DOP-C02 Resilient Cloud Solutions Practice Question
A company wants to ensure that its Amazon S3 bucket is resilient to accidental deletion of objects. Which TWO actions should be taken?
⚠ Common exam trap
Watch out — candidates often confuse S3 Object Lock (which prevents overwrites and deletes during a retention period) with MFA Delete (which requires additional authentication for delete operations), but Object Lock does not protect against accidental bucket deletion or version deletion without MFA, and it is not a direct resilience mechanism for accidental deletion scenarios.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable MFA Delete on the bucket.
Enabling MFA Delete on an S3 bucket requires multi-factor authentication for any delete operations, including object version deletion and bucket deletion. This adds a critical layer of protection against accidental or unauthorized deletions, as the user must present both their AWS credentials and a valid MFA code to perform these destructive actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable MFA Delete on the bucket.
Why this is correct
MFA Delete requires an authenticated AWS user to provide both a valid AWS credential and a one-time code from an MFA device before permanently deleting an object version or toggling the versioning state. This effectively blocks accidental or malicious permanent deletion because an attacker who compromises credentials would still need physical access to the MFA token. It is a strong, targeted defense for critical S3 data, especially when combined with versioning.
- ✗
Enable S3 Object Lock.
Why it's wrong here
S3 Object Lock enforces a WORM (write-once-read-many) retention policy, meaning objects cannot be overwritten or deleted until the retention period expires or a legal hold is removed. Although it does protect against deletion, it is a compliance control designed for regulatory record retention and requires versioning to be enabled, which makes it more complex and rigid than simply enabling versioning. For a general resilience requirement, versioning with MFA Delete offers a more flexible protection without binding the data to a fixed retention timeframe.
- ✓
Enable S3 Versioning.
Why this is correct
S3 Versioning maintains multiple versions of the same object, so if an object is deleted or overwritten, the previous versions remain available for recovery. Every deletion is recorded as a delete marker rather than removing the underlying data, and any authenticated user with sufficient permission can restore a prior version at any time. This directly provides resilience against both accidental deletion and unintended overwrites, making it a fundamental building block for S3 data protection.
- ✗
Enable S3 Transfer Acceleration.
Why it's wrong here
S3 Transfer Acceleration uses a globally distributed edge network to upload objects to an S3 bucket faster by routing over Amazon's high-speed backbone instead of the public internet. Its sole purpose is improving upload performance, particularly over long distances, and it has no effect on durability, deletion prevention, or the ability to recover lost data. Enabling it does not add any resilience capability, so it is irrelevant to a requirement focused on protecting the bucket.
- ✗
Configure a lifecycle policy to expire objects after 30 days.
Why it's wrong here
A lifecycle policy that expires objects after 30 days automatically schedules deletion of objects once they reach that age, which is a data governance or cost-optimization mechanism rather than a resilience safeguard. Far from preventing data loss, this rule actively removes the data and can permanently destroy the only copy if no backup or version retention exists. It would increase, not decrease, the risk of losing critical objects, so it cannot satisfy a resilience requirement.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.