DOP-C02 Resilient Cloud Solutions Practice Question
A company uses a third-party backup solution to back up its EC2 instances daily. The backups are stored in an S3 bucket with default settings. The company wants to ensure that backups are protected from accidental deletion and are available for at least one year. Which combination of S3 features should the DevOps engineer implement?
⚠ Common exam trap
Many exam-takers confuse versioning with immutability, assuming that versioning alone prevents deletion, but versioning only creates multiple versions and does not prevent the current version from being deleted (it becomes a delete marker), whereas S3 Object Lock provides true immutability by preventing any deletion or overwrite during the retention period.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable S3 Object Lock with Governance mode and a retention period of 365 days, and set a lifecycle policy to transition to S3 Glacier Deep Archive after 30 days.
S3 Object Lock with Governance mode prevents objects from being deleted or overwritten by any user (including the root user) for the specified retention period of 365 days, meeting the one-year availability requirement. The lifecycle policy to transition to S3 Glacier Deep Archive after 30 days reduces storage costs while still keeping the data accessible for retrieval within 12 hours, which is acceptable for backup retention. This combination ensures immutability and cost-effective long-term storage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable MFA Delete and set a lifecycle policy to transition to S3 Glacier after 30 days.
Why it's wrong here
Enabling MFA Delete requires every permanently destructive operation (such as deleting an object version or suspending versioning) to be authenticated with a second factor, but it does not prevent an authorized user from deleting the current version of an object—it only adds an extra authentication step, which is impractical to automate and does not provide a retention guarantee. Additionally, transitioning to S3 Glacier (Standard) after 30 days does nothing to protect the object from being deleted during that 30-day window or even after the transition, since lifecycle policies only move data between storage classes and never grant immutability.
- ✗
Enable versioning and set a lifecycle policy to expire noncurrent versions after 365 days.
Why it's wrong here
Versioning preserves every object version, but the protection is only against overwriting the current version; a user with Versioned Delete permission can still permanently delete both the current and all noncurrent versions. The lifecycle rule that expires noncurrent versions after 365 days automates cleanup of old versions but does not in any way protect the current version, which remains fully deletable at any time. Moreover, if a delete marker is created, the object is effectively 'deleted' even though the underlying version remains until lifecycle expiry, so versioning alone cannot stop a malicious actor from removing the live copy of your backup data.
- ✗
Enable cross-Region replication to a bucket with versioning enabled.
Why it's wrong here
Cross-Region Replication (CRR) asynchronously copies objects to a destination bucket, but the source bucket remains a standard, mutable S3 bucket—any user with s3:DeleteObject permission can delete the object from the source, and with versioned bucket configuration also delete or add delete markers to versions. The destination bucket, even if versioning is enabled, is still an ordinary bucket; a user with permissions there can permanently purge both source-replicated copies and any version history. Finally, CRR does not apply any retention or governance controls, so it offers no protection against accidental, malicious, or ransomware-based deletion—it is simply a data availability feature, not a data protection feature.
- ✓
Enable S3 Object Lock with Governance mode and a retention period of 365 days, and set a lifecycle policy to transition to S3 Glacier Deep Archive after 30 days.
Why this is correct
S3 Object Lock with Governance mode applies a Write-Once-Read-Many (WORM) policy that guarantees the backup objects cannot be modified or deleted by any ordinary user—even an account administrator with full S3 access—until the 365-day retention period expires. Governance mode does allow users with the s3:BypassGovernanceRetention permission to override the lock if needed, but a typical backup scenario doesn't grant that to regular IAM roles, so the data remains immutable for the entire year. Pairing this with a lifecycle rule that transitions the objects to S3 Glacier Deep Archive after 30 days satisfies both the need for protection and cost efficiency: the transition preserves Object Lock metadata and the object stays protected through the transition, after which Storage Costs drop to the lowest tier while retention still applies for the remaining 335 days.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.