Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer is setting up a data pipeline using AWS DMS to migrate data from an on-premises database to Amazon RDS for MySQL. The data must be encrypted in transit. Which TWO options can the engineer use? (Choose TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable SSL encryption on the DMS endpoint

Option B is correct because AWS DMS endpoints for MySQL support SSL/TLS, and enabling the SSL encryption setting on the source and target endpoints causes DMS to negotiate an encrypted connection to the database, satisfying the in-transit encryption requirement. Option C is correct because a VPN connection (AWS Site-to-Site VPN) creates an IPsec-encrypted tunnel between the on-premises network and the AWS VPC, protecting data in transit as it crosses the public internet to reach Amazon RDS for MySQL. Option A is not correct because VPC peering only connects AWS VPCs to each other and does not extend to an on-premises network, so it cannot secure this migration path. Option D is not correct because AWS KMS provides encryption at rest for stored data and keys, not encryption of the DMS network connection in transit. Option E is not correct because a VPC endpoint (AWS PrivateLink) provides private connectivity to AWS services within AWS, not an encrypted path from an on-premises database to RDS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use VPC peering between on-premises and AWS

    Why it's wrong here

    VPC peering links two VPCs and cannot extend to an on-premises database, so it does not apply to this migration. Peering is the right mechanism when connecting two AWS VPCs privately, for example linking a DMS subnet to an application VPC within the same region.

  • ✓

    Enable SSL encryption on the DMS endpoint

    Why this is correct

    AWS DMS endpoints expose an SSL mode setting; enabling it encrypts replication traffic between the source, replication instance and target. This directly satisfies the in-transit encryption requirement for the on-premises to Amazon RDS for MySQL migration.

  • ✓

    Set up a VPN connection between on-premises and AWS

    Why this is correct

    A VPN connection encrypts all traffic between the on-premises network and AWS, including the DMS replication instance's connection to the source database, satisfying the in-transit encryption requirement. It operates at the network layer, so DMS traffic traverses the encrypted tunnel without additional endpoint configuration.

  • ✗

    Use KMS to encrypt the DMS connection

    Why it's wrong here

    KMS encrypts data at rest — RDS storage, snapshots and DMS target volumes — and does not secure the wire protocol between endpoints. It is the right control when the requirement is envelope encryption of stored objects under a customer-managed key, not transport confidentiality.

  • ✗

    Use a VPC endpoint for DMS

    Why it's wrong here

    A VPC endpoint provides private connectivity to AWS services over the AWS network, but it does not encrypt the DMS replication stream itself. It is the correct choice for keeping traffic off the public internet when reaching services such as S3 or Secrets Manager from within a VPC.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.