For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Associate (SAA-C03)AWS SAA-C03 Practice Exam 6Question 16
    Medium1 markMultiple Choice
    Domain 1.3: Data SecurityS3Object LockCompliance

    AWS SAA-C03 · Question 16 · Domain 1.3: Data Security

    A financial company must store regulatory documents in Amazon S3. Compliance rules dictate that the documents must be stored in a Write-Once-Read-Many (WORM) model and cannot be deleted or modified by anyone, including the AWS account root user, for exactly 7 years.<br/><br/>Which TWO actions should a solutions architect take? (Select TWO.)

    Answer options:

    A.

    Enable S3 Object Lock in Governance mode.

    B.

    Enable S3 Object Lock in Compliance mode.

    C.

    Set a retention period of 7 years.

    D.

    Use an S3 bucket policy to deny the s3:DeleteObject action.

    E.

    Enable S3 Versioning and MFA Delete.

    How to approach this question

    Differentiate between Compliance mode and Governance mode in S3 Object Lock.

    Full Answer

    S3 Object Lock in Compliance mode ensures objects cannot be overwritten or deleted by any user, including the root user, for the duration of the retention period. This is required for strict regulatory WORM compliance.

    Common mistakes

    Selecting Governance mode or thinking MFA Delete is sufficient for WORM compliance.
    Question 15All questionsQuestion 17

    Practice the full AWS SAA-C03 Practice Exam 6

    65 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A company has multiple AWS accounts in an AWS Organizations organization. The security team wants...MediumQ02A company has two AWS accounts: Account A for development and Account B for production. Developer...MediumQ03A mobile application needs to authenticate users using their social media accounts (Facebook, Goo...EasyQ04A company is running an application on Amazon EC2 instances. The application needs to connect to ...MediumQ05A company has 50 AWS accounts managed by AWS Organizations. The IT team wants to implement a cent...Easy
    View all 65 questions →