DEA-C01 Data Security and Governance Practice Question
A data engineer is setting up an Amazon RDS for MySQL database. The compliance team requires that all data at rest be encrypted. What must the engineer do to enable encryption for this database?
⚠ Common exam trap
DEA-C01 often tests the misconception that encryption can be enabled on an existing RDS instance by modifying it, when in fact it must be set at creation time or via snapshot restore.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Specify an AWS KMS key when launching the DB instance
For Amazon RDS, encryption at rest must be enabled at the time of DB instance creation by specifying an AWS KMS key. Once the DB instance is created, you cannot enable encryption by simply modifying the instance; you would need to create an encrypted snapshot and restore it to a new encrypted instance. Therefore, the engineer must specify a KMS key when launching the DB instance to meet the compliance requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Specify an AWS KMS key when launching the DB instance
Why this is correct
Specifying a customer-managed AWS KMS key at DB instance creation enables encryption at rest for the underlying storage, volumes, snapshots and read replicas, satisfying the compliance requirement. Encryption cannot be enabled retroactively on an existing unencrypted instance; it must be set at launch.
- ✗
Enable encryption after the DB instance is created by modifying the DB instance
Why it's wrong here
RDS encryption can only be enabled when the DB instance is created; modifying an existing unencrypted instance cannot turn it on. The workaround is snapshot, copy with encryption, restore. It tempts because modification works for many other settings, such as instance class or backup retention.
- ✗
Use AWS Secrets Manager to store the encryption key and attach it to the DB instance
Why it's wrong here
Secrets Manager stores and rotates credentials, not the KMS key that encrypts RDS storage volumes. Encryption at rest is configured through the KMS key selected at creation. Storing a key in Secrets Manager would suit application credential management, not enabling storage encryption.
- ✗
Encrypt the underlying EBS volumes after the instance is created
Why it's wrong here
RDS manages its own storage; the underlying EBS volumes are not exposed for direct encryption, and encrypting them post-creation cannot be done. It tempts because EBS encryption is the mechanism for EC2 volumes, so it would be correct for a self-managed database on EC2.
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.