S3 Object Lock stores objects using a write-once-read-many (WORM) model, preventing them from being deleted or overwritten for a set period — the answer for compliance and ransomware-protection scenarios.

Retention modes

Governance mode — most users can’t delete, but privileged users with special permission can. Compliance mode — no one, not even the root account, can delete until retention expires. Legal holds keep an object locked indefinitely until removed. Scenario says “must not be deletable by anyone for X years”? Compliance mode.

Test yourself

Practice question

A regulation requires that financial records in S3 cannot be deleted or altered by anyone, including administrators, for seven years. What do you use?

  1. S3 Versioning only
  2. S3 Object Lock in Compliance mode
  3. A restrictive bucket policy
  4. S3 Object Lock in Governance mode
👉 Click to reveal the answer & explanation

Correct answer: B. Object Lock in Compliance mode enforces WORM so no one — not even root — can delete until retention expires. Versioning (A) keeps history but allows deletion; a bucket policy (C) can be changed; Governance mode (D) lets privileged users override.

Related topics

Amazon S3 · S3 versioning · AWS Backup

CloudExamPro Premium

Ready to pass the AWS Solutions Architect Associate (SAA-C03)?

Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.

  • ✓  6 full-length practice exams
  • ✓  A detailed explanation for every single question
  • ✓  Realistic, scenario-based questions — not memory dumps
  • ✓  Lifetime access, kept current for 2026

Get the SAA-C03 Practice Exams →or try 25 free questions first

Limited-time offer · ends in --Days:--Hrs:--Min:--Sec
Get Instant Access