Courseiva
Data Protection →hardMultiple Choice

SCS-C02 Data Protection Practice Question

Network Topology
# aws s3api get-bucket-versioningbucket my-versioned-bucket# aws s3api get-bucket-lifecycle-configurationRefer to the exhibit."Status": "Enabled","MFADelete": "Enabled""Rules": ["ID": "ExpireOldVersions","Filter": {},"Expiration": {"Days": 30

A company has an S3 bucket with versioning and MFA Delete enabled. A user attempts to delete an object version using the AWS CLI without MFA. What will happen?

⚠ Common exam trap

SCS-C02 often tests the misconception that MFA Delete applies to all delete operations, but it only applies to deleting specific object versions or changing versioning state; deleting an object without a version ID (creating a delete marker) does not require MFA.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The request fails with an AccessDenied error.

When MFA Delete is enabled on an S3 bucket, any request to permanently delete an object version or to change the versioning state of the bucket must include a valid MFA token. If a user attempts to delete an object version without MFA, the request fails with an AccessDenied error. This is the expected behavior to protect against accidental or malicious deletions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The object version is marked for deletion and will be deleted after 30 days.

    Why it's wrong here

    The assertion that the version is marked for deletion is incorrect. S3 uses lifecycle expiration rules to schedule deletions after a period, but a direct DELETE request either succeeds or fails immediately; it never places a 'pending deletion' state without a lifecycle policy. More fundamentally, because MFA Delete is enabled, the request lacks the required MFA token and is rejected with AccessDenied before any marking or scheduling occurs.

  • ✓

    The request fails with an AccessDenied error.

    Why this is correct

    The correct behavior is that the request fails with AccessDenied. S3 MFA Delete requires an MFA-authenticated request to permanently delete an object version. Since the request does not include the x-amz-mfa header with a valid MFA code, S3 denies the DeleteObject call. This prevents any deletion, including creation of delete markers.

  • ✗

    The object version is deleted and a delete marker is created.

    Why it's wrong here

    A delete marker is normally created when you perform a DELETE without specifying a versionId in a versioning-enabled bucket. However, MFA Delete overrides this behavior: even a request that would create a delete marker requires MFA authentication. Without the required MFA credentials, S3 denies the request, so no delete marker is created.

  • ✗

    The object version is deleted but not permanently.

    Why it's wrong here

    The idea that the version is deleted 'but not permanently' is a misunderstanding of versioning mechanics. Versioned objects are never in a temporary state; each version is either present or permanently absent. With MFA Delete enabled, the DELETE request fails outright, so the version remains fully intact; no soft delete or 'logical delete' occurs.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.