DEA-C01 Data Store Management Practice Question
A company stores application logs in an Amazon S3 bucket. A compliance policy states that log objects must be retained for exactly 90 days and then permanently deleted, and that no one, including administrators, should be able to delete them earlier. The data engineer must enforce this with the least effort. What should the engineer do?
⚠ Common exam trap
The trap here is treating versioning or lifecycle transitions as immutability controls, when only Object Lock in compliance mode prevents deletion by any principal during the retention period.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply an S3 Object Lock retention period of 90 days in compliance mode to the bucket, and configure a lifecycle rule to expire objects after 90 days.
S3 Object Lock in compliance mode provides WORM protection that even the root user cannot override before the retention period ends, which satisfies the immutability requirement. Pairing it with a lifecycle rule that expires objects after 90 days ensures automatic permanent deletion at the required time. Together they enforce the compliance policy with minimal operational effort.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an S3 Lifecycle rule that transitions objects to S3 Glacier Deep Archive after 90 days.
Why it's wrong here
Transitioning to Glacier Deep Archive moves objects to cheaper storage but does not delete them, so the retention requirement is not met. It also does not prevent administrators from deleting objects earlier. This option addresses cost, not the mandated permanent deletion after 90 days.
- ✓
Apply an S3 Object Lock retention period of 90 days in compliance mode to the bucket, and configure a lifecycle rule to expire objects after 90 days.
Why this is correct
S3 Object Lock in compliance mode prevents any user, including the root user, from deleting or overwriting an object version until the retention period expires. Setting a 90-day retention plus a lifecycle expiration rule enforces both the immutability and the automatic deletion after 90 days, satisfying the policy with minimal ongoing effort.
- ✗
Use AWS Backup to create a vault with a 90-day retention and a vault lock in compliance mode.
Why it's wrong here
AWS Backup vault lock can enforce retention on backups, but the primary log objects in S3 are not protected from deletion by users. This adds a backup copy rather than enforcing immutability on the live objects, and it does not automatically delete the source objects after 90 days. It is more complex than necessary.
- ✗
Enable S3 Versioning and add a bucket policy that denies s3:DeleteObject to all principals.
Why it's wrong here
Versioning retains prior versions but does not prevent deletion of current objects or versions, and a deny policy can be modified by an administrator. It also does not automatically delete objects after 90 days. This approach fails both the immutability and the automated expiration requirements.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.