DeviceLock Service : Managing DeviceLock Service for Windows : Service Options : Auditing & Shadowing : Safe file overwrite
  
Safe file overwrite
Enable this parameter to prevent the deletion of the original file as a result of user attempts to replace it with a file with the same name and prohibited contents. When this parameter is enabled, the original file remains in the folder intact once its overwriting is prohibited by content-aware rules. The event of the original file restoration is logged in the audit log.
 
Note: When this parameter is enabled and any content-aware rules are in effect that deny write access, deletion of files may take longer than usual.