SCS-C02 Data Protection Practice Question
A company is designing a data protection strategy for its Amazon S3 buckets. Which TWO actions can help protect data from accidental deletion or overwrite?
⚠ Common exam trap
SCS-C02 often tests whether candidates confuse durability/replication features with deletion-protection features — Cross-Region Replication and encryption are distractors because they do not prevent deletion or overwrite.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable MFA Delete on the bucket.
Option A (Enable MFA Delete on the bucket) is correct because MFA Delete requires multi-factor authentication to permanently delete an object version or to suspend or re-enable versioning, adding a strong safeguard against accidental or malicious deletion. Option D (Enable versioning on the bucket) is correct because versioning keeps multiple variants of an object in the same bucket, so an overwrite creates a new version and a delete only adds a delete marker, allowing the prior version to be restored. Together, versioning preserves prior object states and MFA Delete protects those versions from being permanently removed. Option B (Cross-Region Replication) is not correct here because it copies objects to another bucket for durability and compliance, but it does not by itself prevent deletion or overwrite in the source bucket. Option C (default encryption) protects data confidentiality at rest but does not stop deletion or overwrite. Option E (a lifecycle policy to expire objects) actually deletes objects, which is the opposite of protecting against accidental deletion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable MFA Delete on the bucket.
Why this is correct
MFA Delete is a bucket-level feature that, when enabled alongside versioning, requires a valid multi-factor authentication code before S3 will permanently delete an object version or change the versioning state. Even if an IAM policy grants s3:DeleteObject or s3:DeleteObjectVersion, the API call fails unless the x-amz-mfa header contains a valid code, adding an independent security layer. This specifically prevents accidental or malicious deletion by requiring physical possession of an MFA device, making it a direct and powerful control for data protection.
- ✗
Enable Cross-Region Replication.
Why it's wrong here
Cross-Region Replication (CRR) asynchronously copies objects from a source bucket to a destination bucket in a different AWS Region, which provides geographic redundancy and helps with disaster recovery. However, CRR does not by default replicate delete markers, and even when you enable replication of delete markers, it copies the marker rather than protecting the source object from deletion. Moreover, if a source object is permanently deleted, replication cannot restore it — the delete is not undone. Therefore, CRR does not prevent or recover from deletions and is not a data protection mechanism for the original object.
- ✗
Enable default encryption.
Why it's wrong here
Default encryption automatically applies server-side encryption to all newly stored objects, using options such as SSE-S3, SSE-KMS, or SSE-C, thereby protecting data at rest from unauthorized read access. Encryption is a confidentiality measure; it does not affect any delete operations, lifecycle rules, or the permissions that govern who can remove objects. An actor with the s3:DeleteObject permission can still delete an object regardless of whether it is encrypted. Thus, default encryption has no bearing on preventing data loss due to deletion.
- ✓
Enable versioning on the bucket.
Why this is correct
Enabling versioning on an S3 bucket preserves every version of an object, including overwrites and deletions; a standard delete operation places a delete marker instead of erasing the underlying data. This means previous versions remain retrievable, allowing an administrator to restore data after an accidental or intentional deletion, as long as the versions have not been permanently removed by a lifecycle policy or an explicit delete with the version ID. Versioning alone does not require MFA and therefore does not stop deletion attempts, but it provides a robust recovery mechanism, making it a valid part of a data protection strategy.
- ✗
Set a lifecycle policy to expire objects.
Why it's wrong here
A lifecycle policy is a set of rules that automates actions such as transitioning objects to colder storage or permanently expiring them after a specified number of days. For example, an Expiration action will permanently delete objects or object versions, which directly removes backups and leads to data loss rather than preventing it. Because lifecycle policies are destructive by design, they work against the goal of protecting data against deletion unless that is the explicit intent. Consequently, this option is incorrect for preventing deletion.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.