CCSP Cloud Security Operations Practice Question
A financial services company stores regulated data in Amazon S3 and must prove to auditors that objects cannot be deleted or overwritten for seven years, even by a compromised root account. The security team needs the strongest native control that preserves the data for the retention period. Which S3 feature should they enable?
⚠ Common exam trap
The trap here is treating replication or versioning as equivalent to immutability, when only Object Lock in compliance mode resists even root-level deletion.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
S3 Object Lock in compliance mode
S3 Object Lock in compliance mode enforces a write-once-read-many retention that no principal, including the account root, can shorten or remove before the retention date. Versioning and replication improve durability and recoverability but remain mutable by privileged users, so only compliance-mode Object Lock satisfies the immutability proof the auditors demand.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
S3 Cross-Region Replication to a second bucket
Why it's wrong here
Cross-Region Replication copies objects to another bucket for durability and latency, but the destination bucket is also writable and deletable by authorized principals. Replication alone does not enforce retention, so it cannot guarantee the objects remain unchanged for seven years.
- ✓
S3 Object Lock in compliance mode
Why this is correct
S3 Object Lock in compliance mode prevents any user, including the root account, from overwriting or deleting a protected object version until the retention date passes. This is the strongest native immutability control in S3 and directly satisfies the seven-year retention requirement for regulated data.
- ✗
Bucket policies that deny s3:DeleteObject to all principals
Why it's wrong here
Bucket policies are evaluated at request time and can be modified by an administrator, so a compromised privileged account could change the policy and then delete the data. Policy-based denial is not immutable and does not meet the auditor's requirement that data survive even root-level compromise.
- ✗
S3 Versioning with a lifecycle rule to transition objects to S3 Glacier Deep Archive
Why it's wrong here
Versioning preserves prior versions when objects are overwritten or deleted, but a principal with sufficient permissions can still delete individual versions or the entire bucket. Lifecycle transitions only change storage class, so this combination does not provide the immutable retention guarantee the auditors require.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.