A cloud customer receives a litigation hold notice requiring preservation of data stored in an object storage service. Which service feature should the customer use to ensure data cannot be modified or deleted until the hold is released?
Object Lock enforces write-once-read-many (WORM) protection at the object level, preventing modification or deletion for a defined retention period. This directly satisfies the litigation hold's requirement that data remain immutable until the hold is formally released, independent of user permissions.
Why this answer
Object Lock is the S3-compatible feature that enforces WORM (Write Once, Read Many) protection by applying a retention policy (governance or compliance mode) or a legal hold to objects. When a retention period or legal hold is in place, the object cannot be overwritten or deleted by any user, including the root account, until the hold is released. This directly satisfies the litigation hold requirement to preserve data in an immutable state.
Exam trap
CCSP often tests the misconception that versioning or encryption provides immutability; candidates must recognize that only Object Lock (WORM) enforces non-modification and non-deletion for litigation holds.
How to eliminate wrong answers
Option B is wrong because lifecycle policies only move or expire objects (e.g., transition to Glacier or delete after N days) and do not prevent modification or deletion; in fact, a lifecycle rule could delete the very data under hold. Option C is wrong because versioning only preserves prior versions of an object — a user can still delete the current version or overwrite it, and without Object Lock a delete marker can be placed, so it does not guarantee immutability. Option D is wrong because server-side encryption protects confidentiality of data at rest but does nothing to prevent an authorized user from modifying or deleting the object.