SAA-C03 Design Secure Architectures Practice Question
A solutions architect is designing a storage solution for a financial firm. The firm requires that data stored in Amazon S3 must be protected against accidental deletion and all changes to the data must be versioned. Which TWO features should the architect implement to meet these requirements? (Select TWO)
⚠ Common exam trap
SAA-C03 often tests the distinction between versioning (preserves history) and MFA Delete (requires MFA to permanently delete versions), and candidates frequently confuse Object Lock Governance mode with MFA Delete as deletion protection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable S3 Versioning on the bucket.
Option A is correct because enabling S3 Versioning on the bucket preserves every prior version of an object, so overwrites and deletes create new versions rather than destroying data, directly satisfying the requirement that all changes to the data be versioned. Option B is correct because MFA Delete adds a second authentication factor requiring the bucket owner's MFA token plus a valid request to permanently delete an object version or to suspend versioning, which protects the versioned data against accidental or malicious deletion. Together, Versioning provides the version history and MFA Delete guards the deletion of those versions, which is exactly the combination the financial firm needs. Option C is not appropriate because Lifecycle policies only transition or expire objects and do not provide versioning or deletion protection. Option D is not appropriate because S3 Object Lock in Governance mode enforces a retention period (WORM) rather than versioning all changes, and Governance mode can be bypassed by users with special permissions. Option E is not appropriate because Block Public Access only restricts public exposure of the bucket and has nothing to do with versioning or protecting against deletion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable S3 Versioning on the bucket.
Why this is correct
S3 Versioning allows multiple variants of an object to be kept in the same bucket. When an object is deleted, S3 inserts a delete marker instead of permanently removing the data, which allows for easy recovery of the original file and maintains a full history of all changes.
- ✓
Enable MFA Delete on the bucket.
Why this is correct
MFA Delete provides an additional layer of security by requiring multi-factor authentication to either change the versioning state of the bucket or permanently delete an object version. This prevents even users with administrative permissions from accidentally or maliciously purging data without the required physical token.
- ✗
Implement S3 Lifecycle policies to move data to Glacier.
Why it's wrong here
S3 Lifecycle policies are used for cost optimization by transitioning objects to cheaper storage classes or expiring them after a set period. While useful for management, they do not provide protection against accidental deletion or support the requirement for versioning data as it changes.
- ✗
Configure a Default Retention Period using S3 Object Lock in Governance mode.
Why it's wrong here
S3 Object Lock in Governance mode prevents objects from being deleted or overwritten, but it is primarily used for WORM compliance. While it prevents deletion, the scenario specifically asks for versioning of changes, which is a separate mechanism provided by the Versioning feature itself.
- ✗
Use S3 Block Public Access at the account level.
Why it's wrong here
S3 Block Public Access is a critical security control that prevents objects from being shared publicly. However, it does not protect against accidental deletion by authorized internal users or provide the versioning capabilities required to track changes to the data over time.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 149 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.