Courseiva

CCSP Cloud Security Operations Practice Question

A healthcare company stores regulated data in Amazon S3. An auditor requires proof that objects are protected against accidental deletion or overwrite for a fixed period, and that the protection cannot be removed even by the root account. Which S3 feature should the security team implement?

⚠ Common exam trap

The trap here is treating versioning or a restrictive bucket policy as equivalent to WORM protection, when both can be reversed by privileged accounts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

S3 Object Lock in compliance mode with a retention period matching the required fixed duration.

S3 Object Lock in compliance mode creates a write-once-read-many (WORM) protection that no principal, including the root account, can bypass or shorten during the retention period. Governance mode and bucket policies are administratively changeable, and versioning alone does not prevent deletion. Compliance mode directly satisfies the immutability and fixed-duration requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    S3 Object Lock in compliance mode with a retention period matching the required fixed duration.

    Why this is correct

    S3 Object Lock in compliance mode prevents object versions from being overwritten or deleted for the specified retention period. Critically, compliance mode cannot be bypassed or shortened by any user, including the AWS account root user, satisfying the auditor's immutability requirement. Governance mode, by contrast, allows privileged users to alter retention.

  • ✗

    S3 Object Lock in governance mode with a retention period matching the required fixed duration.

    Why it's wrong here

    Governance mode enforces retention but allows users with the s3:BypassGovernanceRetention permission to remove or shorten the lock. Because the root account can be granted that permission, protection is not absolute. The requirement that even the root account cannot remove protection rules out governance mode.

  • ✗

    A bucket policy that denies s3:DeleteObject and s3:PutObject to all principals except a dedicated backup role.

    Why it's wrong here

    Bucket policies are evaluated at request time and can be modified or deleted by an administrator or the root user. They do not create immutable retention; a principal with s3:PutBucketPolicy can simply rewrite the policy. This does not provide the tamper-proof protection the auditor demands.

  • ✗

    S3 Versioning with a lifecycle rule that transitions noncurrent versions to S3 Glacier Deep Archive.

    Why it's wrong here

    Versioning preserves prior object versions, but any principal with delete permissions, including the root user, can permanently delete versions or suspend versioning. Lifecycle transition to Glacier Deep Archive only changes storage class; it does not prevent deletion. This fails the requirement that protection be immutable even against the root account.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.