Vault Lock enforces write-once-read-many (WORM) protection on your AWS Backup vault, so backups can’t be deleted or shortened before their retention period — even by administrators. It’s ransomware and compliance insurance for backups.
The tell
When a scenario requires that backups themselves cannot be deleted or altered for a retention period (protection against ransomware or malicious insiders), that’s Backup Vault Lock in compliance mode. It’s the backup-layer equivalent of S3 Object Lock.
Test yourself
A company must guarantee that its backups cannot be deleted or have their retention shortened by anyone, including admins, for compliance. What enforces this?
- A restrictive IAM policy
- AWS Backup Vault Lock (compliance mode)
- S3 Versioning
- More frequent backups
👉 Click to reveal the answer & explanation
Correct answer: B. Vault Lock in compliance mode enforces immutable WORM protection on backups so no one can delete or shorten retention. An IAM policy (A) can be changed; S3 Versioning (C) protects objects, not backup vaults; more frequent backups (D) don’t prevent deletion.
Related topics
AWS Backup · S3 Object Lock · Disaster Recovery Strategies
Ready to pass the AWS Solutions Architect Associate (SAA-C03)?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026
Get the SAA-C03 Practice Exams →or try 25 free questions first