Courseiva

Two Actions to Prevent Accidental S3 Bucket Deletion: MFA Delete and Deny DeleteBucket

A company wants to protect its S3 bucket data from accidental deletion or overwrite. Which feature should be enabled?

⚠ Common exam trap

The trap is assuming MFA Delete or a deny-DeleteObject bucket policy is the primary protection — both are secondary controls that depend on versioning already being enabled.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable S3 Versioning

S3 Versioning preserves every prior version of an object, so an accidental overwrite creates a new version while the original remains recoverable, and an accidental delete inserts a delete marker rather than removing data. This directly satisfies the requirement to protect against both accidental deletion and overwrite without blocking legitimate writes. Versioning is the foundational control that MFA Delete and replication build upon.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable cross-region replication

    Why it's wrong here

    Cross-region replication (CRR) copies objects to a destination bucket in another AWS Region, but it replicates the current state of each object. If an object is accidentally overwritten or deleted, that destructive change is also replicated to the destination, so it does not provide rollback or protection against logical corruption. CRR is designed for geographic resilience, latency reduction, or compliance, not as a bulwark against accidental modifications in the source bucket.

  • ✗

    Apply a bucket policy that denies DeleteObject

    Why it's wrong here

    A bucket policy that denies s3:DeleteObject can block explicit delete API calls, but S3 overwrites are performed via s3:PutObject, not DeleteObject. An accidental PUT of an object with the same key will silently replace the existing data, and the original bytes are unrecoverable unless another protection mechanism, such as versioning or object lock, retains prior content. Additionally, a deny-only policy can be bypassed by the root user with explicit allow permissions unless combined with an SCP, making it an incomplete safety measure.

  • ✓

    Enable S3 Versioning

    Why this is correct

    Enabling S3 Versioning is the correct first-line protection because it retains every version of an object, including the original, whenever an overwrite (PUT) or delete (DELETE) occurs. With versioning, an overwritten object's previous version is preserved as a non-current version, and a DELETE action only inserts a deletemarker, leaving all prior versions intact. You can recover accidental changes by simply fetching a previous version, making it the foundational mechanism that enables other features like lifecycle rules, MFA Delete, and point-in-time restores.

  • ✗

    Enable MFA Delete

    Why it's wrong here

    MFA Delete is a powerful additional layer that requires multi-factor authentication to permanently delete versions or suspend versioning, but it is not a primary data-protection feature on its own. If versioning is not enabled, there are no object versions to protect, so MFA Delete has nothing to preserve against overwrite damage. It also does not block ordinary PUT overwrites or non-versioning DELETE calls; it only guards against destructive operations on existing versions, making it a supplemental security control rather than a standalone recovery solution.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on DOP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company wants to ensure its data in Amazon S3 is protected against accidental deletion. The bucket stores critical documents. Which approach provides the HIGHEST level of resilience?

easy
  • A.Apply a bucket policy that denies s3:DeleteObject for all users.
  • B.Enable S3 lifecycle policies to archive objects to Glacier.
  • ✓ C.Enable versioning and MFA delete on the bucket.
  • D.Configure cross-region replication (CRR) to another bucket.

Why C: Enabling versioning and MFA delete provides protection against both accidental overwrites and malicious deletions. Versioning allows recovery of deleted or overwritten objects, while MFA delete adds an extra layer of security by requiring multi-factor authentication for permanent deletions. Option A is incorrect because a bucket policy that denies s3:DeleteObject can prevent deletions but does not allow recovery if the policy is bypassed or changed. Option B is incorrect because lifecycle policies archive objects to Glacier, which reduces costs but does not prevent or recover from accidental deletion. Option D is incorrect because cross-region replication protects against regional failures but does not protect against accidental deletion within the source bucket.

Variation 2. A company wants to ensure that its Amazon S3 bucket is resilient to accidental deletion of objects. Which TWO actions should be taken?

easy
  • ✓ A.Enable MFA Delete on the bucket.
  • B.Enable S3 Object Lock.
  • ✓ C.Enable S3 Versioning.
  • D.Enable S3 Transfer Acceleration.
  • E.Configure a lifecycle policy to expire objects after 30 days.

Why A: Enabling MFA Delete on an S3 bucket requires multi-factor authentication for any delete operations, including object version deletion and bucket deletion. This adds a critical layer of protection against accidental or unauthorized deletions, as the user must present both their AWS credentials and a valid MFA code to perform these destructive actions.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.