SOA-C02 Reliability and Business Continuity Practice Question
A SysOps administrator needs to ensure that an S3 bucket can recover from accidental deletions by users. The bucket stores versioned objects. What additional configuration should be enabled to prevent permanent deletion?
⚠ Common exam trap
Many exam-takers assume a bucket policy denying s3:DeleteObject is sufficient, but it does not prevent accidental deletion by authorized users who have delete permissions and can simply remove the policy; MFA Delete is the only way to enforce an additional authentication factor for permanent deletions in versioned buckets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable MFA Delete on the bucket.
Enabling MFA Delete on the S3 bucket adds an extra layer of protection by requiring multi-factor authentication for any DeleteObject or DeleteBucket operations. Even if a user has s3:DeleteObject permission, they cannot permanently delete versioned objects unless they present a valid MFA code. This prevents accidental or unauthorized permanent deletions while still allowing versioned objects to be recovered.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable S3 Server-Side Encryption.
Why it's wrong here
S3 Server-Side Encryption encrypts object data at rest using AWS-managed, KMS-managed, or customer-provided keys. It protects the confidentiality of the content but has no effect on deletion actions or lifecycle behavior. Any IAM principal with s3:DeleteObject permission can still permanently delete the encrypted object, so this option does not prevent loss of data.
- ✗
Enable S3 Lifecycle rules to expire objects.
Why it's wrong here
S3 Lifecycle expiration rules are designed to automatically delete objects or abort incomplete multipart uploads after a specific time period. Rather than preventing deletion, these rules actively purge current or noncurrent versions, increasing the risk of unintended data loss. With versioning enabled, expiration permanently removes versions, so it is exactly the opposite of a deletion safeguard.
- ✓
Enable MFA Delete on the bucket.
Why this is correct
MFA Delete requires the principal making a destructive request to supply a valid one-time code from a hardware or virtual MFA device, in addition to normal AWS authentication. When applied to a versioned bucket, it protects against permanently deleting an object version and against changing the bucket's versioning state. This means an accidental delete creates a recoverable delete marker, and even compromised AWS credentials cannot irreversibly purge data without the MFA code.
- ✗
Configure a bucket policy to deny s3:DeleteObject.
Why it's wrong here
A bucket policy that denies s3:DeleteObject with a blanket effect blocks every principal, including the bucket owner and legitimate applications, from deleting any current object version. It also fails to restrict s3:DeleteObjectVersion, so noncurrent versions can still be permanently purged by authorized users. Because the policy is static and does not enforce multi-factor authentication, it breaks normal lifecycle and operational deletions rather than providing a controlled safeguard.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.