A regulator requires proof that backup copies cannot be deleted until each copy's retention period expires - explicitly including deletions attempted by internal administrators. Which platform mechanism matches that wording?
Select an answer to reveal the explanation.
Short Explanation
'Nobody can delete this, not even us' is a very specific legal sentence, and exactly one mechanism actually says it: retention lock in compliance mode, where the clock owns the data. Governance mode, RBAC, and detective alerts only promise you'll notice a deletion - not that it couldn't happen.
Full Explanation
Compliance-mode Retention Lock enforces minimum retention at the system level: delete and shorten-retention attempts are rejected regardless of the requester's privilege until each object's period lapses. Enforcement lives below the permission layer, which makes the claim provable: the most privileged account gets the same refusal as the least, in a witnessed test if needed. RBAC restrictions target the very privilege layer the regulator distrusts: privileged roles, support escalations, or stolen credentials still act, and documented policy is process evidence, not enforcement. Governance mode exists to allow an authorized override - that is the modes' entire distinction - so offering it here quietly violates the requirement: an escalation path is a deletion path. Checksum verification is detective: it proves a deletion happened after the fact, whereas the requirement is that it cannot happen at all, and detection reports do not satisfy non-erasability. Exam caveat: retention must be set as data is locked, compliance mode cannot simply be switched off when it becomes inconvenient, and because periods are clock-driven, reliable time synchronization is part of the control's integrity. Operational check: in a test window, attempt to delete a compliance-locked test object from the most privileged account, confirm the rejection, and archive the audit entry as compliance evidence.