Courseiva

SAA-C03 Design Resilient Architectures Practice Question

A media company stores finalized video masters in an Amazon S3 bucket in the us-east-1 Region. Compliance requires that the objects be recoverable if they are accidentally deleted or overwritten for at least 90 days, and that no user, including administrators, be able to permanently erase them during that period. Which S3 feature should the solutions architect enable?

⚠ Common exam trap

The trap here is treating governance mode and compliance mode as interchangeable, when only compliance mode removes the ability of privileged users to bypass retention.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

S3 Object Lock in compliance mode with a retention period of 90 days on the bucket.

The requirement is legal-hold-style immutability that even administrators cannot override. S3 Object Lock in compliance mode enforces exactly that: protected object versions cannot be deleted or overwritten by any identity until the retention period lapses, and the retention cannot be shortened. Governance mode and replication both leave a path for privileged users to destroy the data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    S3 Versioning with a lifecycle rule that transitions noncurrent versions to S3 Glacier Deep Archive after 30 days.

    Why it's wrong here

    Versioning preserves prior object versions, but any principal with delete permissions can still permanently remove a specific version or the delete marker. Lifecycle transitions only change the storage class of noncurrent versions; they do not prevent an administrator from issuing a permanent delete, so the immutability requirement is not satisfied.

  • ✗

    S3 Object Lock in governance mode with a retention period of 90 days on the bucket.

    Why it's wrong here

    Governance mode allows users with the s3:BypassGovernanceRetention permission to remove or shorten the retention, so an administrator could still permanently delete the objects. Because the requirement states that no user, including administrators, may erase the data during the period, governance mode is insufficient and compliance mode is required.

  • ✓

    S3 Object Lock in compliance mode with a retention period of 90 days on the bucket.

    Why this is correct

    S3 Object Lock in compliance mode prevents any user, including the root account, from deleting or overwriting a protected object version until the retention period expires. A 90-day retention period matches the compliance window exactly, and the protection cannot be shortened or bypassed, which is what the requirement demands.

  • ✗

    S3 Cross-Region Replication to a bucket in another Region with versioning enabled on both buckets.

    Why it's wrong here

    Cross-Region Replication creates a copy in another Region for durability and latency, but it does not prevent deletion of the source objects. A user with delete permissions can still remove the original, and replication may even propagate the delete marker depending on configuration, so this does not provide the required immutability.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.