Courseiva

SAA-C03 Design Resilient Architectures Practice Question

A team uses an S3 bucket to store important customer-generated exports. They need protection against accidental overwrites and also want copies of the data in another AWS Region for disaster recovery. Which S3 configuration best satisfies both requirements?

⚠ Common exam trap

Candidates often think lifecycle policies or AWS Backup alone can handle both accidental overwrites and disaster recovery, but they fail to address the real-time protection and cross-region copy requirements that versioning and CRR specifically provide.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable S3 versioning and configure Cross-Region Replication to a destination bucket in another Region.

Enabling S3 versioning protects against accidental overwrites by preserving all object versions, allowing recovery of previous versions. Configuring Cross-Region Replication (CRR) automatically replicates objects to a destination bucket in another AWS Region, providing disaster recovery by maintaining a copy of the data in a separate geographic location.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable S3 lifecycle policies to automatically move objects to Glacier after 30 days only.

    Why it's wrong here

    Lifecycle policies that transition objects to Glacier after 30 days only reduce storage costs by moving data to cold storage, but they do not protect against accidental overwrites or deletes. Without versioning, a write or delete permanently replaces or removes the only copy, and Glacier's retrieval times make rapid recovery impractical. Additionally, this approach lacks any cross-Region copy, so it does not provide resilience against an entire Region becoming unavailable.

    When this WOULD be correct

    A question asking for cost-effective long-term archival of infrequently accessed data, with no requirement for versioning or cross-region replication, would make this correct.

  • ✓

    Enable S3 versioning and configure Cross-Region Replication to a destination bucket in another Region.

    Why this is correct

    Enabling S3 versioning preserves every version of an object, so accidental overwrites or deletes can be undone by restoring a prior version or removing a delete marker. Cross-Region Replication then asynchronously copies new and updated objects to a bucket in another Region, providing a geographically separate copy for disaster recovery. Together these features directly address both object-level corruption and Region-level failures, making them the correct solution.

  • ✗

    Disable all versioning and rely on AWS Backup to restore objects from a scheduled backup window.

    Why it's wrong here

    Disabling versioning removes the ability to recover from accidental overwrites or deletes because old object states are immediately discarded. AWS Backup can restore objects from scheduled snapshots, but the backup window and restore process introduce significant RPO and RTO, meaning recent changes may be lost and recovery could take hours. Versioning provides near-instant, per-object rollback that backups cannot match, and the lack of replication still leaves the data vulnerable to Regional failures.

    When this WOULD be correct

    If the question required a centralized backup solution across multiple AWS services (e.g., EC2, RDS, and S3) with a defined retention policy and compliance auditing, AWS Backup would be the correct answer.

  • ✗

    Enable S3 Block Public Access and SSE-S3 encryption, without using versioning or replication.

    Why it's wrong here

    Block Public Access and SSE-S3 encryption are security controls that prevent unauthorized public access and encrypt data at rest, but they do not address data resilience. These features do not create additional object versions, nor do they replicate data across Regions, so an overwrite, delete, or Regional outage still results in permanent loss. Security and encryption are necessary for protecting data from threats, but they are independent of availability and recovery requirements.

    When this WOULD be correct

    An exam question asking for the best way to secure an S3 bucket from public access and ensure data encryption at rest, without mentioning versioning or replication requirements, would make this option correct.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.

✓Enable S3 versioning and configure Cross-Region Replication to a destination bucket in another Region.Correct answer▾

Why this is correct

Enabling S3 versioning preserves every version of an object, so accidental overwrites or deletes can be undone by restoring a prior version or removing a delete marker. Cross-Region Replication then asynchronously copies new and updated objects to a bucket in another Region, providing a geographically separate copy for disaster recovery. Together these features directly address both object-level corruption and Region-level failures, making them the correct solution.

✗Enable S3 lifecycle policies to automatically move objects to Glacier after 30 days only.Wrong answer — click to see why▾

Why this is wrong here

Lifecycle policies to Glacier only address storage cost optimization, not protection against accidental overwrites or cross-region disaster recovery.

★ When this WOULD be the correct answer

A question asking for cost-effective long-term archival of infrequently accessed data, with no requirement for versioning or cross-region replication, would make this correct.

Why candidates choose this

Candidates may confuse lifecycle management with data protection, assuming moving to Glacier provides backup or recovery capabilities.

✗Disable all versioning and rely on AWS Backup to restore objects from a scheduled backup window.Wrong answer — click to see why▾

Why this is wrong here

AWS Backup does not prevent accidental overwrites; it only provides scheduled backups. Without versioning, overwritten objects are permanently lost until the next backup, and recovery point objectives may not align with real-time protection.

★ When this WOULD be the correct answer

If the question required a centralized backup solution across multiple AWS services (e.g., EC2, RDS, and S3) with a defined retention policy and compliance auditing, AWS Backup would be the correct answer.

Why candidates choose this

Candidates may assume that AWS Backup offers the same protection as versioning for overwrites, or they overestimate the frequency of backups, not realizing that versioning provides immediate recovery without relying on backup schedules.

✗Enable S3 Block Public Access and SSE-S3 encryption, without using versioning or replication.Wrong answer — click to see why▾

Why this is wrong here

Block Public Access and SSE-S3 encryption protect against unauthorized access and encrypt data at rest, but they do not prevent accidental overwrites or provide cross-region disaster recovery copies.

★ When this WOULD be the correct answer

An exam question asking for the best way to secure an S3 bucket from public access and ensure data encryption at rest, without mentioning versioning or replication requirements, would make this option correct.

Why candidates choose this

Candidates may mistakenly think that security measures like Block Public Access and encryption are sufficient for data protection and disaster recovery, overlooking the need for versioning and replication.

Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.