SAA-C03 Practice Question: S3 Object Lock Compliance mode prevents deletion…
A financial services company must store audit logs in S3 for 7 years and ensure that no one — including the AWS account root user — can delete or overwrite the logs during the retention period. Which S3 Object Lock configuration should a solutions architect use?
⚠ Common exam trap
Candidates choose Governance mode because 'governance' sounds strict. In AWS terminology, Governance is the LESS strict option — it can be bypassed by privileged users. Compliance mode is immutable: no one can remove the retention until the period expires. This distinction is critical for financial regulations like SEC Rule 17a-4 and FINRA requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Object Lock in Compliance mode with a 7-year retention period
S3 Object Lock in Compliance mode prevents ALL users — including the root account — from deleting or overwriting objects before the retention period expires. The retention period itself cannot be shortened once set in Compliance mode. Governance mode also prevents most deletions, but users with s3:BypassGovernanceRetention permission (and the root account) can delete objects or shorten the retention period. For regulatory requirements where not even root can override, Compliance mode is mandatory.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Object Lock in Compliance mode with a 7-year retention period
Why this is correct
S3 Object Lock in Compliance mode establishes an unalterable Write Once, Read Many (WORM) state for objects. This mode prevents any user, including the AWS account root user, from deleting or overwriting objects until the specified retention period, in this case, 7 years, has expired. The retention period cannot be shortened or removed by anyone, ensuring the highest level of data immutability required for strict financial regulatory compliance.
- ✗
Object Lock in Governance mode with a 7-year retention period
Why it's wrong here
S3 Object Lock in Governance mode offers strong protection against accidental deletion or modification, but it is not absolute. While it prevents most users from altering objects, the AWS account root user or any IAM principal explicitly granted the `s3:BypassGovernanceRetention` permission can bypass the retention settings. This bypass capability means Governance mode fails to meet the strict requirement that absolutely no one, including the root user, can delete the logs.
- ✗
S3 Versioning with a lifecycle rule to transition objects to Glacier after 7 years
Why it's wrong here
S3 Versioning primarily protects against unintended overwrites or deletions by keeping multiple versions of an object. However, a user with appropriate permissions can still permanently delete all versions of an object, including delete markers, effectively removing the data from the bucket. Lifecycle rules are designed to automate the transition of objects between different S3 storage classes to optimize costs, not to provide immutability or prevent intentional data deletion.
- ✗
A bucket policy with Deny for s3:DeleteObject applied to all principals including root
Why it's wrong here
IAM policies, including bucket policies, are designed to manage permissions for IAM users, roles, and federated identities within an AWS account. The AWS account root user, by its nature, possesses implicit full administrative access to all resources and is inherently exempt from restrictions imposed by IAM policies, even explicit Deny statements. Therefore, a bucket policy attempting to deny `s3:DeleteObject` to all principals, including root, would not prevent the root user from performing the deletion.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.