Be able to select the exact configuration that satisfies an encryption or access-control requirement: KMS key policies, TLS enforcement parameters, security group references, and IAM authentication. The single most important thing is knowing which setting enforces the requirement versus which merely permits it.
Start practicing
Database Security — choose a session length
Free · No account required
Domain overview
Domain 3 of DBS-C01 covers securing AWS databases: encryption at rest with KMS, encryption in transit with TLS/SSL, IAM database authentication, VPC security groups, subnet groups, and audit logging. Questions are scenario-based, asking you to pick the configuration that satisfies a stated compliance or least-privilege requirement.
Exam objectives
Enforcing TLS/SSL in transit on RDS via parameter groups and require_secure_transport
Encrypting Redshift COPY/UNLOAD traffic to S3 using SSL and KMS keys
Least-privilege VPC security groups and private subnet placement for RDS
DynamoDB encryption at rest with customer-managed KMS keys and key policies
Assuming RDS encryption at rest can be enabled on an existing unencrypted instance; it requires snapshot restore into a new encrypted instance.
Forcing SSL on the client only, forgetting the server-side parameter (e.g., require_secure_transport) that rejects non-TLS connections.
Opening a database security group to 0.0.0.0/0 or a broad CIDR instead of referencing the application's security group as the source.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A company runs an Amazon RDS for MySQL DB instance in a VPC. Security requirements mandate that only specific EC2 instances in the same VPC can connect to the database. The security group attached to the RDS instance currently allows inbound traffic on port 3306 from 0.0.0.0/0. Which combination of steps should a database specialist take to meet the security requirement without impacting existing application connectivity? (Choose two.)
2A company uses Amazon ElastiCache for Redis to cache session data. The security team requires that all data in transit be encrypted. The Redis cluster currently does not have encryption in transit enabled. The database specialist needs to enable encryption in transit with minimal downtime. Which action should the specialist take?
3A company is designing a multi-tier application that uses Amazon RDS for PostgreSQL. The application must encrypt data at rest and in transit. Which combination of steps should be taken to meet these requirements? (Choose the single best answer.)
4A company is using Amazon RDS for MySQL with Multi-AZ deployment. The security team wants to ensure that database administrators cannot view sensitive data. Which TWO actions should be taken to achieve this goal?
5Arrange the steps to restore an Amazon RDS for MySQL DB instance to a new instance from a manual snapshot in the correct order.
6Match each AWS database migration tool/service to its function.
7A developer needs to allow an application running on an EC2 instance to read and write data to a DynamoDB table named 'Orders'. The EC2 instance is configured with an IAM role. Which IAM policy should be attached to the role?
8A company's security team wants to encrypt data at rest for an existing RDS for PostgreSQL DB instance. The instance is currently unencrypted. Which steps should the team take to enable encryption with minimal downtime?
9A company uses Amazon DynamoDB with AWS KMS customer managed keys for encryption at rest. The security team wants to audit who is using the KMS key to encrypt and decrypt data. Which AWS service should be used?
10A company has a multi-AZ RDS for PostgreSQL DB instance. The security team wants to ensure that database audit logs are stored in CloudWatch Logs for real-time monitoring. The team enabled the 'pgaudit.log' parameter and set 'log_destination' to 'csvlog'. However, logs are not appearing in CloudWatch. What is the most likely cause?
11A developer is writing an AWS Lambda function that needs to access a Secrets Manager secret to retrieve database credentials. The Lambda function has an IAM role. Which action must be allowed in the IAM policy?
12A company is using Amazon Aurora MySQL-Compatible Edition. The database administrator wants to restrict a specific user to only execute SELECT statements on a specific database. Which SQL command should the administrator use?
13Which TWO actions should be taken to protect sensitive data in an Amazon RDS for Oracle DB instance? (Choose two.)
14Which TWO AWS services can be used to centrally manage database credentials securely? (Choose two.)
15A database administrator runs the AWS CLI command shown in the exhibit. The administrator wants to enable encryption at rest for the RDS instance. What should the administrator do?
16A company wants to encrypt data at rest for an existing Amazon RDS for Oracle DB instance. The database is currently unencrypted. What is the simplest way to enable encryption with minimal downtime?
17A company is using Amazon Aurora MySQL-Compatible Edition. The security team wants to ensure that database credentials are not stored in application configuration files. They decide to use AWS Secrets Manager to manage credentials. The application is hosted on Amazon EC2 instances that have an IAM role attached. What is the most secure way to grant the application access to the secret?
18A company is using Amazon DynamoDB to store sensitive customer data. They need to ensure that all data is encrypted at rest using a customer-managed AWS KMS key. The company also wants to rotate the KMS key every year. What is the simplest way to achieve key rotation?
19A company uses Amazon RDS for SQL Server with Multi-AZ deployment. The security team has mandated that all connections to the database must use SSL/TLS. The database is accessed by multiple applications running on EC2 instances. Which configuration ensures that all connections use SSL/TLS?
20A company uses Amazon DynamoDB with a global secondary index (GSI) on a table that contains sensitive data. The security team requires that the GSI be encrypted with a different AWS KMS key than the base table. Can this be achieved, and if so, how?
21A company is deploying a new application on Amazon RDS for PostgreSQL. The security policy requires that all data be encrypted at rest and in transit. Which TWO actions should the company take to meet these requirements?
22A company uses Amazon Aurora MySQL-Compatible Edition. The security team wants to implement database activity streams to monitor database activity. Which THREE statements are true about Aurora database activity streams?
23A company is using Amazon DynamoDB and wants to restrict access to a specific table so that only users in a particular IAM group can perform read and write operations. Which THREE steps should be taken to achieve this?
