Courseiva

DOP-C02 Resilient Cloud Solutions Practice Question

A company wants to ensure that its Amazon S3 bucket is resilient to accidental deletion of objects. Which TWO actions should be taken?

⚠ Common exam trap

Watch out — candidates often confuse S3 Object Lock (which prevents overwrites and deletes during a retention period) with MFA Delete (which requires additional authentication for delete operations), but Object Lock does not protect against accidental bucket deletion or version deletion without MFA, and it is not a direct resilience mechanism for accidental deletion scenarios.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable MFA Delete on the bucket.

Enabling MFA Delete on an S3 bucket requires multi-factor authentication for any delete operations, including object version deletion and bucket deletion. This adds a critical layer of protection against accidental or unauthorized deletions, as the user must present both their AWS credentials and a valid MFA code to perform these destructive actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable MFA Delete on the bucket.

    Why this is correct

    MFA Delete requires an authenticated AWS user to provide both a valid AWS credential and a one-time code from an MFA device before permanently deleting an object version or toggling the versioning state. This effectively blocks accidental or malicious permanent deletion because an attacker who compromises credentials would still need physical access to the MFA token. It is a strong, targeted defense for critical S3 data, especially when combined with versioning.

  • ✗

    Enable S3 Object Lock.

    Why it's wrong here

    S3 Object Lock enforces a WORM (write-once-read-many) retention policy, meaning objects cannot be overwritten or deleted until the retention period expires or a legal hold is removed. Although it does protect against deletion, it is a compliance control designed for regulatory record retention and requires versioning to be enabled, which makes it more complex and rigid than simply enabling versioning. For a general resilience requirement, versioning with MFA Delete offers a more flexible protection without binding the data to a fixed retention timeframe.

  • ✓

    Enable S3 Versioning.

    Why this is correct

    S3 Versioning maintains multiple versions of the same object, so if an object is deleted or overwritten, the previous versions remain available for recovery. Every deletion is recorded as a delete marker rather than removing the underlying data, and any authenticated user with sufficient permission can restore a prior version at any time. This directly provides resilience against both accidental deletion and unintended overwrites, making it a fundamental building block for S3 data protection.

  • ✗

    Enable S3 Transfer Acceleration.

    Why it's wrong here

    S3 Transfer Acceleration uses a globally distributed edge network to upload objects to an S3 bucket faster by routing over Amazon's high-speed backbone instead of the public internet. Its sole purpose is improving upload performance, particularly over long distances, and it has no effect on durability, deletion prevention, or the ability to recover lost data. Enabling it does not add any resilience capability, so it is irrelevant to a requirement focused on protecting the bucket.

  • ✗

    Configure a lifecycle policy to expire objects after 30 days.

    Why it's wrong here

    A lifecycle policy that expires objects after 30 days automatically schedules deletion of objects once they reach that age, which is a data governance or cost-optimization mechanism rather than a resilience safeguard. Far from preventing data loss, this rule actively removes the data and can permanently destroy the only copy if no backup or version retention exists. It would increase, not decrease, the risk of losing critical objects, so it cannot satisfy a resilience requirement.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.