Use S3 Object Lock compliance mode with replication to block admin deletion in the DR Region

Design and implement controls to manage the lifecycle of data at rest. Design and implement network security controls.
Answer Correct answer: B — S3 Object Lock compliance mode replicates with the objects, blocking even admin deletion in the secondary Region.

A company needs a solution to protect critical data from being permanently deleted. The data is stored in Amazon S3 buckets. The company needs to replicate the S3 objects from the company's primary AWS Region to a secondary Region to meet disaster recovery requirements. The company must also ensure that users who have administrator access cannot permanently delete the data in the secondary Region. Which solution will meet these requirements?

  1. Configure AWS Backup to perform cross-Region S3 backups. Select a backup vault in the secondary Region. Enable AWS Backup Vault Lock in governance mode for the backups in the secondary Region.
  2. Implement S3 Object Lock in compliance mode in the primary Region. Configure S3 replication to replicate the objects to an S3 bucket in the secondary Region. Correct Answer
  3. Configure S3 replication to replicate the objects to an S3 bucket in the secondary Region. Create an S3 bucket policy to deny the s3:ReplicateDelete action on the S3 bucket in the secondary Region.
  4. Configure S3 replication to replicate the objects to an S3 bucket in the secondary Region. Configure S3 object versioning on the S3 bucket in the secondary Region.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Compliance mode Object Lock cannot be removed by any user, including the root account, for the retention period, which is the only way to stop an administrator from deleting data. Used together with S3 Replication, the lock and retention metadata are copied to the secondary bucket, meeting both DR replication and admin-proof deletion protection.

Critical S3 data must be protected from permanent deletion and replicated to a secondary Region, and even administrators must not be able to delete it there. S3 Object Lock in compliance mode prevents deletion or overwrite by any user, including admins, and its retention settings replicate with the objects when used with S3 Replication, so the secondary copy is equally protected.

Using a bucket policy that denies s3:ReplicateDelete or enabling versioning alone. A bucket policy can be changed by an admin (so it does not truly block admins), and versioning only soft-deletes via markers, not permanent protection from deletion of the bucket/objects.

Community Discussion (7 comments)

Zek 👍 6
B https://docs.aws.amazon.com/AmazonS3/latest/userguide/object-lock-managing.html#object-lock-managing-replication
youonebe 👍 1 Selected: B
S3 Object Lock in compliance mode prevents objects from being deleted or overwritten, even by administrators. This would ensure that once the data is replicated to the secondary Region, it cannot be permanently deleted. Object Lock is a perfect fit for protecting critical data against accidental or malicious deletion.
IPLogic 👍 1 Selected: B
B. This solution ensures that the data is protected from being permanently deleted by using S3 Object Lock in compliance mode, which prevents even users with administrator access from deleting the objects. Additionally, configuring S3 replication will ensure that the objects are replicated to the secondary Region, meeting the disaster recovery requirements12.
NimiBes 👍 1 Selected: B
"You can use Object Lock with S3 Replication to enable automatic, asynchronous copying of locked objects and their retention metadata, across S3 buckets. This means that for replicated objects, Amazon S3 takes the object lock configuration of the source bucket. " Link: https://docs.aws.amazon.com/AmazonS3/latest/userguide/object-lock-managing.html#object-lock-managing-replication
jade290 👍 1 Selected: C
The question is limiting deletion only to the secondary region, not the primary. If you do an Object lock, then you cannot delete in the primary or secondary region. https://docs.aws.amazon.com/AmazonS3/latest/userguide/object-lock-managing.html#object-lock-managing-replication --> Section titled "Using Object Lock with S3 Replication"
fibonacciname 👍 3 Selected: B
B is correct
Certified101 👍 2 Selected: B
B agree

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

S3 Object Lock in compliance mode blocks deletion or overwrite of protected objects for the retention period, and no user—including those with administrator access—can bypass it. When combined with S3 Replication, the object lock configuration and retention metadata are replicated to the secondary Region bucket, so the DR copy is protected against permanent deletion by admins as required.

Why the Other Options Are Wrong

A (AWS Backup Vault Lock governance mode) can be removed by users with appropriate IAM permissions, so it does not guarantee protection from administrators. C (bucket policy denying s3:ReplicateDelete) can be edited or deleted by an admin, so it is not tamper-proof. D (versioning only) allows deletions via delete markers and does not prevent an admin from permanently removing objects or the bucket.

Community Comment Notes

Community chose B overwhelmingly (89 votes). A top comment linked the Object Lock + Replication doc and noted compliance mode "prevents objects from being deleted or overwritten, even by administrators." One C voter argued Object Lock would also block primary-region deletion, but the requirement explicitly covers the secondary Region.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide