Courseiva

CCSP Cloud Security Operations Practice Question

A financial services company stores regulated data in Amazon S3 and must prove to auditors that objects cannot be deleted or overwritten for seven years, even by a compromised root account. The security team needs the strongest native control that preserves the data for the retention period. Which S3 feature should they enable?

⚠ Common exam trap

The trap here is treating replication or versioning as equivalent to immutability, when only Object Lock in compliance mode resists even root-level deletion.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

S3 Object Lock in compliance mode

S3 Object Lock in compliance mode enforces a write-once-read-many retention that no principal, including the account root, can shorten or remove before the retention date. Versioning and replication improve durability and recoverability but remain mutable by privileged users, so only compliance-mode Object Lock satisfies the immutability proof the auditors demand.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    S3 Cross-Region Replication to a second bucket

    Why it's wrong here

    Cross-Region Replication copies objects to another bucket for durability and latency, but the destination bucket is also writable and deletable by authorized principals. Replication alone does not enforce retention, so it cannot guarantee the objects remain unchanged for seven years.

  • ✓

    S3 Object Lock in compliance mode

    Why this is correct

    S3 Object Lock in compliance mode prevents any user, including the root account, from overwriting or deleting a protected object version until the retention date passes. This is the strongest native immutability control in S3 and directly satisfies the seven-year retention requirement for regulated data.

  • ✗

    Bucket policies that deny s3:DeleteObject to all principals

    Why it's wrong here

    Bucket policies are evaluated at request time and can be modified by an administrator, so a compromised privileged account could change the policy and then delete the data. Policy-based denial is not immutable and does not meet the auditor's requirement that data survive even root-level compromise.

  • ✗

    S3 Versioning with a lifecycle rule to transition objects to S3 Glacier Deep Archive

    Why it's wrong here

    Versioning preserves prior versions when objects are overwritten or deleted, but a principal with sufficient permissions can still delete individual versions or the entire bucket. Lifecycle transitions only change storage class, so this combination does not provide the immutable retention guarantee the auditors require.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.