AWS S3 Cross-Region Replication for Multi-Region HA
A company deploys an application in two AWS Regions. The application currently uses an Amazon S3 bucket in the primary Region to store data. A DevOps engineer needs to ensure that the application is highly available in both Regions. The DevOps engineer has created a new S3 bucket in the secondary Region. All existing and new objects must be in both S3 buckets. The application must fail over between the Regions with no data loss. Which combination of steps will meet these requirements with the MOST operational efficiency? (Choose three.)
Community Insight
The exam traps candidates who assume standard unidirectional CRR is sufficient; 'fail over with no data loss' in an active-active context requires two-way replication.
This question tests the configuration of bidirectional Amazon S3 replication to ensure zero data loss during multi-region failover, requiring IAM roles and specific replication rules.
Candidates select A and C, failing to realize that unidirectional replication allows data divergence when the application fails over to the secondary region.
Community Discussion (17 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
To achieve high availability with no data loss across two regions, the solution must support writes from both sides. Option A provides the necessary IAM permissions for S3 Batch Operations (often used for initial bulk sync) and S3 replication itself. Option C sets up the first leg of the replication (Primary to Secondary). Crucially, Option D ('Create a two-way replication rule') addresses the requirement that data created in the secondary region post-failover must also be replicated back to the primary, preventing data loss. While technically this involves creating rules on both buckets, the option phrasing 'two-way replication rule' is the key discriminator here.Why the Other Options Are Wrong
Option B references AWS Batch, which is irrelevant for S3 replication tasks. Option E suggests using AWS Batch with Fargate to run CLI sync commands, which is operationally inefficient compared to native S3 features like CRR or S3 Batch Operations. Option D is correct because it explicitly mandates the bidirectional flow required by the scenario.Community Comment Notes
Many learners initially hesitate on 'two-way replication' because they are taught CRR is unidirectional. However, comments like those from 'that1guy' correctly point out that 'All existing and new objects must be in BOTH S3 buckets' necessitates bidirectional sync. As 'xdkonorek2' noted, unidirectional replication fails if you failover to Region B and then back to A, as data created in B would be lost. The consensus confirms that 'ADF' is the correct combination.Official Reference
Exam Strategy
When a question specifies 'no data loss' in a multi-region active-active or failover scenario, always look for bidirectional replication options. Standard unidirectional CRR will cause data loss if the secondary region becomes the writer.
Frequently Asked Questions
Why is unidirectional CRR insufficient?
Unidirectional CRR only replicates Primary to Secondary. If the app fails over to Secondary and writes data, that data is not sent back to Primary, causing loss upon return.
Is 'two-way replication rule' a real AWS feature?
Yes, Managed Replication (MRP) supports two-way rules. It automates the creation of replication rules between buckets to keep them in sync bidirectionally.
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →