Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

A healthcare company must store patient records in Amazon S3 for a minimum of 7 years to meet regulatory requirements. During this period, the records must not be deleted or modified by any user, including the root user. Which S3 feature should be used to enforce this?

⚠ Common exam trap

Candidates often suggest S3 Lifecycle Policies. Lifecycle policies move or delete data based on age, but they do not prevent an administrator from manually deleting data before the time expires.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

S3 Object Lock in Compliance mode

S3 Object Lock provides Write-Once-Read-Many (WORM) protection. When configured in Compliance mode, an object version cannot be deleted or overwritten by any user, including the root user, for the duration of the retention period. This is the only way to satisfy strict regulatory requirements for data immutability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    S3 Versioning with MFA Delete

    Why it's wrong here

    While S3 Versioning keeps history and MFA Delete prevents accidental deletions, an authorized user with an MFA token could still delete the data. This does not provide the absolute 'no modification or deletion' guarantee required for regulatory compliance that persists even against administrative actions.

  • ✗

    S3 Object Lock in Governance mode

    Why it's wrong here

    In Governance mode, users with special permissions (like the 's3:BypassGovernanceRetention' permission) can still delete or modify the objects. Since the requirement states that even the root user must be restricted, Governance mode is insufficient as it allows for administrative overrides during the retention period.

  • ✓

    S3 Object Lock in Compliance mode

    Why this is correct

    Compliance mode ensures that an object version cannot be overwritten or deleted by any user, including the AWS account root user. The retention period is strictly enforced, and the mode cannot be changed or shortened, making it the correct choice for meeting high-bar regulatory standards.

  • ✗

    S3 Lifecycle policy with an expiration of 7 years

    Why it's wrong here

    Lifecycle policies are used to automate the deletion or transition of objects after a certain timeframe. They do not prevent a user from manually deleting the object before the expiration date. Therefore, they cannot be used to guarantee that data will remain available for the full 7-year period.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 149 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.