Courseiva

SAA-C03 Practice Question: S3 Object Lock Compliance mode prevents deletion…

A financial services company must store audit logs in S3 for 7 years and ensure that no one — including the AWS account root user — can delete or overwrite the logs during the retention period. Which S3 Object Lock configuration should a solutions architect use?

⚠ Common exam trap

Candidates choose Governance mode because 'governance' sounds strict. In AWS terminology, Governance is the LESS strict option — it can be bypassed by privileged users. Compliance mode is immutable: no one can remove the retention until the period expires. This distinction is critical for financial regulations like SEC Rule 17a-4 and FINRA requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Object Lock in Compliance mode with a 7-year retention period

S3 Object Lock in Compliance mode prevents ALL users — including the root account — from deleting or overwriting objects before the retention period expires. The retention period itself cannot be shortened once set in Compliance mode. Governance mode also prevents most deletions, but users with s3:BypassGovernanceRetention permission (and the root account) can delete objects or shorten the retention period. For regulatory requirements where not even root can override, Compliance mode is mandatory.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Object Lock in Compliance mode with a 7-year retention period

    Why this is correct

    S3 Object Lock in Compliance mode establishes an unalterable Write Once, Read Many (WORM) state for objects. This mode prevents any user, including the AWS account root user, from deleting or overwriting objects until the specified retention period, in this case, 7 years, has expired. The retention period cannot be shortened or removed by anyone, ensuring the highest level of data immutability required for strict financial regulatory compliance.

  • ✗

    Object Lock in Governance mode with a 7-year retention period

    Why it's wrong here

    S3 Object Lock in Governance mode offers strong protection against accidental deletion or modification, but it is not absolute. While it prevents most users from altering objects, the AWS account root user or any IAM principal explicitly granted the `s3:BypassGovernanceRetention` permission can bypass the retention settings. This bypass capability means Governance mode fails to meet the strict requirement that absolutely no one, including the root user, can delete the logs.

  • ✗

    S3 Versioning with a lifecycle rule to transition objects to Glacier after 7 years

    Why it's wrong here

    S3 Versioning primarily protects against unintended overwrites or deletions by keeping multiple versions of an object. However, a user with appropriate permissions can still permanently delete all versions of an object, including delete markers, effectively removing the data from the bucket. Lifecycle rules are designed to automate the transition of objects between different S3 storage classes to optimize costs, not to provide immutability or prevent intentional data deletion.

  • ✗

    A bucket policy with Deny for s3:DeleteObject applied to all principals including root

    Why it's wrong here

    IAM policies, including bucket policies, are designed to manage permissions for IAM users, roles, and federated identities within an AWS account. The AWS account root user, by its nature, possesses implicit full administrative access to all resources and is inherently exempt from restrictions imposed by IAM policies, even explicit Deny statements. Therefore, a bucket policy attempting to deny `s3:DeleteObject` to all principals, including root, would not prevent the root user from performing the deletion.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.