objects must be in BOTH S3 buckets' necessitates bidirectional sync. As 'xdkonorek2' noted, unidirectional replication fails if you failover to Region B and then back to A, as data created in B would be lost. The consensus confirms that 'ADF' is the correct combination.

Official Reference

Exam Strategy

When a question specifies 'no data loss' in a multi-region active-active or failover scenario, always look for bidirectional replication options. Standard unidirectional CRR will cause data loss if the secondary region becomes the writer.

Frequently Asked Questions

Why is unidirectional CRR insufficient?

Unidirectional CRR only replicates Primary to Secondary. If the app fails over to Secondary and writes data, that data is not sent back to Primary, causing loss upon return.

Is 'two-way replication rule' a real AWS feature?

Yes, Managed Replication (MRP) supports two-way rules. It automates the creation of replication rules between buckets to keep them in sync bidirectionally.

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide