Amazon S3 Complete Guide — CLF-C02 Exam Key Points
Amazon S3 is one of the most frequently tested services on the CLF-C02 exam. Focusing on storage class comparisons, security configurations, versioning, and Snow Family concepts will help you score well.
---
What is Amazon S3?
Amazon S3 (Simple Storage Service) is AWS's flagship object storage service. Files (objects) are stored in containers called buckets, with no capacity limits.
Common use cases include backup and storage, disaster recovery, archiving, static website hosting, data lakes, media hosting, big data analytics, and software distribution.
---
Buckets and Objects
A bucket is the container unit for data in S3. Bucket names must be globally unique across all AWS accounts worldwide and are created in a specific region. Although S3 appears to be a global service in the console, buckets are created at the region level. Naming rules require names to start with a lowercase letter or number, be between 3 and 63 characters, and prohibit underscores (_) and IP-style formats.
| Rule | Details | |------|---------| | Name | Must be globally unique across all accounts | | Region | Buckets are created in a specific region | | Naming rules | Start with lowercase/number, 3–63 characters, no underscores, no IP format |
Objects are identified by a Key — the full path is the key. For example, in , the entire path is the key. S3 has no real directory concept; it is simply a long key name containing slashes (/). The maximum object size is 5 TB, and files larger than 5 GB require multipart upload. Objects can include metadata, tags (up to 10), and version IDs.
---
S3 Security
S3 access control can be configured in several ways. IAM policies allow or deny API calls by specific IAM users or roles. Bucket policies are JSON-based, apply to the entire bucket, and can permit cross-account access. Object ACLs and bucket ACLs provide fine-grained access control at the individual object or bucket level.
| Method | Description | |--------|-------------| | IAM Policy | Allow/deny API calls by specific IAM users/roles | | Bucket Policy | JSON-based, applied to entire bucket, allows cross-account access | | Object ACL | Fine-grained access control at the individual object level | | Bucket ACL | Access control at the bucket level |
Below is an example bucket policy that allows public read access.
By default, all public access is blocked. This is to prevent corporate data leaks. If static website hosting is not working, first check whether public read access is allowed in the bucket policy.
---
Key S3 Features
Versioning
Versioning is enabled at the bucket level. Each time a file is overwritten with the same key, the version number increments, allowing you to restore accidentally deleted files or roll back to a previous version. Files stored before versioning was enabled have a version ID of null. Disabling versioning does not delete previously created versions.
Static Website Hosting (S3 Websites)
S3 can host static websites based on HTML, CSS, and JavaScript. The website URL format is . If you receive a 403 error, check whether public read access is allowed in the bucket policy.
Access Logs
All S3 requests (both allowed and denied) can be saved as logs to another S3 bucket. This is useful for auditing and anomaly pattern analysis.
Replication
Replication comes in two types: CRR (Cross-Region Replication) and SRR (Same-Region Replication). Versioning must be enabled on both the source and destination buckets to use replication.
| Type | Description | Use Case | |------|-------------|----------| | CRR (Cross-Region Replication) | Replicate to a different region | Compliance, lower latency | | SRR (Same-Region Replication) | Replicate within the same region | Log aggregation, test account sync |
---
S3 Storage Classes
Storage class selection questions appear frequently on the CLF-C02 exam. Make sure you understand the characteristics and use cases of each class.
S3 durability is the same for all storage classes at eleven nines (99.999999999%). Availability varies by class.
