DEA-C01 Data Security and Governance Practice Question
A data engineer is setting up a data pipeline using AWS DMS to migrate data from an on-premises database to Amazon RDS for MySQL. The data must be encrypted in transit. Which TWO options can the engineer use? (Choose TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable SSL encryption on the DMS endpoint
Option B is correct because AWS DMS endpoints for MySQL support SSL/TLS, and enabling the SSL encryption setting on the source and target endpoints causes DMS to negotiate an encrypted connection to the database, satisfying the in-transit encryption requirement. Option C is correct because a VPN connection (AWS Site-to-Site VPN) creates an IPsec-encrypted tunnel between the on-premises network and the AWS VPC, protecting data in transit as it crosses the public internet to reach Amazon RDS for MySQL. Option A is not correct because VPC peering only connects AWS VPCs to each other and does not extend to an on-premises network, so it cannot secure this migration path. Option D is not correct because AWS KMS provides encryption at rest for stored data and keys, not encryption of the DMS network connection in transit. Option E is not correct because a VPC endpoint (AWS PrivateLink) provides private connectivity to AWS services within AWS, not an encrypted path from an on-premises database to RDS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use VPC peering between on-premises and AWS
Why it's wrong here
VPC peering links two VPCs and cannot extend to an on-premises database, so it does not apply to this migration. Peering is the right mechanism when connecting two AWS VPCs privately, for example linking a DMS subnet to an application VPC within the same region.
- ✓
Enable SSL encryption on the DMS endpoint
Why this is correct
AWS DMS endpoints expose an SSL mode setting; enabling it encrypts replication traffic between the source, replication instance and target. This directly satisfies the in-transit encryption requirement for the on-premises to Amazon RDS for MySQL migration.
- ✓
Set up a VPN connection between on-premises and AWS
Why this is correct
A VPN connection encrypts all traffic between the on-premises network and AWS, including the DMS replication instance's connection to the source database, satisfying the in-transit encryption requirement. It operates at the network layer, so DMS traffic traverses the encrypted tunnel without additional endpoint configuration.
- ✗
Use KMS to encrypt the DMS connection
Why it's wrong here
KMS encrypts data at rest — RDS storage, snapshots and DMS target volumes — and does not secure the wire protocol between endpoints. It is the right control when the requirement is envelope encryption of stored objects under a customer-managed key, not transport confidentiality.
- ✗
Use a VPC endpoint for DMS
Why it's wrong here
A VPC endpoint provides private connectivity to AWS services over the AWS network, but it does not encrypt the DMS replication stream itself. It is the correct choice for keeping traffic off the public internet when reaching services such as S3 or Secrets Manager from within a VPC.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.