24A company is migrating its on-premises Oracle database to Amazon RDS for Oracle. The security team requires that all data at rest be encrypted using a customer-managed key stored in AWS KMS, and that the key be rotated automatically every year. The company also needs to ensure that only specific IAM roles can access the key. Which combination of steps should the database administrator take to meet these requirements?
25A company is using Amazon RDS for PostgreSQL. The security team wants to ensure that all connections to the database are encrypted in transit. Currently, applications connect using the PostgreSQL native encryption (SSL/TLS). What is the MOST secure way to enforce encrypted connections?
26A company is using Amazon DynamoDB to store customer session data. The security team requires that all data is encrypted at rest using a customer-managed KMS key, and that access to the key is restricted to specific IAM roles. The company also wants to ensure that DynamoDB Accelerator (DAX) cluster is encrypted. Which steps should be taken to meet these requirements?
27A company is using Amazon RDS for PostgreSQL and needs to implement column-level encryption for sensitive data. The application must be able to encrypt and decrypt data transparently. Which approach should be taken?
28A company is using Amazon RDS for MySQL and needs to comply with PCI DSS requirements. Which TWO actions should the company take to secure the database? (Choose TWO.)
29A company is designing a security architecture for Amazon DynamoDB. They need to ensure that only authorized applications can access the data, and that data in transit is encrypted. Which THREE steps should be taken? (Choose THREE.)
30An IAM policy is attached to an IAM user. The user wants to connect to an RDS MySQL database using IAM database authentication. What does this policy allow?
31A company is migrating its on-premises Oracle database to Amazon RDS for Oracle. As part of the migration, they need to ensure that all sensitive data is encrypted at rest using AWS Key Management Service (AWS KMS). Which configuration step is required to achieve this?
32A company uses Amazon DynamoDB with AWS KMS-managed encryption at rest. The security team requires that all access to a particular DynamoDB table be logged for audit purposes. Which solution meets this requirement?
33A company is using Amazon RDS for MySQL and needs to restrict access to the database to only specific Amazon EC2 instances in the same VPC. Which security mechanism should be used?
34A company uses Amazon Aurora MySQL-Compatible Edition and needs to audit all SQL statements executed by database users. Which feature should be enabled?
35A company is using Amazon DynamoDB and wants to ensure that only authorized users can access a specific table. Which AWS service should be used to manage access control?
36A company is using Amazon RDS for PostgreSQL with automated backups. The security team requires that backups be encrypted at rest. The DB instance is currently unencrypted. What is the most efficient way to enable encryption for future backups?
37A company uses Amazon ElastiCache for Redis and needs to encrypt data in transit between the application and the cache cluster. Which feature should be enabled?
38A company is using Amazon DynamoDB and wants to ensure that all data is automatically encrypted at rest. What is the default encryption status for a new DynamoDB table?
39A company is designing a security strategy for Amazon RDS for SQL Server. Which TWO actions should be taken to encrypt data at rest? (Choose TWO.)
40A company is running an Amazon RDS for MySQL DB instance in a VPC. The security team requires that all connections to the database use SSL/TLS. The DBA has enabled 'require_secure_transport' parameter in the DB parameter group. However, after applying the change and rebooting, some applications that were previously connecting successfully are now failing. What is the most likely cause?
41A financial services company is using Amazon DynamoDB to store customer transaction data. The compliance team requires that all data be encrypted at rest using a customer-managed AWS KMS key, and that access to the key be auditable via AWS CloudTrail. Additionally, the security team wants to ensure that DynamoDB can only be accessed from within the VPC using a VPC endpoint. Which combination of steps should the company take to meet these requirements?
42A developer needs to securely store database credentials for an application that runs on Amazon EC2 and connects to an Amazon RDS for PostgreSQL database. The credentials must be automatically rotated every 90 days. Which AWS service should the developer use to meet these requirements?
43A company is migrating its on-premises Oracle database to Amazon RDS for Oracle. The database contains sensitive data that must be encrypted at rest and in transit. The security team also requires that the encryption keys be rotated every year. The DBA has enabled encryption at rest using a customer-managed KMS key and SSL/TLS for in-transit encryption. What additional step is needed to meet the key rotation requirement?
44A company is using Amazon RDS for SQL Server with Multi-AZ deployment. The security team requires that all database activity be monitored for suspicious queries. The database specialist enabled RDS Database Activity Streams and configured AWS Lambda to process the stream. However, the Lambda function fails to process some events when the database fails over to the standby instance. What is the most likely cause?
45A company is using Amazon Aurora MySQL-Compatible Edition. The security team wants to restrict access to the database so that only specific applications running on Amazon EC2 instances can connect. The EC2 instances are in the same VPC as the Aurora cluster. Which combination of steps should be taken to enforce this restriction?
46A company is using Amazon RDS for MySQL to host a web application. The security team has identified that the application is vulnerable to SQL injection attacks. The team wants to implement a defense-in-depth strategy to protect the database. Which THREE measures should be taken to mitigate SQL injection risks?
47A company has an Amazon RDS for MySQL DB instance that stores sensitive customer data. The security team requires that all data at rest be encrypted using a customer-managed AWS KMS key. The DB instance was originally launched without encryption. Which combination of steps will meet the requirement with the least downtime?
48A database administrator needs to audit all SQL statements executed on an Amazon RDS for PostgreSQL DB instance. Which service should be used to capture and log the SQL statements?
49A company is using Amazon DynamoDB with a global table that replicates data across two AWS Regions. The security team requires that all data be encrypted at rest with a customer-managed AWS KMS key. How should the company configure the KMS keys to meet this requirement?
50A company has an Amazon Redshift cluster that contains sensitive data. The security team requires that data be encrypted at rest using a customer-managed AWS KMS key. The cluster was initially launched without encryption. How can the company enable encryption with minimal downtime?
51A company wants to ensure that only specific IAM users can perform certain operations on an Amazon RDS DB instance, such as creating snapshots or modifying the instance. Which AWS feature should be used to define these permissions?
52A company stores sensitive data in an Amazon S3 bucket that is accessed by an Amazon Redshift cluster. The security team requires that the data in transit between Redshift and S3 be encrypted. Which configuration ensures this?
53Which THREE of the following are best practices for securing an Amazon DynamoDB table? (Select THREE.)
54Which TWO of the following are methods to encrypt data at rest for an Amazon RDS for Oracle DB instance? (Select TWO.)
55An IAM policy is attached to a role used by an application to access an Amazon RDS for MySQL DB instance. The DB instance is encrypted with a customer-managed KMS key. The application is unable to create a snapshot of the encrypted DB instance. Which missing permission is the most likely cause?
56A database administrator is troubleshooting connectivity to an Amazon RDS for MySQL DB instance. The application is running on an EC2 instance in the same VPC and security group. The application can connect using the endpoint shown in the exhibit. However, the security team requires that all connections be encrypted using SSL. The DBA has enabled SSL on the DB instance and modified the parameter group to set require_secure_transport to ON. The application is now failing to connect. What is the most likely cause?
57A company is running an Amazon RDS for MySQL DB instance in a VPC. The security team requires that all connections to the database use SSL/TLS. Which combination of steps should be taken to enforce this? (Choose two.)
58A financial services company stores sensitive data in an Amazon DynamoDB table. The security team requires that all data at rest be encrypted with a customer-managed key that is rotated automatically every 12 months. The company also needs to audit key usage. Which solution meets these requirements?
59A company uses Amazon Redshift for its data warehouse. The security team wants to encrypt the data at rest and ensure that only authorized users can access the encryption keys. Which AWS service should be used to manage the encryption keys?
60A company is using Amazon RDS for MySQL and wants to restrict access to the database based on the source IP address. Which AWS feature should be used to achieve this?
61A company is deploying an Amazon DynamoDB table with server-side encryption using a customer-managed AWS KMS key. The security team requires that the key be automatically rotated every year and that access to the key be logged. Which THREE steps should be taken?
62A company has an Amazon Redshift cluster that contains sensitive data. The security team wants to ensure that all data is encrypted at rest and that the encryption keys are managed by AWS. Which configuration should be used?
63A company uses an Amazon RDS for PostgreSQL database with Multi-AZ deployment. The security team wants to audit all SQL queries executed against the database for compliance purposes. Which solution should be implemented to capture and store the queries?
64A security engineer is investigating an Amazon RDS for MySQL database that was compromised. The engineer finds that the compromise was due to a SQL injection vulnerability in a web application. The web application uses a database user with full administrative privileges. What is the BEST practice to prevent such incidents in the future?
65A company uses Amazon DynamoDB for its critical application. The security team requires that all access to DynamoDB tables be logged and monitored for suspicious activity. The company also needs to be alerted when a user deletes a table. Which combination of AWS services should be used?
66A company's security policy requires that all database passwords be rotated every 90 days. The company uses AWS Secrets Manager to store database credentials for Amazon RDS. Which feature can be used to automate password rotation?
67A company is deploying a new Amazon RDS for MySQL database in a VPC. The database must be accessible only from an application server running in the same VPC. The security team also wants to ensure that the database is not accessible from the internet. Which TWO configurations are required? (Choose TWO.)
68A company is using an Amazon RDS for PostgreSQL database to store sensitive customer data. The security team requires that all data be encrypted at rest and in transit, and that access to the database is restricted to only specific applications. Currently, the database is encrypted at rest using AWS KMS, and connections are made over SSL. However, the security team wants to ensure that even if the database credentials are compromised, an attacker cannot access the database from unauthorized IP addresses. What should be done to meet this requirement?
69A company is migrating an on-premises Oracle database to Amazon RDS for Oracle. The database contains personally identifiable information (PII). The security team requires that the data be encrypted at rest using a customer-managed key stored in AWS KMS. Additionally, the team wants to ensure that the key can be rotated automatically every year. What should the company do to meet these requirements?
70A company uses Amazon Redshift for data warehousing. The security team has implemented column-level security using Redshift's column-level access controls. However, during a security audit, it is discovered that a user with SELECT privilege on a table can still see the content of a column that should be restricted. The column is defined with a GRANT statement that only allows SELECT on certain columns to specific users. What is the most likely cause of this issue?
71A company is using Amazon DynamoDB with fine-grained access control using IAM policies. The security team wants to ensure that a specific IAM role can only read the 'status' attribute from items in a table. The table is named 'Orders'. Which IAM policy statement should be used?
72A company is using an Amazon RDS for MySQL DB instance. The security team requires that all database connections be encrypted in transit. Which configuration step ensures this requirement is met?
73A company is using Amazon Redshift for data warehousing. The security team requires column-level access control so that certain users cannot view specific columns containing PII. Which approach should the data engineer implement?
74A company is using Amazon Redshift and needs to encrypt data at rest with a customer-managed key. Which TWO steps are required to enable encryption with a customer-managed AWS KMS key?
75A developer is checking the encryption status of an RDS MySQL instance. The CLI output shows StorageEncrypted is true. What does this indicate?
76A financial services company runs a critical application on Amazon RDS for PostgreSQL. The database stores sensitive customer financial data. The security team has mandated that all access to the database must be through IAM database authentication to eliminate the need for passwords. The application currently uses a master user password stored in AWS Secrets Manager. The DBA needs to implement IAM authentication without downtime. The application is deployed on Amazon ECS and connects to the database using a connection string. The DBA has already created an IAM role for the ECS task with a policy that allows rds-db:connect. The DBA has also modified the DB instance to require SSL. However, after making these changes, the application cannot connect. The error message indicates 'IAM authentication is not enabled for this user'. What step did the DBA miss?
77A small business runs a web application on a single Amazon RDS for MySQL DB instance. The application uses a master user account for all database operations. The security team is concerned about the risk of SQL injection and wants to implement the principle of least privilege. They want to create separate database users for read-only and read-write operations. The application currently uses a single connection string. The developer needs to modify the application to use two separate users. What is the correct approach to implement this securely?
78A healthcare company is migrating its patient records database to Amazon RDS for SQL Server. The database contains Protected Health Information (PHI). The compliance team requires that all PHI data be encrypted at rest and that the encryption keys be stored in a dedicated AWS CloudHSM cluster. Additionally, the database must be replicated to a second AWS region for disaster recovery. The DBA has enabled RDS encryption at rest using a KMS key, but the compliance team insists on using CloudHSM. What should the DBA do to meet the compliance requirement while maintaining disaster recovery?
79A company stores sensitive data in an Amazon RDS for PostgreSQL DB instance. The security team requires that all data at rest be encrypted. The instance is currently unencrypted. What is the simplest way to enable encryption with minimal downtime?
80A company uses an Amazon RDS for MySQL DB instance that needs to be accessed by a Lambda function. Which TWO steps should be taken to ensure secure access?
81A company is designing a secure strategy for managing Amazon RDS for Oracle encryption keys. They want to use AWS KMS with Customer Master Keys (CMKs) for encryption at rest. Which THREE best practices should they follow?
82A financial company uses Amazon DynamoDB to store customer transaction data. The compliance team requires that all data be encrypted at rest using a customer-managed AWS KMS key. Additionally, they need to ensure that the key is used only for DynamoDB and no other AWS service. How can the company meet these requirements?
83A developer needs to allow an application running on an EC2 instance to connect to an Amazon RDS for MySQL DB instance securely. Which combination of steps should the developer take?
84A security engineer is designing a VPC with an RDS instance. The database must not be accessible from the internet, but EC2 instances in a private subnet must connect. Which security group configuration is MOST secure?
85A company wants to audit all SQL statements executed on their RDS for PostgreSQL database. Which AWS service should they use?
86A company has a compliance requirement to encrypt all RDS snapshots at rest using a customer-managed KMS key. The RDS instance is already encrypted with an AWS-managed key. What is the correct procedure to ensure snapshots use the customer-managed key?
87A developer accidentally deleted an RDS database. Which action will allow the database to be restored with the least data loss?
88A company wants to enforce encryption in transit for all connections to their ElastiCache for Redis cluster. Which security measure should they implement?
89A security team needs to grant an IAM user permission to modify only the 'db_secrets' secret in AWS Secrets Manager. Which IAM policy statement is correct?
90Which TWO actions can help protect an RDS database from SQL injection attacks? (Choose 2.)
91A developer needs to connect to the RDS instance from an EC2 instance in the same VPC. The EC2 instance's security group allows outbound traffic to 0.0.0.0/0. The RDS security group inbound rules currently allow traffic from 0.0.0.0/0 on port 3306. After a security review, the company decides to restrict inbound traffic to the VPC only. Which inbound rule should be added to the RDS security group?
92A developer retrieved a database secret using the AWS CLI as shown. What is the MOST secure way to store and rotate this secret?
93A company is storing sensitive customer data in an Amazon RDS for MySQL DB instance. They need to ensure that data is encrypted at rest. What is the simplest way to achieve this?
94A company uses Amazon RDS for PostgreSQL and needs to ensure that only specific IP addresses can connect to the database. Which configuration should be used?
95A company is designing a multi-tenant application using Amazon Aurora MySQL. Each tenant's data must be isolated from others. They need to encrypt data at rest with a unique AWS KMS key per tenant. How can this be achieved?
96A company is using Amazon DynamoDB with server-side encryption enabled. They need to ensure that all access to the table is audited. Which service should be used to capture data-plane API calls?
97A company needs to rotate the master user password for an Amazon RDS for MySQL DB instance. What is the recommended way to do this without downtime?
98A security engineer needs to ensure that all access to an Amazon DynamoDB table is encrypted in transit. Which configuration achieves this?
99Which TWO of the following are methods to control access to an Amazon RDS DB instance? (Select TWO.)
100Which THREE of the following are best practices for securing an Amazon Aurora MySQL database? (Select THREE.)
101An IAM policy is attached to a user. What is the effect of this policy on the user's ability to delete the DB instance named prod-db? The policy is: ```json { "Version": "2012-10-17", "Statement": [ { "Effect": "Deny", "Action": "rds:DeleteDBInstance", "Resource": "arn:aws:rds:us-east-1:123456789012:db:prod-db" }, { "Effect": "Allow", "Action": "rds:*", "Resource": "*" } ] } ```
102An RDS DB instance has two security groups attached. Security group sg-12345678 allows inbound traffic on port 3306 from 0.0.0.0/0. Security group sg-87654321 allows inbound traffic on port 3306 from 10.0.0.0/16. What is the effective inbound access to the DB instance?
103A financial services company uses Amazon DynamoDB to store transaction records. The security team requires that all items be encrypted at rest using a customer-managed AWS KMS key. Additionally, the company must be able to audit key usage and rotation. What is the MOST secure and auditable approach?
104A developer needs to grant an IAM user the ability to perform all operations on an Amazon RDS DB instance except the ability to delete it. Which IAM policy action should be explicitly denied?
105A company uses Amazon RDS for PostgreSQL with Multi-AZ deployment. The security team wants to ensure that any access to the database is logged, including SELECT queries. What should be done to capture these logs?
106A company runs an Amazon Aurora MySQL-compatible database cluster. The security team requires that all database credentials be rotated automatically every 30 days. Which combination of AWS services can meet this requirement with minimal operational overhead?
107A developer accidentally exposed an Amazon RDS snapshot to the public. What is the quickest way to remediate this issue?
108A company uses Amazon Redshift for data warehousing. The security team requires that all data be encrypted at rest with a customer-managed key, and that the key be rotated every year. Which configuration meets these requirements?
109Which TWO actions will help protect an Amazon RDS for MySQL database from a SQL injection attack? (Select TWO.)
110Refer to the exhibit. The output is from the AWS CLI for an RDS instance. The security team suspects that the encryption key used for this DB instance has been compromised. What is the required action to re-encrypt the instance with a new key?
111Refer to the exhibit. A developer created an IAM policy with the above command and attached it to a user. What is the security implication of this policy?
112A company wants to encrypt data at rest for an existing Amazon RDS for MySQL DB instance. The database is currently unencrypted. What is the most efficient way to enable encryption?
113A security team needs to audit all SQL statements executed against an Amazon Aurora MySQL DB cluster. Which combination of actions should be taken to achieve this? (Choose TWO.)
114A company is using an Amazon DynamoDB table with a global table configuration across two AWS regions. The security team wants to ensure that all data is encrypted in transit between the regions. What should the team do?
115A company wants to audit all API calls made to its Amazon RDS DB instances. Which AWS service should be used to capture these API calls?
116A company is using Amazon DynamoDB Accelerator (DAX) for caching. The security team is concerned about data in transit between the application and DAX. What should the team do to ensure that all traffic to DAX is encrypted?
117A company is running an Amazon RDS for SQL Server DB instance with Multi-AZ deployment. The security team wants to ensure that all data at rest is encrypted using a customer-managed key stored in AWS KMS. Which steps must be taken to achieve this? (Choose THREE.)
118A company is using Amazon Aurora MySQL and needs to audit database logins. Which of the following can be used to capture login events? (Choose TWO.)
119A company is migrating an Oracle database to Amazon RDS for Oracle. Security policy requires that all database connections be encrypted in transit. The security team wants to enforce that clients must use TLS 1.2 or higher. How can this be achieved?
120A company is running an Amazon RDS for SQL Server instance with Multi-AZ deployment. The security team requires that all data at rest be encrypted. The instance was originally launched without encryption. What is the most efficient way to enable encryption at rest for this existing instance?
121A company uses Amazon DynamoDB to store session data. The security team has enabled DynamoDB Accelerator (DAX) for performance. However, they are concerned about data encryption at rest. DAX encrypts data at rest by default. The security team wants to use a customer managed key (CMK) in AWS KMS. How can this be configured?
122A company is using Amazon Aurora MySQL and needs to audit all database logins and query activity. Which feature should be enabled to meet this requirement?
123A company is using Amazon RDS for MySQL and wants to restrict access to a specific database so that an application user can only perform SELECT and INSERT operations on tables within that database. The application user already exists. Which SQL statement should be executed?
124A company is using Amazon DynamoDB with AWS Lambda to process data. The Lambda function needs to read and write items to a DynamoDB table. The security team wants to follow the principle of least privilege. Which IAM policy statement should be attached to the Lambda execution role?
125A company is using Amazon RDS for PostgreSQL and needs to ensure that all connections to the database use encryption in transit. The database is accessible over the internet. Which configuration is required?
126A company wants to ensure that an Amazon RDS for MySQL DB instance is encrypted at rest. Which action should be taken to enable encryption for the first time?
127A database administrator needs to audit all SQL statements executed on an Amazon Aurora MySQL DB cluster, including SELECT queries. Which AWS service should be used to capture and store these logs?
128A company has an Amazon RDS for PostgreSQL DB instance that needs to be accessed by an application running on an Amazon EC2 instance. Both resources are in the same VPC. The security team insists that all traffic between the application and the database be encrypted in transit. Which configuration ensures this?
129A company wants to store database credentials for an Amazon RDS instance securely. Which AWS service should be used to rotate the credentials automatically?
130A company needs to audit access to an Amazon DynamoDB table. The audit should capture which IAM user or role performed each action. Which AWS service should be used?
131A company has an Amazon DynamoDB table with a global secondary index (GSI). The security team wants to ensure that the table and the GSI are encrypted at rest. How can this be achieved?
132A company has an Amazon RDS for MySQL DB instance that is publicly accessible. The security team wants to restrict access to only specific IP addresses. Which configuration should be used?
133A company wants to encrypt an existing unencrypted Amazon RDS for PostgreSQL DB instance. What is the correct procedure?
134A company is using Amazon DynamoDB with client-side encryption using the DynamoDB Encryption Client. The encryption keys are stored in AWS KMS. The security team wants to ensure that the encryption keys can be used only by authorized applications. What should be done?
135A company is using Amazon RDS for MySQL and needs to encrypt data at rest for an existing DB instance. Which approach meets this requirement with minimal downtime?
136A company uses Amazon Aurora MySQL and needs to audit all database logins, including failed attempts. Which feature should be enabled?
137A company needs to securely store and manage the master password for their Amazon RDS for PostgreSQL instance. Which AWS service is purpose-built for managing secrets with automatic rotation?
