DOP-C02 Resilient Cloud Solutions Practice Question
A company wants to ensure its data in Amazon S3 is protected against accidental deletion. The bucket stores critical documents. Which approach provides the HIGHEST level of resilience?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable versioning and MFA delete on the bucket.
Enabling versioning and MFA delete provides protection against both accidental overwrites and malicious deletions. Versioning allows recovery of deleted or overwritten objects, while MFA delete adds an extra layer of security by requiring multi-factor authentication for permanent deletions. Option A is incorrect because a bucket policy that denies s3:DeleteObject can prevent deletions but does not allow recovery if the policy is bypassed or changed. Option B is incorrect because lifecycle policies archive objects to Glacier, which reduces costs but does not prevent or recover from accidental deletion. Option D is incorrect because cross-region replication protects against regional failures but does not protect against accidental deletion within the source bucket.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply a bucket policy that denies s3:DeleteObject for all users.
Why it's wrong here
A bucket policy that denies s3:DeleteObject for all users is ineffective as a deletion-protection control because it only blocks direct DeleteObject API calls; it does not stop S3 Lifecycle expiration, which can permanently remove objects without invoking DeleteObject, and any user with s3:PutBucketPolicy or administrative permissions can simply modify or remove the denial. It also degrades operational flexibility by prohibiting legitimate deletes, so it is not a substitute for versioning.
- ✗
Enable S3 lifecycle policies to archive objects to Glacier.
Why it's wrong here
S3 Lifecycle policies are designed for storage-class management and cost optimization, not data protection: they transition objects to S3 Glacier (or other classes) based on age and may include expiration actions that permanently delete objects. Configuring a lifecycle rule to archive to Glacier does not generate a backup or enable versioning, so objects can still be overwritten or deleted with no recovery path. In fact, an incorrectly configured lifecycle expiration rule could actually cause the data loss the company is trying to prevent.
- ✓
Enable versioning and MFA delete on the bucket.
Why this is correct
Enabling versioning on the bucket creates a new version for every object put, overwrite, or delete, so a delete operation only inserts a delete marker that hides old versions rather than purging them; with versioning enabled, you can permanently recover any object version. MFA Delete fortifies this by requiring an MFA code (using root credentials) to permanently delete an object version, suspend versioning, or change the versioning state—thus preventing attackers or accidental admin actions from irreversibly destroying data.
- ✗
Configure cross-region replication (CRR) to another bucket.
Why it's wrong here
Cross-region replication does not stop deletions—it asynchronously copies object changes to another bucket, and if delete markers are replicated (or if version-level deletions are made), the object is effectively gone in both regions. CRR primarily protects against region-level failures and improves latency/availability, but it cannot restore data that was accidentally or maliciously deleted unless versioning is also enabled on both source and destination. Therefore, relying solely on CRR gives a false sense of data protection.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.