SAA-C03 Design Resilient Architectures Practice Question
Your media processing pipeline writes original uploads to an S3 bucket and later generates derivative files. An operator accidentally deletes a subset of original uploads in production. You need to (1) restore the deleted objects with minimal data loss and (2) protect against both regional disasters and future operator mistakes. The company requires recovery even if objects are deleted and later overwritten.
What is the most effective change to meet these requirements?
⚠ Common exam trap
Watch out — candidates often think a bucket policy denying DeleteObject is sufficient to prevent data loss, but it does not protect against overwrites, authorized user mistakes, or regional disasters, and without versioning, deleted objects are permanently lost.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable S3 versioning on the bucket and configure cross-Region replication so previous versions are available after regional loss and accidental deletion.
Enabling S3 Versioning preserves all object versions, including overwrites and deletions (which become delete markers), allowing you to restore deleted objects by removing the delete marker. Cross-Region Replication (CRR) replicates both current and previous versions to a secondary Region, protecting against regional disasters. Together, they ensure recovery even if objects are deleted and later overwritten, meeting all requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable S3 versioning on the bucket and configure cross-Region replication so previous versions are available after regional loss and accidental deletion.
Why this is correct
Enabling S3 versioning preserves every PUT as a new version, so an accidental DELETE only adds a delete marker and the original object can be restored instantly. Cross-Region replication (CRR) asynchronously copies every version — including previous ones — to a secondary Region, providing recoverability if the entire source Region becomes unavailable. Together, versioning addresses user error and CRR addresses regional loss, satisfying the full recovery requirement.
- ✗
Move all objects to S3 Glacier Instant Retrieval and apply a lifecycle policy to keep only the latest object copy.
Why it's wrong here
S3 Glacier Instant Retrieval is an archive storage class designed for long-lived data with millisecond access, but it has no inherent versioning, deletion protection, or cross-Region redundancy. Applying a lifecycle rule to keep only the latest object copy would actually purge all older versions (if any existed) and the single remaining copy is still vulnerable to deletion or a Regional outage. This option intentionally discards historical versions, contradicting the requirement to retain previous versions for recovery.
When this WOULD be correct
This option would be correct if the requirements were to reduce storage costs for infrequently accessed data while maintaining millisecond retrieval times, and there was no need to recover from accidental deletion or regional disasters.
- ✗
Use S3 server-side encryption with KMS keys and rely on access logs to manually recover the deleted objects.
Why it's wrong here
Server-side encryption with AWS KMS (SSE-KMS) protects object confidentiality by encrypting data at rest, but it does not increase durability and has no mechanism to protect against deletion or to store history. S3 access logs can confirm that a DELETE request was made and by whom, yet logs record request metadata, not object contents, so they cannot rebuild the deleted file's bytes. Without versioning or replication, the original uploads are gone forever, making this a security-monitoring aid rather than a data recovery solution.
When this WOULD be correct
If the requirement was to audit who deleted objects and when, without needing to restore them, enabling S3 server access logs and using AWS CloudTrail would be correct. This scenario focuses on detective controls, not recovery.
- ✗
Enable S3 bucket policies that deny DeleteObject, but do not enable versioning or replication.
Why it's wrong here
A bucket policy that denies s3:DeleteObject can block ordinary IAM users from issuing deletes, but it cannot prevent deletes from the AWS account root user, lifecycle expirations, or a compromised administrative role, so it only narrows some future mistakes. Because versioning is not enabled, the currently deleted objects were permanently removed and no prior copy exists to restore. Without replication, there is also no second Region copy, so the policy provides neither recovery for existing deletions nor resilience against a regional failure.
When this WOULD be correct
A question requiring prevention of accidental deletion by unauthorized users (e.g., preventing a junior admin from deleting objects) where versioning is already enabled and disaster recovery is not a concern. The policy would block delete API calls while versioning retains previous versions.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.
✓Enable S3 versioning on the bucket and configure cross-Region replication so previous versions are available after regional loss and accidental deletion.Correct answer▾
Why this is correct
Enabling S3 versioning preserves every PUT as a new version, so an accidental DELETE only adds a delete marker and the original object can be restored instantly. Cross-Region replication (CRR) asynchronously copies every version — including previous ones — to a secondary Region, providing recoverability if the entire source Region becomes unavailable. Together, versioning addresses user error and CRR addresses regional loss, satisfying the full recovery requirement.
✗Move all objects to S3 Glacier Instant Retrieval and apply a lifecycle policy to keep only the latest object copy.Wrong answer — click to see why▾
Why this is wrong here
Glacier Instant Retrieval does not provide versioning, so deleted objects cannot be restored. Additionally, a lifecycle policy keeping only the latest copy would not protect against accidental deletion or overwrites, and Glacier does not offer cross-region replication for disaster recovery.
★ When this WOULD be the correct answer
This option would be correct if the requirements were to reduce storage costs for infrequently accessed data while maintaining millisecond retrieval times, and there was no need to recover from accidental deletion or regional disasters.
Why candidates choose this
Candidates may mistakenly believe that Glacier Instant Retrieval provides versioning or that a lifecycle policy can protect against deletion, overlooking that versioning is essential for recovery.
✗Use S3 server-side encryption with KMS keys and rely on access logs to manually recover the deleted objects.Wrong answer — click to see why▾
Why this is wrong here
Access logs only record requests; they do not restore deleted objects. Manual recovery from logs is impractical and cannot restore objects that were overwritten, failing the requirement for recovery after overwrite.
★ When this WOULD be the correct answer
If the requirement was to audit who deleted objects and when, without needing to restore them, enabling S3 server access logs and using AWS CloudTrail would be correct. This scenario focuses on detective controls, not recovery.
Why candidates choose this
Candidates may think that encryption and logs provide comprehensive protection, overlooking that logs are not a backup mechanism and cannot restore deleted or overwritten objects.
✗Enable S3 bucket policies that deny DeleteObject, but do not enable versioning or replication.Wrong answer — click to see why▾
Why this is wrong here
Denying DeleteObject via bucket policy does not protect against regional disasters, and if an operator deletes objects, they are still permanently lost because versioning is not enabled. Overwritten objects are also unrecoverable.
★ When this WOULD be the correct answer
A question requiring prevention of accidental deletion by unauthorized users (e.g., preventing a junior admin from deleting objects) where versioning is already enabled and disaster recovery is not a concern. The policy would block delete API calls while versioning retains previous versions.
Why candidates choose this
Candidates think a bucket policy denying deletes is a simple, low-cost solution that directly prevents operator mistakes, overlooking the need for versioning to recover already-deleted objects and the lack of regional disaster protection.
Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.