Protecting an S3 bucket from deletion by leaked long-term credentials using Object Lock
A company has an application that stores data in a single Amazon S3 bucket. The company must keep all data for 1 year. The company’s security team is concerned that an attacker could gain access to the AWS account through leaked long-term credentials. Which solution will ensure that existing and future objects in the S3 bucket are protected?
Community Votes
71% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
S3 Object Lock (WORM) prevents deletion or overwrite for the retention period even by a user with valid credentials, so isolating data in a locked bucket neutralizes the risk of leaked long-term credentials better than detection-only or MFA-delete controls.
To protect existing and future objects against an attacker holding leaked credentials, isolate the data in a security-team account and apply S3 Object Lock with a 1-year retention. Replicate from the source bucket (including a Batch Replication job for existing objects) so WORM protection covers all data regardless of who holds credentials.
Relying on GuardDuty (Option D) — it only detects suspicious S3 activity; it does not prevent an attacker with valid credentials from deleting or overwriting objects.
Community Discussion (13 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option A directly addresses the threat: an attacker with leaked long-term credentials could otherwise delete or overwrite data. By replicating into a separate security-team account and enabling S3 Object Lock with a 1-year default retention, objects become immutable for that period even to a credential holder. S3 Versioning plus Batch Replication brings both existing and future objects under protection.Why the Other Options Are Wrong
Option B and C depend on MFA Delete or Service Catalog constraints, which add friction but are not as absolute as WORM retention and still leave windows where valid credentials can act. Option D (GuardDuty) is detect-only and cannot prevent deletion. The security team's concern is prevention, not detection.Community Comment Notes
nharaz (likes 8) explains Object Lock prevents deletion/overwrite and replication covers existing data. career360guru (likes 5) argues D is the only option addressing the security risk and that replicating does not remove the original-bucket credential risk — a fair caveat, but Object Lock's immutability is the stronger control for the stated goal.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →