SCS-C02 S3 Object Lock Practice Question
A company wants to store audit logs for a minimum of 7 years to meet compliance requirements. The logs are stored in Amazon S3. Which action should be taken to ensure logs are not deleted before 7 years?
⚠ Common exam trap
SCS-C02 often tests whether candidates confuse versioning or MFA Delete with true immutability, leading them to pick options that preserve data but do not legally prevent deletion before the retention period.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable S3 Object Lock in Compliance mode with a 7-year retention period on the bucket.
S3 Object Lock in Compliance mode prevents any user, including the root account, from deleting or overwriting an object version until the retention period expires. Setting a 7-year retention period on the bucket enforces the compliance requirement at the object level and cannot be bypassed, which is exactly what is needed to guarantee logs are not deleted before 7 years.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable MFA Delete on the bucket.
Why it's wrong here
MFA Delete requires a second authentication factor to delete an object version or suspend bucket versioning, which helps deter unauthorized or accidental deletion. However, it only applies to a limited set of destructive operations and does not establish any retention duration. An authorized user who presents a valid MFA token can immediately delete audit logs, so MFA Delete cannot satisfy a mandated seven-year retention period.
- ✗
Configure an S3 Lifecycle policy to transition objects to Glacier after 7 years.
Why it's wrong here
An S3 Lifecycle policy that transitions objects to Glacier after 7 years changes the storage class for cost optimization but imposes no prohibition on deletion. Users with s3:DeleteObject permissions can still delete objects at any time, and the lifecycle rule itself can be edited or removed, so there is no immutable retention guarantee. To satisfy a 7-year audit-log retention requirement, you need a mechanism that actively blocks deletion, not one that simply archives data.
- ✗
Enable S3 Versioning to preserve all versions of objects.
Why it's wrong here
Enabling S3 Versioning preserves every overwrite as a new version, so it can prevent accidental loss of previous copies, but it does not restrict deletion. A user authorized to call DeleteObject can remove the current version and, if they specify the version ID, delete all previous versions as well. Because versioning alone imposes no minimum storage duration, it cannot ensure that audit logs remain for seven years.
- ✓
Enable S3 Object Lock in Compliance mode with a 7-year retention period on the bucket.
Why this is correct
S3 Object Lock in Compliance mode gives each object a write-once-read-many (WORM) retention period, and once a 7-year retention is applied, no user, including the AWS account root user, can delete or overwrite that object version until the period expires. Because Compliance mode is irrevocable for the locked object, even an admin with full permissions cannot shorten the retention or remove the lock. This directly enforces the seven-year audit-log requirement at the S3 API level.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.