Courseiva
Infrastructure Security →mediumMultiple Choice

SCS-C02 S3 Object Lock Practice Question

A company wants to store audit logs for a minimum of 7 years to meet compliance requirements. The logs are stored in Amazon S3. Which action should be taken to ensure logs are not deleted before 7 years?

⚠ Common exam trap

SCS-C02 often tests whether candidates confuse versioning or MFA Delete with true immutability, leading them to pick options that preserve data but do not legally prevent deletion before the retention period.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable S3 Object Lock in Compliance mode with a 7-year retention period on the bucket.

S3 Object Lock in Compliance mode prevents any user, including the root account, from deleting or overwriting an object version until the retention period expires. Setting a 7-year retention period on the bucket enforces the compliance requirement at the object level and cannot be bypassed, which is exactly what is needed to guarantee logs are not deleted before 7 years.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable MFA Delete on the bucket.

    Why it's wrong here

    MFA Delete requires a second authentication factor to delete an object version or suspend bucket versioning, which helps deter unauthorized or accidental deletion. However, it only applies to a limited set of destructive operations and does not establish any retention duration. An authorized user who presents a valid MFA token can immediately delete audit logs, so MFA Delete cannot satisfy a mandated seven-year retention period.

  • ✗

    Configure an S3 Lifecycle policy to transition objects to Glacier after 7 years.

    Why it's wrong here

    An S3 Lifecycle policy that transitions objects to Glacier after 7 years changes the storage class for cost optimization but imposes no prohibition on deletion. Users with s3:DeleteObject permissions can still delete objects at any time, and the lifecycle rule itself can be edited or removed, so there is no immutable retention guarantee. To satisfy a 7-year audit-log retention requirement, you need a mechanism that actively blocks deletion, not one that simply archives data.

  • ✗

    Enable S3 Versioning to preserve all versions of objects.

    Why it's wrong here

    Enabling S3 Versioning preserves every overwrite as a new version, so it can prevent accidental loss of previous copies, but it does not restrict deletion. A user authorized to call DeleteObject can remove the current version and, if they specify the version ID, delete all previous versions as well. Because versioning alone imposes no minimum storage duration, it cannot ensure that audit logs remain for seven years.

  • ✓

    Enable S3 Object Lock in Compliance mode with a 7-year retention period on the bucket.

    Why this is correct

    S3 Object Lock in Compliance mode gives each object a write-once-read-many (WORM) retention period, and once a 7-year retention is applied, no user, including the AWS account root user, can delete or overwrite that object version until the period expires. Because Compliance mode is irrevocable for the locked object, even an admin with full permissions cannot shorten the retention or remove the lock. This directly enforces the seven-year audit-log requirement at the S3 API level.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.