DEA-C01 Data Security and Governance Practice Question
A data engineer needs to ensure that data stored in Amazon S3 is automatically deleted after 30 days. Which S3 feature should be used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
S3 Lifecycle policy
S3 Lifecycle policies can automatically delete objects after a specified time period, such as 30 days. Option B (MFA Delete) requires multi-factor authentication for deletion but does not automate deletion. Option C (Versioning) keeps multiple versions but does not delete. Option D (Object Lock) prevents deletion or modification but does not schedule automatic deletion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
S3 Lifecycle policy
Why this is correct
An S3 Lifecycle policy defines expiration rules that automatically delete objects after a specified number of days, directly meeting the 30-day deletion requirement. It applies at bucket or prefix level without custom code, unlike versioning or replication, which retain data rather than remove it.
- ✗
S3 MFA Delete
Why it's wrong here
MFA Delete adds an authentication requirement before versioned objects can be permanently deleted; it does not delete anything automatically. It is tempting because it concerns deletion control, but scheduled removal after 30 days is performed by an S3 Lifecycle expiration policy.
- ✗
S3 Versioning
Why it's wrong here
Versioning retains multiple object versions and protects against overwrites and deletes; it never expires objects on a schedule. It is tempting because it governs object lifecycle behaviour, but automatic deletion after 30 days requires an S3 Lifecycle expiration rule.
- ✗
S3 Object Lock
Why it's wrong here
Object Lock enforces WORM retention that prevents deletion for a fixed period, directly opposing the 30-day deletion requirement. It is tempting because it also uses time-based retention settings, but it is designed for compliance immutability, not scheduled expiry.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.