S3 Object Lock stores objects using a write-once-read-many (WORM) model, preventing them from being deleted or overwritten for a set period — the answer for compliance and ransomware-protection scenarios.
Retention modes
Governance mode — most users can’t delete, but privileged users with special permission can. Compliance mode — no one, not even the root account, can delete until retention expires. Legal holds keep an object locked indefinitely until removed. Scenario says “must not be deletable by anyone for X years”? Compliance mode.
Test yourself
A regulation requires that financial records in S3 cannot be deleted or altered by anyone, including administrators, for seven years. What do you use?
- S3 Versioning only
- S3 Object Lock in Compliance mode
- A restrictive bucket policy
- S3 Object Lock in Governance mode
👉 Click to reveal the answer & explanation
Correct answer: B. Object Lock in Compliance mode enforces WORM so no one — not even root — can delete until retention expires. Versioning (A) keeps history but allows deletion; a bucket policy (C) can be changed; Governance mode (D) lets privileged users override.
Related topics
Amazon S3 · S3 versioning · AWS Backup
Ready to pass the AWS Solutions Architect Associate (SAA-C03)?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026
Get the SAA-C03 Practice Exams →or try 25 free questions first