Abort the Glacier vault lock, fix the policy, and initiate the lock again

Answer Correct answer: A — abort the vault lock, fix the policy, and initiate the lock again during the waiting period.

A company is storing data in Amazon S3 Glacier. A security engineer implemented a new vault lock policy for 10 TB of data and called the initiate-vault-lock operation 12 hours ago. The audit team identified a typo in the policy that is allowing unintended access to the vault. What is the MOST cost-effective way to correct this error?

  1. Call the abort-vault-lock operation. Update the policy. Call the initiate-vault-lock operation again. Correct Answer
  2. Copy the vault data to a new S3 bucket. Delete the vault Create a new vault with the data.
  3. Update the policy to keep the vault lock in place.
  4. Update the policy. Call the initiate-vault-lock operation again to apply the new policy.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

During the Vault Lock waiting period the policy is not yet locked, so abort-vault-lock cancels it cheaply; you then fix and re-initiate. Copying 10 TB to a new S3 bucket and recreating the vault (B) is far more expensive and slow. Options C/D that just 'update the policy' while a lock is pending do not apply the corrected policy correctly. A is the cost-effective path.

A Glacier Vault Lock was initiated 12 hours ago but has a typo allowing unintended access. Vault Lock has a lock-in waiting period before the policy becomes immutable; while still in that window, the most cost-effective fix is to call abort-vault-lock, correct the policy, and initiate-vault-lock again—no data copy or new vault needed.

Copying the vault data to a new bucket and recreating the vault (B)—10 TB of egress/copy is costly and slow versus simply aborting the pending lock. Assuming you can edit the policy in place during the waiting period (C/D)—the initiate step must be re-run after correction; A is the proper sequence.

Community Discussion (3 comments)

Pat9595 👍 1 Selected: A
A. Call the abort-vault-lock operation. Update the policy. Call the initiate-vault-lock operation again. ✅ Why? The S3 Glacier Vault Lock feature has a lock-in period before the policy becomes immutable. The "initiate-vault-lock" operation starts a 24-hour window where the policy can still be modified or aborted. Since the vault lock was initiated only 12 hours ago, you can still abort it, correct the policy, and restart the process without extra cost.
IPLogic 👍 1 Selected: A
The most cost-effective way to correct the error is: A. Call the abort-vault-lock operation. Update the policy. Call the initiate-vault-lock operation again. Since the vault lock policy is still in the “InProgress” state, you can abort the lock operation, correct the typo in the policy, and then initiate the vault lock operation again. This approach avoids the need to move large amounts of data or create new vaults, making it the most efficient solution.
Bad_Mat 👍 1
The answer is A

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

S3 Glacier Vault Lock enforces a lock-in waiting period before a policy becomes immutable. Because the lock was initiated only 12 hours ago, it is still within that window, so abort-vault-lock cancels the pending lock at no data cost; you correct the policy and call initiate-vault-lock again. This is the most cost-effective correction.

Why the Other Options Are Wrong

B copies 10 TB of data to a new bucket and recreates the vault, which is expensive and slow compared with aborting the pending lock. C and D try to update the policy while a lock is pending without re-running the proper abort/revise/initiate sequence, so the typo is not cleanly fixed. A is correct.

Community Comment Notes

Community voted A (100). Commenters explained the Vault Lock waiting period lets you abort before lock-in, then update and re-initiate—far cheaper than copying 10 TB to a new vault. A confirmed.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide