Courseiva

DEA-C01 Data Security and Governance Practice Question

A company uses Amazon RDS for MySQL to store transactional data. The database contains sensitive financial information. The company's security policy requires that all data at rest be encrypted using a customer-managed KMS key. The database was originally launched without encryption at rest. The security team now needs to enable encryption without significant downtime. What should they do?

⚠ Common exam trap

DEA-C01 often tests the misconception that you can enable encryption on an existing RDS instance by modifying it, when in fact encryption must be applied at creation or via snapshot restore, leading candidates to choose the modify option.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a snapshot of the database, copy the snapshot with encryption enabled, and restore a new DB instance from the encrypted snapshot.

RDS for MySQL does not support enabling encryption at rest on an existing unencrypted DB instance. The only supported method is to take a snapshot, copy the snapshot with encryption enabled using a customer-managed KMS key, and then restore a new DB instance from that encrypted snapshot. This approach requires a brief downtime during the switchover but avoids a full data migration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a snapshot of the database, copy the snapshot with encryption enabled, and restore a new DB instance from the encrypted snapshot.

    Why this is correct

    RDS does not support encrypting an existing unencrypted instance in place. Snapshot-copy with encryption re-encrypts the data under a customer-managed KMS key, and restoring creates a new encrypted instance, meeting the policy with only the brief downtime of a snapshot restore.

  • ✗

    Enable encryption by modifying the DB instance's storage type to 'encrypted'.

    Why it's wrong here

    Storage type selects gp2, gp3 or io1 performance characteristics; it carries no encryption attribute, so no encrypted storage type exists to switch to. Encryption at rest is fixed at instance creation. Snapshot, copy with encryption using the customer-managed KMS key, then restore is the supported route.

  • ✗

    Use the AWS DMS (Database Migration Service) to migrate data to a new encrypted RDS instance.

    Why it's wrong here

    While AWS DMS can migrate data to a new encrypted RDS instance, it fails this scenario because the security policy requires encryption at rest using a customer-managed KMS key *without significant downtime*. DMS requires a full table-level migration, which, for a large transactional database, introduces prolonged replication lag and a cutover window that violates the low-downtime requirement. This option is tempting because DMS is the standard tool for migrating between RDS instances with different configurations, such as enabling encryption, and would be correct if the business could tolerate a scheduled maintenance window.

  • ✗

    Modify the DB instance and enable encryption under the 'Storage' settings.

    Why it's wrong here

    RDS does not permit enabling storage encryption on an existing unencrypted instance; the modify API exposes no such toggle. The supported path is snapshotting, encrypting the snapshot copy with the customer-managed KMS key, then restoring. Modification is the right tool for instance class, storage size or parameter changes.

About these practice questions

One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.