Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer is setting up an Amazon RDS for MySQL database. The compliance team requires that all data at rest be encrypted. What must the engineer do to enable encryption for this database?

⚠ Common exam trap

DEA-C01 often tests the misconception that encryption can be enabled on an existing RDS instance by modifying it, when in fact it must be set at creation time or via snapshot restore.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Specify an AWS KMS key when launching the DB instance

For Amazon RDS, encryption at rest must be enabled at the time of DB instance creation by specifying an AWS KMS key. Once the DB instance is created, you cannot enable encryption by simply modifying the instance; you would need to create an encrypted snapshot and restore it to a new encrypted instance. Therefore, the engineer must specify a KMS key when launching the DB instance to meet the compliance requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Specify an AWS KMS key when launching the DB instance

    Why this is correct

    Specifying a customer-managed AWS KMS key at DB instance creation enables encryption at rest for the underlying storage, volumes, snapshots and read replicas, satisfying the compliance requirement. Encryption cannot be enabled retroactively on an existing unencrypted instance; it must be set at launch.

  • ✗

    Enable encryption after the DB instance is created by modifying the DB instance

    Why it's wrong here

    RDS encryption can only be enabled when the DB instance is created; modifying an existing unencrypted instance cannot turn it on. The workaround is snapshot, copy with encryption, restore. It tempts because modification works for many other settings, such as instance class or backup retention.

  • ✗

    Use AWS Secrets Manager to store the encryption key and attach it to the DB instance

    Why it's wrong here

    Secrets Manager stores and rotates credentials, not the KMS key that encrypts RDS storage volumes. Encryption at rest is configured through the KMS key selected at creation. Storing a key in Secrets Manager would suit application credential management, not enabling storage encryption.

  • ✗

    Encrypt the underlying EBS volumes after the instance is created

    Why it's wrong here

    RDS manages its own storage; the underlying EBS volumes are not exposed for direct encryption, and encrypting them post-creation cannot be done. It tempts because EBS encryption is the mechanism for EC2 volumes, so it would be correct for a self-managed database on EC2.

About these practice questions

This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.