Courseiva

SOA-C02 Reliability and Business Continuity Practice Question

A company uses Amazon S3 to store backup data. The SysOps administrator needs to ensure that the data is protected against accidental deletion by users with administrative privileges. Which combination of actions should the administrator take? (Choose TWO.)

⚠ Common exam trap

SOA-C02 often tests the misconception that bucket policies or CloudTrail can prevent deletion, when in fact only MFA Delete and versioning provide protection against accidental deletion by privileged users.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable MFA Delete on the S3 bucket.

Option A is correct because MFA Delete adds an additional authentication factor requirement for permanently deleting object versions or changing the versioning state of the bucket, which specifically protects against accidental deletion even by users with administrative privileges. Option C is correct because enabling versioning ensures that overwritten or deleted objects are retained as noncurrent versions, allowing recovery of data that would otherwise be lost. Together, versioning preserves deleted objects and MFA Delete prevents an administrator from permanently removing them or disabling versioning without an MFA token. Option B is not appropriate because a blanket deny of s3:DeleteObject would break legitimate deletion workflows and can be bypassed or modified by users with administrative privileges who can edit bucket policies. Option D is incorrect because lifecycle transitions to S3 Glacier only change storage class and do not protect against deletion. Option E is incorrect because CloudTrail only records API activity for auditing; it does not prevent or recover from accidental deletion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable MFA Delete on the S3 bucket.

    Why this is correct

    MFA Delete is the correct safeguard for this scenario because it forces any request that permanently deletes an object version, or that suspends versioning on the bucket, to include a valid code from a hardware or virtual MFA device. This prevents an attacker who has stolen console credentials or an IAM access key from irrevocably erasing backup data, since they would also need possession of the MFA token. It is important to note that MFA Delete can only be enabled when versioning is turned on, and it must be set via the AWS CLI or API rather than the console.

  • ✗

    Apply an S3 bucket policy that denies s3:DeleteObject for all users.

    Why it's wrong here

    Applying a bucket policy that denies s3:DeleteObject for all users is overly broad and not a workable protection. Such a policy would block every normal deletion workflow, including legitimate lifecycle operations and the creation of delete markers on versioned objects, while leaving the separate s3:DeleteObjectVersion permission unconstrained so permanent deletion of old versions would still be possible. A blanket denial like this breaks operational processes and does not target the specific risk of malicious permanent deletion.

  • ✓

    Enable versioning on the S3 bucket.

    Why this is correct

    Enabling versioning is a valid protective measure because S3 retains every version of an object, so a conventional 'delete' API call only places a delete marker on the object rather than erasing the underlying data. The previous versions remain recoverable by removing that delete marker, which means a mistaken or unauthorized deletion can be undone in minutes. Versioning also forms the foundation for MFA Delete and lifecycle expiration rules, making it a necessary first step before adding stronger safeguards.

  • ✗

    Configure a lifecycle policy to transition objects to S3 Glacier.

    Why it's wrong here

    Configuring a lifecycle rule to transition objects to S3 Glacier moves data to a lower-cost storage class after a defined age, but it says nothing about who can call the DeleteObject operation. In fact, if the lifecycle policy also includes expiration actions, it can automatically permanently delete current or noncurrent versions, making it a deletion risk rather than a protective control. Glacier transitions are about storage economics and long-term retention, not access control or recovery from deletion.

  • ✗

    Enable AWS CloudTrail to log all S3 API calls.

    Why it's wrong here

    Enabling CloudTrail and S3 data event logging will give you an audit trail that records the user, source IP, time, and API call for every deletion, which is invaluable for post-incident investigation. However, logging is a detective control, not a preventive one: it cannot block a DeleteObject or DeleteObjectVersion request, nor can it restore an object once a version has been permanently erased. You would still need versioning and MFA Delete to stop or undo the deletion itself.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.