CCSP Cloud Security Operations Practice Question
A cloud operations team at a healthcare company runs a multi-account AWS organization. Compliance requires that all Amazon S3 server access logs and AWS CloudTrail management events are retained for 7 years and cannot be altered or deleted by any account administrator, including the account that owns the bucket. The security architect must design a storage solution that enforces write-once-read-many (WORM) immutability at the storage layer. Which approach BEST satisfies these requirements?
⚠ Common exam trap
The trap here is assuming that a deny-delete bucket policy or S3 Versioning provides true immutability, when only S3 Object Lock in compliance mode prevents privileged principals from altering or removing locked objects.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure an S3 bucket with S3 Object Lock in compliance mode and a default retention period of 7 years, then centralize logs into that bucket.
The scenario demands storage-layer immutability that survives even privileged administrators and enforces a fixed 7-year retention. S3 Object Lock in compliance mode is the only mechanism here that makes object versions unalterable and undeletable for the retention period, and a default retention rule automates the 7-year window for all ingested logs. Encryption, versioning, replication, and bucket policies govern access or durability but do not deliver WORM guarantees.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Replicate logs to a second S3 bucket in a different Region using S3 Cross-Region Replication and apply a restrictive bucket policy on the replica.
Why it's wrong here
Cross-Region Replication improves durability and availability but the replica is still mutable and deletable by an authorized principal. A restrictive bucket policy can be edited by the bucket owner's administrator, so it does not provide immutable WORM storage. This design also does not enforce a defined 7-year retention window, leaving compliance exposure.
- ✗
Enable S3 Versioning and a bucket policy that denies s3:DeleteObject for all principals except the organization's root user.
Why it's wrong here
Versioning preserves prior object versions but does not prevent a principal with sufficient permissions from deleting the current version or permanently removing noncurrent versions. A bucket policy denying deletes can be modified by an administrator who controls the bucket policy, so it is not tamper-proof. It also does not enforce a retention period, so it fails the 7-year WORM requirement.
- ✗
Store logs in an S3 bucket encrypted with AWS KMS customer managed keys and rotate the keys every 90 days.
Why it's wrong here
KMS encryption protects confidentiality at rest and key rotation limits the blast radius of a compromised key, but neither prevents deletion or modification of objects. An administrator with s3:DeleteObject permission and access to the key could still remove logs. This option addresses encryption, not WORM immutability or the 7-year retention period required by the scenario.
- ✓
Configure an S3 bucket with S3 Object Lock in compliance mode and a default retention period of 7 years, then centralize logs into that bucket.
Why this is correct
S3 Object Lock in compliance mode enforces WORM semantics for the specified retention period; no principal, including the root user of the owning account, can overwrite or delete a locked object version until the retention date passes. A default retention rule applies the 7-year period automatically to every new object, satisfying the healthcare retention and immutability mandate.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.