Courseiva

SOA-C02 Reliability and Business Continuity Practice Question

A company's S3 bucket contains critical data. The bucket policy accidentally allowed public write access, and a malicious actor uploaded several objects. The company needs to recover the bucket to a known good state as quickly as possible. What should the SysOps administrator do?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use S3 Versioning to restore the bucket to a previous version.

Enabling S3 Versioning allows restoring a bucket to a previous state by deleting the current versions of objects, effectively rolling back to the last good version before the malicious uploads. Option A is incorrect because S3 Object Lock prevents deletion or overwrite for a specified retention period but does not provide version rollback. Option B is incorrect because MFA Delete requires additional authentication for delete operations but does not help restore previous versions. Option D is incorrect because S3 Cross-Region Replication replicates objects to another region but does not provide versioning or rollback capabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable S3 Object Lock on the bucket to prevent further modifications.

    Why it's wrong here

    S3 Object Lock enforces a write-once-read-many (WORM) model, preventing objects from being deleted or overwritten for a specified retention period or indefinitely via legal holds. However, it only protects new writes after it is enabled and cannot undo an existing overwrite or deletion that already occurred. Since the critical data is already compromised, enabling Object Lock now would not restore the previous object content or bring back removed versions.

  • ✗

    Enable MFA Delete on the bucket to secure delete operations.

    Why it's wrong here

    Enabling MFA Delete on the bucket adds a required multi-factor authentication code for permanently deleting object versions and for suspending versioning, which helps prevent unauthorized or accidental destructive actions. This is strictly a preventive security control; it does not maintain or recover historical copies of data. If the current object is already overwritten or deleted, MFA Delete provides no mechanism to revert to the prior state, so it fails to address the immediate recovery need.

  • ✓

    Use S3 Versioning to restore the bucket to a previous version.

    Why this is correct

    S3 Versioning is the correct option because it preserves every version of an object, including all overwrites and deletes, as long as versioning was enabled before the incident. With versioning active, a simple DELETE creates a delete marker instead of removing the object, and an overwrite creates a new version while the old one remains accessible. To restore, you can delete the delete marker or copy the desired previous version back to the bucket, effectively rolling the data back to its earlier state.

  • ✗

    Configure S3 Cross-Region Replication to replicate data to another region.

    Why it's wrong here

    Cross-Region Replication (CRR) asynchronously copies new objects from the source bucket to a destination bucket in a different AWS Region, primarily for geographic redundancy, latency optimization, or compliance-driven distance requirements. It only replicates objects after the replication rule is configured and does not snapshot or retain a history of object versions within the source bucket. Even when versioning is enabled on both buckets, CRR does not offer a rollback capability or allow you to revert to a previous version of a corrupted or deleted object.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.