Courseiva
Data Protection →mediumMultiple Choice

SCS-C02 Data Protection Practice Question

A company is designing a data protection solution for Amazon S3 that must prevent any user from accidentally deleting objects. Which combination of S3 features should be used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable S3 Versioning and MFA Delete.

Enabling S3 Versioning preserves all object versions, allowing recovery of deleted objects, and MFA Delete requires multi-factor authentication for permanent deletions, preventing accidental or unauthorized deletions. Option A is wrong because Cross-Region Replication copies objects to another bucket but does not prevent deletion of the source objects. Option B is wrong because Object Lock with governance mode prevents overwrites and deletions only if a retention period is set, but it does not block deletion of the bucket itself or version-level deletions if the lock is not applied. Option C is wrong because default encryption (SSE-KMS) protects data at rest but does not prevent deletion of objects.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use S3 Cross-Region Replication to another bucket.

    Why it's wrong here

    S3 Cross-Region Replication asynchronously copies objects to a destination bucket in another region, but it does nothing to prevent deletion of the source object. When a versioned object is deleted in the source bucket, a delete marker is created and—if delete marker replication is enabled—the marker is replicated to the destination, meaning the data is still considered deleted from the operational namespace. Without versioning on the source bucket, the delete is permanent and replication cannot resurrect the original object; at best, CRR only provides a separate copy that might survive the deletion, but the requirement is to prevent any user from deleting objects, which CRR does not enforce.

  • ✗

    Enable S3 Object Lock with governance mode.

    Why it's wrong here

    S3 Object Lock in governance mode prevents object deletion only for users without the `s3:BypassGovernanceRetention` permission, but any user granted that permission—including root or administrators—can still delete objects, so it does not satisfy the requirement to prevent *any* user from accidentally deleting objects. It is tempting because governance mode is designed to protect against accidental deletion by most users while allowing authorised administrators to modify retention settings, making it correct for scenarios where a controlled override is needed.

  • ✗

    Configure S3 default encryption with SSE-KMS.

    Why it's wrong here

    Configuring default encryption with SSE-KMS protects data at rest by encrypting objects with AWS KMS customer master keys, but encryption has no effect on the data lifecycle or permission model for deletion. Any user with the s3:DeleteObject permission can still issue a DELETE request and remove objects, regardless of whether they are encrypted, because object deletion is a metadata operation and does not require the encryption key to be accessible.

  • ✓

    Enable S3 Versioning and MFA Delete.

    Why this is correct

    Enabling S3 Versioning together with MFA Delete is the correct answer because versioning preserves every overwrite and deletion as a previous version, while MFA Delete adds a second-factor requirement for permanently erasing versions or changing the bucket's versioning state. When an object is deleted, S3 simply creates a delete marker and the prior versions remain recoverable; without the MFA token, even the AWS account root user cannot permanently delete a version, which effectively prevents accidental or malicious deletion.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.