Courseiva

DEA-C01 Amazon RDS encryption at rest Practice Question

A company uses Amazon RDS for MySQL to store financial data. A compliance requirement mandates that all database connections must be encrypted. Which configuration step is necessary?

⚠ Common exam trap

DEA-C01 often tests the confusion between encryption at rest (storage encryption) and encryption in transit (require_secure_transport), leading candidates to pick the storage encryption option for a connection-encryption requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set the RDS parameter require_secure_transport to 1.

For Amazon RDS for MySQL, the parameter require_secure_transport controls whether the DB instance accepts only SSL/TLS-encrypted connections. Setting it to 1 enforces encryption for all client connections, satisfying the compliance mandate. This is the direct, database-level control for connection encryption, distinct from storage encryption or network isolation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Set the RDS parameter require_secure_transport to 1.

    Why this is correct

    This is correct. To enforce encrypted connections for RDS MySQL, you must modify the DB parameter group to require SSL/TLS by setting parameters such as 'require_secure_transport' to 1. While the exact parameter name may vary, the intent is to enforce encryption in transit.

  • ✗

    Create the RDS DB instance in a private subnet.

    Why it's wrong here

    A private subnet restricts network reachability but does not encrypt traffic; connections inside the VPC remain plaintext. Encryption in transit requires forcing SSL/TLS via a parameter group setting such as require_secure_transport. Private subnets would be the right step for isolating the database from public internet access, not for meeting encryption mandates.

  • ✗

    Enable encryption for the RDS DB instance at creation time.

    Why it's wrong here

    Enabling instance encryption at creation encrypts data at rest, not connections. The requirement mandates encrypted connections, which needs parameter group settings forcing SSL/TLS and clients connecting with the SSL option. Encryption at rest cannot be enabled after creation without snapshot restoration.

  • ✗

    Configure the VPC security group to only allow traffic from certain IPs.

    Why it's wrong here

    Restricting source IPs in a security group controls network reachability, not transport encryption; plaintext MySQL traffic from an allowed address still traverses unencrypted. It is tempting because security groups are the standard tool for limiting database access, and would be correct when the requirement is to prevent connections from untrusted networks rather than to encrypt them.

About these practice questions

Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.