SAA-C03 Design Resilient Architectures Practice Question
A media company stores finalized video masters in an Amazon S3 bucket in the us-east-1 Region. Compliance requires that the objects be recoverable if they are accidentally deleted or overwritten for at least 90 days, and that no user, including administrators, be able to permanently erase them during that period. Which S3 feature should the solutions architect enable?
⚠ Common exam trap
The trap here is treating governance mode and compliance mode as interchangeable, when only compliance mode removes the ability of privileged users to bypass retention.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
S3 Object Lock in compliance mode with a retention period of 90 days on the bucket.
The requirement is legal-hold-style immutability that even administrators cannot override. S3 Object Lock in compliance mode enforces exactly that: protected object versions cannot be deleted or overwritten by any identity until the retention period lapses, and the retention cannot be shortened. Governance mode and replication both leave a path for privileged users to destroy the data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
S3 Versioning with a lifecycle rule that transitions noncurrent versions to S3 Glacier Deep Archive after 30 days.
Why it's wrong here
Versioning preserves prior object versions, but any principal with delete permissions can still permanently remove a specific version or the delete marker. Lifecycle transitions only change the storage class of noncurrent versions; they do not prevent an administrator from issuing a permanent delete, so the immutability requirement is not satisfied.
- ✗
S3 Object Lock in governance mode with a retention period of 90 days on the bucket.
Why it's wrong here
Governance mode allows users with the s3:BypassGovernanceRetention permission to remove or shorten the retention, so an administrator could still permanently delete the objects. Because the requirement states that no user, including administrators, may erase the data during the period, governance mode is insufficient and compliance mode is required.
- ✓
S3 Object Lock in compliance mode with a retention period of 90 days on the bucket.
Why this is correct
S3 Object Lock in compliance mode prevents any user, including the root account, from deleting or overwriting a protected object version until the retention period expires. A 90-day retention period matches the compliance window exactly, and the protection cannot be shortened or bypassed, which is what the requirement demands.
- ✗
S3 Cross-Region Replication to a bucket in another Region with versioning enabled on both buckets.
Why it's wrong here
Cross-Region Replication creates a copy in another Region for durability and latency, but it does not prevent deletion of the source objects. A user with delete permissions can still remove the original, and replication may even propagate the delete marker depending on configuration, so this does not provide the required immutability.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.