138An application uses an Amazon RDS for MySQL database. The security team requires that all traffic to the database be encrypted in transit. Which configuration ensures this?
139A company wants to audit all SQL statements executed on their Amazon Aurora MySQL database for compliance. Which AWS feature should be enabled?
140Which TWO actions should a company take to secure an Amazon RDS for MySQL database that is accessible from the internet? (Choose two.)
141Which THREE components are required to set up IAM database authentication for an Amazon RDS for MySQL DB instance? (Choose three.)
142A security engineer runs the commands shown in the exhibit for an RDS MySQL DB instance. The engineer wants to enforce SSL connections to the database. What should the engineer do?
143A company is using Amazon RDS for MySQL with automated backups enabled. The security team requires that all backups be encrypted at rest. Which configuration ensures that new automated backups are encrypted?
144A financial company uses Amazon RDS for PostgreSQL with a custom parameter group. The security team wants to ensure that all connections to the database are encrypted in transit. Which action should the database administrator take?
145A developer is troubleshooting an issue where an IAM user cannot perform a 'DescribeTable' action on a DynamoDB table. The IAM policy attached to the user is: {"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":["dynamodb:GetItem","dynamodb:PutItem"],"Resource":"*"}]}. What is the most likely reason for the failure?
146A company wants to restrict access to an Amazon RDS for MySQL DB instance so that only applications running in a specific VPC can connect. Which solution should be implemented?
147A company needs to encrypt an existing unencrypted Amazon RDS for Oracle DB instance. Which set of steps should be followed?
148A company needs to encrypt data at rest for their Amazon Aurora PostgreSQL database. Which solution is the MOST secure and requires the least operational overhead?
149A security team is investigating a potential data breach in an Amazon RDS for SQL Server database. They need to determine which user executed a specific DELETE statement at a particular time. What should they do?
150A company wants to restrict access to an Amazon DynamoDB table so that only specific IAM users can read and write data. What is the BEST way to achieve this?
151A company hosts a critical application on Amazon RDS for PostgreSQL. The security team requires that all database connections be encrypted in transit. Which configuration step is necessary?
152A company is using Amazon RDS for Oracle with Transparent Data Encryption (TDE) enabled. They need to rotate the TDE master key. What is the correct procedure?
153Which TWO actions can be used to encrypt an existing unencrypted Amazon RDS for MySQL DB instance? (Choose 2.)
154Refer to the exhibit. An engineer runs the CLI command to check security groups attached to the RDS instance 'mydb'. The output shows only one security group. The engineer wants to ensure that only traffic from an application server with IP 10.0.1.5 is allowed to the database port 3306. Which security group rule should be added?
155A company is launching a new application that requires an Amazon RDS for PostgreSQL database. The database will store highly sensitive data, and the security team mandates that all data at rest must be encrypted. The company also requires that the encryption keys be managed by the security team using AWS CloudHSM. What is the MOST efficient way to meet these requirements?
156A company uses Amazon DynamoDB with fine-grained access control using IAM policies. A developer reports that an application role can read and write to the 'orders' table but cannot perform a Scan operation on a Global Secondary Index (GSI). The IAM policy attached to the role includes 'dynamodb:Scan' and the resource ARN for the table. What is the likely reason for this failure?
157A company wants to centrally manage database user credentials and rotate them automatically. The database is an Amazon RDS for MySQL instance. Which AWS service should be used?
158A developer is building a serverless application that uses Amazon DynamoDB. The application needs to access the database from an AWS Lambda function. The security team mandates that the Lambda function should not use long-term AWS credentials. Which TWO steps should be taken to securely grant access? (Choose TWO.)
159A company has an Amazon RDS for SQL Server DB instance that stores financial data. The security team requires that all database activity be monitored in real-time for suspicious queries. Which AWS service should be used to meet this requirement?
160A company runs an e-commerce platform on AWS using an Amazon Aurora MySQL database. The database is accessed by multiple microservices, each using a separate database user. The security team recently discovered that a developer accidentally committed database credentials to a public GitHub repository. The credentials were for a user that had write access to the database. The team immediately revoked the credentials and rotated them. However, they want to prevent such incidents from happening again. They need a solution that ensures credentials are not hardcoded in application code, are rotated automatically, and are accessible only to authorized microservices. What should they do?
161A company is using Amazon RDS for MySQL with encryption at rest enabled. The security team wants to ensure that the database backups stored in Amazon S3 are also encrypted using a customer-managed KMS key. What should be done to meet this requirement?
162A financial services company runs an Amazon Aurora PostgreSQL cluster. Compliance requires that all connections to the database use TLS with a minimum version of TLS 1.2, and that any non-encrypted connections are rejected. The security team has already enabled the cluster parameter rds.force_ssl. Which additional step must be taken to enforce TLS 1.2 or higher for all client connections?
163A company runs an Amazon RDS for SQL Server DB instance in a private subnet. A security engineer must ensure that all connections to the database are encrypted in transit and that the DB instance rejects any unencrypted client connections. The company uses a self-signed certificate for the DB instance. What should the security engineer do to meet these requirements?
164A company uses Amazon Aurora PostgreSQL and wants to implement fine-grained access control for a table containing sensitive data. The security team needs to allow users in the 'analysts' role to see only rows where the 'region' column matches their assigned region, which is stored in a session variable. They also need to ensure that the filtering cannot be bypassed by users with direct table access. Which approach should a database specialist recommend?
165A company stores sensitive data in an Amazon DynamoDB table. The security team wants to ensure that all data at rest is encrypted using a customer managed key in AWS KMS, and that the key is automatically rotated every year. They also need to monitor who uses the key. Which combination of actions should a database specialist take to meet these requirements?
