Courseiva

DEA-C01 Data Security and Governance Practice Question

A company stores regulated records in an Amazon S3 bucket and must prove that individual objects cannot be deleted or overwritten for 365 days after creation, even by the account root user. The compliance team also needs to retain the ability to delete the bucket itself after the retention window expires. Which configuration meets these requirements?

⚠ Common exam trap

Test-takers frequently confuse governance mode with compliance mode, when only compliance mode is immune to privileged deletion and retention changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable S3 Versioning and apply an S3 Object Lock default retention rule in compliance mode with a 365-day period.

S3 Object Lock in compliance mode provides write-once-read-many protection that no principal, including the root user, can override before the retention date. A default retention rule applies the period automatically to newly created object versions. Since the lock applies to object versions, the bucket itself can still be deleted after retention lapses and versions are removed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable S3 Versioning and apply an S3 Object Lock default retention rule in compliance mode with a 365-day period.

    Why this is correct

    Object Lock in compliance mode prevents any principal, including the root user, from deleting or overwriting a protected object version until the retain-until date passes. A default retention rule applies the 365-day period automatically to new objects. Because the lock protects object versions rather than the bucket, the bucket can still be removed once all versions age out and are deleted.

  • ✗

    Enable S3 Object Lock in governance mode with a 365-day retention period and grant s3:BypassGovernanceRetention to the security team.

    Why it's wrong here

    Governance mode allows users with the bypass permission to delete or alter retention, so it cannot guarantee that the root user or privileged operators are unable to remove objects. The requirement states objects must be protected even from the root user, which only compliance mode enforces. Governance mode is appropriate when some administrators must retain override capability.

  • ✗

    Apply a bucket policy that denies s3:DeleteObject and s3:PutObject to all principals for 365 days using a date condition.

    Why it's wrong here

    A bucket policy deny can be modified or removed by an administrator, so it does not provide the immutability the compliance team requires against privileged users. It also blocks writes rather than protecting existing versions, and it cannot enforce per-object retention based on each object's creation time. Object Lock is the only S3 feature that makes retention tamper-proof.

  • ✗

    Enable S3 Versioning and add a lifecycle rule that transitions objects to S3 Glacier Deep Archive after 365 days.

    Why it's wrong here

    Lifecycle transitions change the storage class of objects; they do not prevent deletion or overwriting. A user with delete permissions could still remove object versions during the retention period. This configuration addresses cost optimization rather than immutability, so it fails the core requirement of protecting records for a fixed period regardless of caller identity.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.