| Class | Availability | Characteristics | Primary Use Case | |-------|--------------|-----------------|------------------| | S3 Standard | 99.99% | Frequently accessed data, low latency | Big data, mobile apps, content distribution | | S3 Standard-IA | 99.9% | Infrequent access but fast retrieval needed | Disaster recovery, backup | | S3 One Zone-IA | 99.5% | Single AZ storage (data loss if AZ is destroyed) | Reproducible secondary backups | | S3 Glacier Instant | 99.9% | Millisecond retrieval, quarterly access | Medical image archiving | | S3 Glacier Flexible | 99.99% | Minutes to hours retrieval | Long-term backup archive | | S3 Glacier Deep Archive | 99.99% | Lowest cost, 12–48 hour retrieval | Long-term compliance storage (7–10 years) | | S3 Intelligent-Tiering | 99.9% | Automatic tier movement based on access patterns | Unpredictable access pattern data |
S3 Glacier Flexible retrieval options are Expedited (1–5 minutes), Standard (3–5 hours), and Bulk (5–12 hours). S3 Glacier Deep Archive takes 12 hours for Standard retrieval and 48 hours for Bulk retrieval.
Minimum storage duration is also an important exam point.
| Class | Minimum Storage Duration | |-------|---------------------------| | Glacier Instant / Flexible | 90 days | | Glacier Deep Archive | 180 days |
Key points that frequently appear on the exam:
The cheapest storage class for long-term retention is Glacier Deep Archive. Intelligent-Tiering automatically moves objects between tiers based on access patterns with no retrieval fees. One Zone-IA stores data in a single AZ, so data loss is possible in the event of an AZ failure.
---
S3 Object Lock and Glacier Vault Lock
S3 Object Lock blocks deletion of object versions for a specified period. Glacier Vault Lock locks the policy itself, making changes impossible. Both features implement the WORM (Write Once Read Many) model — once written, data cannot be modified or deleted. These are used in environments requiring regulatory compliance or data retention.
| Feature | Description | Model | |---------|-------------|-------| | S3 Object Lock | Blocks deletion of object versions for a specified period | WORM | | Glacier Vault Lock | Locks policy to prevent changes (compliance) | WORM |
---
AWS Snow Family
When transferring data over the network would take too long, the AWS Snow Family provides physical device-based data migration services.
The table below shows estimated network transfer times by data size.
| Data Size | 100Mbps | 1Gbps | 10Gbps | |-----------|---------|-------|--------| | 10TB | 12 days | 30 hours | 3 hours | | 100TB | 124 days | 12 days | 30 hours | | 1PB | 3 years | 124 days | 12 days |
If network transfer would take more than a week, using a Snowball device is appropriate.
Snow Family Device Comparison
| Device | Storage | Migration Scale | Characteristics | |--------|---------|-----------------|-----------------| | Snowcone | 8TB | Up to 24TB | Ultra-compact (2.1 kg), usable in harsh environments | | Snowball Edge Storage Optimized | 80TB | Petabyte-scale | Block + S3-compatible storage | | Snowball Edge Compute Optimized | 42TB | Petabyte-scale | 52 vCPU, GPU option (ML, video processing) | | Snowmobile | 100PB/unit | Exabyte-scale | Truck form factor, more efficient than Snowball above 10PB |
Edge Computing
When data needs to be processed on-site in environments with limited internet or power access (moving trucks, ships, mines, etc.), Snow devices can be used. Snowcone and Snowball Edge can run EC2 instances and Lambda functions, and are used for preprocessing, edge ML, and media transcoding.
AWS OpsHub
AWS OpsHub is desktop software that allows you to manage Snow Family devices through a GUI without using the CLI.
---
AWS Storage Gateway (Hybrid Cloud)
AWS Storage Gateway is a hybrid storage service that connects on-premises environments to AWS cloud storage. Because S3 uses proprietary technology, it cannot be used directly from on-premises environments — Storage Gateway solves this problem. It is used in disaster recovery, backup, and tiered storage scenarios, and comes in File Gateway, Volume Gateway, and Tape Gateway types.
---
Shared Responsibility Model for S3
Responsibilities are divided between AWS and the customer for S3 as well. AWS is responsible for global infrastructure security, guaranteeing durability and availability, compliance validation, and vulnerability analysis. Customers are responsible for S3 versioning configuration, bucket policy and access control setup, replication configuration, and data encryption (at rest and in transit).