166A company uses Amazon Redshift for its data warehouse. The security team wants to ensure that all data stored in the cluster is encrypted at rest using a hardware security module (HSM) to meet regulatory requirements. Which encryption option should be used?
167A company uses Amazon DynamoDB with a table that contains sensitive customer records. The security team wants to implement fine-grained access control so that each application user can only read and write items where the partition key matches their own user ID. The team also wants to ensure that the user cannot access items belonging to other users even if they craft their own requests. Which TWO actions should a database specialist take to meet these requirements? (Choose two.)
168A healthcare company stores sensitive patient data in an Amazon RDS for Oracle DB instance. The security team requires that all data at rest be encrypted using a customer-managed AWS KMS key (CMK) that they control, and that the key be rotated annually. They also need to ensure that if the CMK is disabled, the database becomes inaccessible. Which configuration should the database specialist implement?
169A company is using Amazon RDS for Oracle and needs to implement Transparent Data Encryption (TDE) for a new DB instance. The security team wants to use AWS KMS to manage the encryption keys. Which two actions must be performed to enable TDE with KMS for the RDS for Oracle instance? (Choose two.)
170A security engineer manages an Amazon Aurora PostgreSQL cluster that stores regulated data. Audit requirements mandate that all data at rest be encrypted with a customer-managed AWS KMS key, and that the key be automatically rotated every year. The engineer creates a new KMS customer-managed key with automatic rotation enabled and now needs to apply it to the existing cluster. The cluster currently uses an AWS-managed key (aws/rds). What should the engineer do to meet these requirements with the LEAST operational effort?
171A financial services company uses an Amazon Aurora PostgreSQL cluster to store account transaction records. A security policy mandates that all data be encrypted at rest with a customer-managed AWS KMS key, and that the company retain full control over key rotation and access policies. The database was created without encryption. What should a database specialist do to meet the encryption requirement with the LEAST operational effort?
172A financial services company runs an Amazon Aurora PostgreSQL cluster. The security team must ensure that all connections to the database use TLS and that the database rejects any unencrypted connections. The team has already obtained the rds-ca-2019 certificate and configured the client applications to use SSL. Which additional step is required to enforce TLS for all connections?
173A company stores sensitive data in an Amazon DynamoDB table. The security team requires that all data be encrypted at rest using a customer managed AWS KMS key (CMK) and that they can audit all decryption attempts. Which combination of actions should be taken to meet these requirements?
174A company uses Amazon RDS for SQL Server with Transparent Data Encryption (TDE) enabled. The security team wants to ensure that the TDE certificates and private keys are managed by the company and not by AWS. What should the team do to meet this requirement?
175A financial services company runs an Amazon Aurora PostgreSQL cluster. The security team requires that all connections to the database be encrypted in transit. They have configured the cluster to use a custom parameter group. Which combination of steps should they take to enforce TLS for all client connections?
176A company uses Amazon DynamoDB to store user session data. The security team wants to ensure that all data stored in the table is encrypted at rest using a customer-managed AWS KMS key so they can control key rotation and audit key usage. The table currently uses the AWS owned key. What should a database specialist do to meet this requirement?
177A company is using Amazon Aurora MySQL and wants to implement fine-grained access control for its database users. The security team requires that specific users can only access certain columns in a table and that all failed login attempts are logged. Which two actions should the team take to meet these requirements? (Choose two.)
178A production Amazon RDS for Oracle DB instance is encrypted with an AWS managed key (aws/rds). The security team now requires that all data at rest be encrypted with a customer managed AWS KMS key so that key rotation and access can be controlled. What is the MOST operationally efficient way to meet this requirement?
179A financial services company runs an Amazon Aurora PostgreSQL cluster. The security team must ensure that all data at rest, including automated backups and snapshots, is encrypted with a customer-managed AWS KMS key so they can control key rotation and access policies. They also need to audit all key usage. Which combination of steps should they take?
180A company uses Amazon Redshift for its data warehouse. The security team wants to ensure that all data in the cluster is encrypted at rest using a customer-managed key (CMK) from AWS KMS. They also need to ensure that the cluster's snapshots are encrypted with the same key. Which action should they take?
181A company uses Amazon Aurora MySQL and wants to implement database activity monitoring for compliance. The security team must capture all SQL statements executed against the database, including who executed them and when, and store the logs in a centralized location for at least one year. The solution must minimize performance impact on the database. Which approach should a database specialist recommend?
182A healthcare company stores sensitive patient data in an Amazon DynamoDB table. The security team wants to ensure that only application roles running on Amazon EC2 instances in a specific VPC can access the table, and that all access is logged. They also want to prevent any access from outside the VPC. Which solution meets these requirements?
183A financial services company uses Amazon DynamoDB to store sensitive customer transaction data. The security team wants to ensure that all data written to the table is encrypted using a customer managed key in AWS KMS, and that they can audit key usage. Which configuration should they implement?
184A company stores sensitive records in an Amazon DynamoDB table. The security team wants to ensure that all data in the table is encrypted at rest using a key that the company manages and can audit independently of AWS. What should the company do?
185A security engineer needs to grant an application running on Amazon EC2 access to an Amazon RDS for PostgreSQL database without storing long-term database passwords on the instance. The application authenticates to AWS using an IAM role attached to the instance profile. Which approach should the engineer use?
186A healthcare company stores sensitive patient data in an Amazon RDS for SQL Server database. The security team requires that all data at rest be encrypted using a customer-managed AWS KMS key (CMK) and that the key be rotated annually. The database is currently unencrypted. Which sequence of actions should a database specialist take to meet these requirements with minimal downtime?
