Enable S3 Replication Time Control, create an S3 Multi-Region Access Point, and submit its routes on failover
A company runs an application that uses an Amazon S3 bucket to store images. A DevOps engineer needs to implement a multi-Region strategy for the objects that are stored in the S3 bucket. The company needs to be able to fail over to an S3 bucket in another AWS Region. When an image is added to either S3 bucket, the image must be replicated to the other S3 bucket within 15 minutes. The DevOps engineer enables two-way replication between the S3 buckets. Which combination of steps should the DevOps engineer take next to meet the requirements? (Choose three.)
Community Votes
100% of anonymous learners picked answer ABC. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The 15-minute requirement maps specifically to S3 Replication Time Control, which commits to replicating objects within that window (A). Failover without changing application endpoints maps to a Multi-Region Access Point in active-passive configuration (B), and because it is active-passive the traffic routing must be switched explicitly, which is what the SubmitMultiRegionAccessPointRoutes operation does (C). Option E's Route 53 Recovery Controller routing control is a DNS-layer mechanism and does not control S3 Multi-Region Access Point routing, and option D's Transfer Accelerator addresses client upload bandwidth rather than replication speed.
The requirement is a 15-minute replication guarantee between two buckets and the ability to fail over to the bucket in the other Region. Enabling S3 Replication Time Control on each replication rule provides the 15-minute commitment. Creating an S3 Multi-Region Access Point in an active-passive configuration gives a single endpoint that fronts both buckets, and when failover is needed the SubmitMultiRegionAccessPointRoutes operation switches the routing so traffic goes to the surviving bucket. Together these deliver both the replication objective and the controlled failover.
Enabling S3 Transfer Acceleration on both buckets (D) — TEC1's reasoning separates the concerns, and Transfer Acceleration speeds up transfers between clients and S3 over long distances; it does not affect how quickly objects replicate between buckets, so it cannot satisfy the 15-minute replication requirement. Configuring a routing control in Amazon Route 53 Recovery Controller with the buckets in active-passive configuration (E) — trungtd noted that UpdateRoutingControlStates is a Route 53 mechanism, and Route 53 routing controls govern DNS failover for endpoints, not Multi-Region Access Point bucket routing, so the wrong control plane is being used for S3 failover. Enabling Replication Time Control is what provides the 15-minute guarantee, as TEC1 described.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Three steps are needed to satisfy the two requirements. First, the objects must replicate between the buckets within fifteen minutes of being added to either, and that commitment is provided by S3 Replication Time Control, which is enabled on each replication rule and monitors replication to guarantee objects arrive within the fifteen-minute window (A). Second, the application needs a way to reach whichever bucket is currently serving without changing endpoints, which an S3 Multi-Region Access Point provides; configuring it in active-passive configuration means one Region serves traffic while the other stands by (B). Third, because the configuration is active-passive, moving traffic during a failover requires an explicit routing change, which is performed by calling the SubmitMultiRegionAccessPointRoutes operation with the desired Region (C). A, B, and C are the correct combination.Why the Other Options Are Wrong
D enables S3 Transfer Acceleration on both S3 buckets. Transfer Acceleration uses edge locations to speed up transfers between clients and S3 over long distances; it has no effect on how quickly an object replicates from one bucket to another, so it cannot satisfy the fifteen-minute replication requirement. As TEC1 distinguished, Replication Time Control is what guarantees the fifteen-minute window. E configures a routing control in Amazon Route 53 Recovery Controller and adds the S3 buckets in an active-passive configuration. Route 53 Recovery Controller routing controls govern DNS failover for endpoints such as load balancers, not Multi-Region Access Point bucket routing; trungtd noted that UpdateRoutingControlStates is the Route 53 mechanism, so using it to switch S3 Multi-Region Access Point traffic controls the wrong layer. A, B, and C are correct.Community Comment Notes
Community voted A,B,C unanimously. TEC1 explained that enabling Replication Time Control on each rule guarantees objects are replicated within fifteen minutes and that the active-passive Multi-Region Access Point plus route submission provides the failover. jamesf and getadroit both cited the AWS getting-started guide for Amazon S3 Multi-Region Access Points. DKM supplied the exact aws s3control submit-multi-region-access-point-routes invocation with the route-updates payload. trungtd distinguished the Route 53 mechanism from the S3 one. No alternative received support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →