Storage
Amazon S3 essentials
Amazon Simple Storage Service (S3) is object storage with practically unlimited capacity and very high durability. It is one of the most tested services on the exam, across every domain.
Basics
- Data is stored as objects (data + metadata) in buckets, identified by a key (e.g.
invoices/2026/08/42.pdf). - Bucket names are globally unique; buckets live in a Region.
- Objects can be up to 5 TB. A single PUT uploads up to 5 GB; use multipart upload for large objects (recommended above ~100 MB, required above 5 GB).
- Designed for 99.999999999% (11 nines) durability — data is stored redundantly across multiple AZs (except One Zone classes).
- Strong read-after-write consistency for all operations.
Storage classes
| Class | Availability design | Min. storage duration | Retrieval | Best for |
|---|---|---|---|---|
| S3 Standard | Multi-AZ | — | Milliseconds | Frequently accessed data |
| S3 Intelligent-Tiering | Multi-AZ | — | Milliseconds (optional archive tiers slower) | Unknown or changing access patterns — moves objects between tiers automatically; small monitoring fee, no retrieval fees |
| S3 Standard-IA | Multi-AZ | 30 days | Milliseconds, per-GB retrieval fee | Infrequent but immediate access (backups, older data) |
| S3 One Zone-IA | Single AZ | 30 days | Milliseconds, retrieval fee | Re-creatable infrequent data (secondary copies, thumbnails) |
| S3 Glacier Instant Retrieval | Multi-AZ | 90 days | Milliseconds | Archives accessed about once a quarter, needing instant access |
| S3 Glacier Flexible Retrieval | Multi-AZ | 90 days | Expedited 1–5 min, Standard 3–5 h, Bulk 5–12 h | Archives accessed rarely, flexible wait |
| S3 Glacier Deep Archive | Multi-AZ | 180 days | Standard within 12 h, Bulk within 48 h | Lowest cost long-term retention (compliance, 7–10 year archives) |
| S3 Express One Zone | Single AZ (directory buckets) | — | Single-digit milliseconds | Highest-performance, latency-sensitive workloads (ML, analytics) |
IA classes have a minimum billable object size of 128 KB; early deletion before the minimum duration is charged as if stored for the full period.
Key idea
Unknown access pattern → Intelligent-Tiering. Rare access, can wait hours → Glacier Flexible Retrieval. Cheapest possible archive, can wait up to 12–48 hours → Glacier Deep Archive. Rare access but needs milliseconds → Glacier Instant Retrieval.
Lifecycle rules
Automate transitions and expirations by prefix or tag:
Day 0 → S3 Standard
Day 30 → S3 Standard-IA
Day 90 → S3 Glacier Flexible Retrieval
Day 365 → S3 Glacier Deep Archive
Day 2555 → Expire (delete) — e.g. 7-year retention
Also: expire old noncurrent versions, and abort incomplete multipart uploads (they otherwise cost money silently).
Versioning
- Keeps every version of an object; deletes add a delete marker (recoverable).
- Protects against accidental overwrites and deletions.
- Once enabled, can only be suspended, not removed.
- Required for replication and Object Lock.
- MFA Delete can require MFA to permanently delete versions or change versioning state.
Replication
| Cross-Region Replication (CRR) | Same-Region Replication (SRR) | |
|---|---|---|
| Use | DR, compliance, lower latency in another Region | Log aggregation, prod → test copies, data sovereignty within a Region |
- Requires versioning on source and destination; can replicate to another account and change storage class or ownership.
- Only new objects replicate by default — use S3 Batch Replication for existing objects.
- Replication Time Control (RTC) — SLA-backed replication of most objects within 15 minutes.
Performance
- At least 3,500 PUT/COPY/POST/DELETE and 5,500 GET/HEAD requests per second per prefix — spread keys across prefixes for higher aggregate throughput.
- Multipart upload — parallel parts for faster, resumable uploads.
- Byte-range fetches — parallel downloads of parts of an object.
- S3 Transfer Acceleration — faster uploads from distant clients via edge locations.
- CloudFront — faster downloads for global users.
Other features worth knowing
| Feature | Purpose |
|---|---|
| Event notifications | Trigger Lambda, SQS, SNS or EventBridge on object create/delete |
| Pre-signed URLs | Temporary access to upload or download a private object without AWS credentials |
| Static website hosting | Serve a website from a bucket (use CloudFront for HTTPS and performance) |
| Requester Pays | The downloader pays request and transfer costs (sharing large datasets) |
| Object Lock | WORM retention — governance mode (privileged users can override) or compliance mode (no one, not even root, can delete until retention ends); plus legal holds |
| S3 Inventory / Storage Lens | Reports and analytics on objects and usage |
| S3 Batch Operations | Run an action on billions of objects (copy, tag, restore, invoke Lambda) |
| S3 Object Lambda | Transform objects as they're retrieved (e.g. redact PII) |
Exam patterns
- "Data accessed frequently for 30 days, rarely afterwards, kept 7 years" → lifecycle: Standard → Standard-IA/Glacier → Deep Archive → expire.
- "Protect objects from accidental deletion" → versioning (+ MFA Delete).
- "Records must be immutable for 7 years for regulators" → Object Lock in compliance mode.
- "Users upload directly to S3 from the browser securely" → pre-signed URLs.
- "Copy objects to another Region automatically for DR" → Cross-Region Replication.