15 questions selected from source version V8.02
VEEAM CERTIFIED ENGINEER PLUS
Question 1
Scenario: A company is configuring a Scale-Out Backup Repository (SOBR) with an Amazon S3 bucket as
the Capacity Tier. They want to ensure that data is completely protected from malicious deletion and strictly
follows Veeam's immutable best practices.
Which two settings must be configured across the AWS S3 bucket and the VBR console to successfully
enable Capacity Tier immutability? (Choose two)
A. The Amazon S3 bucket must have both Versioning and Object Lock enabled at the exact time of bucket
creation.
B. The "Make recent backups immutable" checkbox must be explicitly enabled within the Veeam Add
External Repository wizard.
C. The assigned AWS IAM user must strictly utilize the s3: BypassGovernanceRetention permission to allow
VBR to write data blocks.
D. The SOBR performance tier must be formatted with the XFS or ReFS file system to successfully pass the
immutable flags to the cloud tier.
E. The Veeam Backup & Replication server must install the AWS CLI software locally to execute the required
immutability API calls.
Answer: A, B
Explanation
Correct Logic (A, B): To support immutability in an AWS S3 Capacity Tier, the S3 bucket must be created with both
Versioning and Object Lock enabled from day one (AWS restriction). Furthermore, inside the VBR console, the administrator
must check the "Make recent backups immutable" option and specify the retention period in days when adding the object
storage repository. Veeam then manages the Object Lock compliance mode natively via its API integration.
Teardown of Distractors:
C is incorrect: Veeam uses Compliance mode, not Governance mode, for Object Lock. Providing bypass permissions defeats
the purpose of strict immutability.
D is incorrect: The file system of the local Performance Tier (ext4, NTFS, XFS, ReFS) has absolutely zero dependency or
impact on the object storage Capacity Tier's ability to use S3 Object Lock.
E is incorrect: VBR has native AWS S3 REST API integration built directly into its core services. It does not require or use the
AWS CLI tool to function.
Page 2