Courseiva
Resilient Cloud Solutions →mediumMultiple Choice

DOP-C02 Resilient Cloud Solutions Practice Question

A company uses a third-party backup solution to back up its EC2 instances daily. The backups are stored in an S3 bucket with default settings. The company wants to ensure that backups are protected from accidental deletion and are available for at least one year. Which combination of S3 features should the DevOps engineer implement?

⚠ Common exam trap

Many exam-takers confuse versioning with immutability, assuming that versioning alone prevents deletion, but versioning only creates multiple versions and does not prevent the current version from being deleted (it becomes a delete marker), whereas S3 Object Lock provides true immutability by preventing any deletion or overwrite during the retention period.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable S3 Object Lock with Governance mode and a retention period of 365 days, and set a lifecycle policy to transition to S3 Glacier Deep Archive after 30 days.

S3 Object Lock with Governance mode prevents objects from being deleted or overwritten by any user (including the root user) for the specified retention period of 365 days, meeting the one-year availability requirement. The lifecycle policy to transition to S3 Glacier Deep Archive after 30 days reduces storage costs while still keeping the data accessible for retrieval within 12 hours, which is acceptable for backup retention. This combination ensures immutability and cost-effective long-term storage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable MFA Delete and set a lifecycle policy to transition to S3 Glacier after 30 days.

    Why it's wrong here

    Enabling MFA Delete requires every permanently destructive operation (such as deleting an object version or suspending versioning) to be authenticated with a second factor, but it does not prevent an authorized user from deleting the current version of an object—it only adds an extra authentication step, which is impractical to automate and does not provide a retention guarantee. Additionally, transitioning to S3 Glacier (Standard) after 30 days does nothing to protect the object from being deleted during that 30-day window or even after the transition, since lifecycle policies only move data between storage classes and never grant immutability.

  • ✗

    Enable versioning and set a lifecycle policy to expire noncurrent versions after 365 days.

    Why it's wrong here

    Versioning preserves every object version, but the protection is only against overwriting the current version; a user with Versioned Delete permission can still permanently delete both the current and all noncurrent versions. The lifecycle rule that expires noncurrent versions after 365 days automates cleanup of old versions but does not in any way protect the current version, which remains fully deletable at any time. Moreover, if a delete marker is created, the object is effectively 'deleted' even though the underlying version remains until lifecycle expiry, so versioning alone cannot stop a malicious actor from removing the live copy of your backup data.

  • ✗

    Enable cross-Region replication to a bucket with versioning enabled.

    Why it's wrong here

    Cross-Region Replication (CRR) asynchronously copies objects to a destination bucket, but the source bucket remains a standard, mutable S3 bucket—any user with s3:DeleteObject permission can delete the object from the source, and with versioned bucket configuration also delete or add delete markers to versions. The destination bucket, even if versioning is enabled, is still an ordinary bucket; a user with permissions there can permanently purge both source-replicated copies and any version history. Finally, CRR does not apply any retention or governance controls, so it offers no protection against accidental, malicious, or ransomware-based deletion—it is simply a data availability feature, not a data protection feature.

  • ✓

    Enable S3 Object Lock with Governance mode and a retention period of 365 days, and set a lifecycle policy to transition to S3 Glacier Deep Archive after 30 days.

    Why this is correct

    S3 Object Lock with Governance mode applies a Write-Once-Read-Many (WORM) policy that guarantees the backup objects cannot be modified or deleted by any ordinary user—even an account administrator with full S3 access—until the 365-day retention period expires. Governance mode does allow users with the s3:BypassGovernanceRetention permission to override the lock if needed, but a typical backup scenario doesn't grant that to regular IAM roles, so the data remains immutable for the entire year. Pairing this with a lifecycle rule that transitions the objects to S3 Glacier Deep Archive after 30 days satisfies both the need for protection and cost efficiency: the transition preserves Object Lock metadata and the object stays protected through the transition, after which Storage Costs drop to the lowest tier while retention still applies for the remaining 335 days.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.