187A company runs an Amazon RDS for SQL Server DB instance in a private subnet. The security team wants to ensure that all administrative access to the database is audited and that only approved IP ranges can connect. Which two actions should be taken? (Choose two.)
188A company is using Amazon RDS for Oracle and wants to implement fine-grained access control for different application teams. They need to ensure that each team can only access specific rows and columns in a table based on their role. They also want to audit all access to sensitive columns. Which two AWS features or configurations should they use? (Choose two.)
189A company uses Amazon DynamoDB to store user session data. The security team wants to implement fine-grained access control so that each user can only access items where the partition key matches their own user ID. The team also wants to ensure that all data is encrypted at rest using a customer-managed AWS KMS key. Which two actions should the team take to meet these requirements? (Choose two.)
190A company runs an Amazon DynamoDB table containing sensitive financial records. The security team wants to ensure that only a specific IAM role can read data from the table, and that all read requests are logged in AWS CloudTrail. The role is used by an AWS Lambda function. Which combination of actions will achieve these requirements?
191A company uses an Amazon RDS for SQL Server DB instance with Transparent Data Encryption (TDE) enabled. The security team wants to ensure that the TDE certificates and private keys are stored in a secure, centralized location and can be audited. Which AWS service should they integrate with to meet these requirements?
192A company uses Amazon DocumentDB (with MongoDB compatibility) to store sensitive data. The security team wants to ensure that all data at rest is encrypted using a key that the company can rotate and audit. They also want to minimize operational overhead. Which solution should they implement?
193A company uses Amazon RDS for SQL Server and wants to audit all login attempts and database operations for compliance. The security team needs to capture detailed logs, including successful and failed logins, and store them for 90 days. Which solution should they implement?
194A company uses Amazon DynamoDB to store user session data. The security team wants to ensure that all data is encrypted at rest using a customer managed key (CMK) in AWS KMS, and that they can audit key usage. They also want to minimize operational overhead. Which approach should they take?
195A company uses Amazon Redshift and needs to implement row-level security so that users from the sales department can only see rows where the region column matches their assigned region. The security team wants to enforce this at the database level without modifying application queries. Which feature should they use?
196A company uses Amazon RDS for SQL Server with Transparent Data Encryption (TDE) enabled using a customer-managed AWS KMS key. The security team wants to ensure that the TDE certificate and private key are protected and that access is audited. Which additional configuration should they implement?
197A company uses Amazon Aurora PostgreSQL and wants to implement row-level security (RLS) to restrict access to rows based on the current database user. The security team requires that the RLS policies are enforced for all users, including the table owner, and that the policies are applied automatically when new tables are created in a specific schema. Which combination of actions should a database specialist take to meet these requirements?
198A company has an Amazon Redshift cluster that contains sensitive data. The security team wants to ensure that all connections to the cluster are encrypted in transit and that only authorized users can connect. They have already configured the cluster in a private VPC subnet. Which additional step should the database specialist take to enforce encryption in transit?
199A company uses Amazon DynamoDB to store user session data. The security team wants to enforce that all data written to the table is encrypted with a customer-managed AWS KMS key, and that only specific IAM roles can read the data. Which combination of actions should they take?
200A financial services company runs Amazon RDS for SQL Server with Transparent Data Encryption (TDE) enabled using a customer-managed KMS key. An auditor asks how the database encryption keys are protected and rotated. The security team must explain which component actually performs the encryption and how key rotation is handled. Which statement is correct?
201A security team is using Amazon RDS for Oracle with Transparent Data Encryption (TDE) enabled. They need to rotate the encryption keys regularly without causing downtime. The RDS instance is using the Oracle Enterprise Edition with the Advanced Security Option. What is the correct method to rotate the TDE master encryption key?
202A healthcare company stores patient records in an Amazon DynamoDB table. The security team must ensure that only authenticated users from a specific Amazon Cognito identity pool can read and write items, and that each user can access only their own records. They decide to use IAM policies with fine-grained access control. Which combination of features must they use to meet these requirements?
203A company runs an Amazon RDS for Oracle DB instance in a private subnet. The security team wants to allow only the application servers in a specific VPC security group to connect to the database on port 1521, and to block all other traffic. What is the correct way to configure this?
204A company runs an Amazon RDS for Oracle DB instance. The security team wants to ensure that all data in the database is encrypted at rest using a key that the company controls and can audit. Which option should the company choose?
205A company runs an Amazon RDS for SQL Server DB instance. The security team wants to ensure that all connections to the database are encrypted using SSL/TLS. They have already created a custom option group and added the SSL option. Which additional step is required to enforce SSL/TLS for all connections?
206A company uses Amazon Redshift and has implemented column-level access control using Redshift's column-level privileges. The security team now wants to ensure that when a user queries a table, they can only see rows that match their department. The company already uses an IAM role for Redshift Spectrum and has a mapping of users to departments in a separate table. Which Redshift feature should be used to enforce row-level security dynamically based on the user's department?
207A company uses Amazon Redshift for a data warehouse. The security team requires that all data in the cluster be encrypted at rest using a hardware security module (HSM) to meet compliance requirements. The cluster is currently unencrypted. What should the company do to meet this requirement?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Be able to select the exact configuration that satisfies an encryption or access-control requirement: KMS key policies, TLS enforcement parameters, security group references, and IAM authentication. The single most important thing is knowing which setting enforces the requirement versus which merely permits it.
The Courseiva DBS-C01 question bank contains 207 questions in the Database Security domain, covering the 18% of the exam attributed to this domain in the official Amazon Web Services blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Database Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included