A data engineer is responsible for an Amazon Redshift cluster that stores financial data. The security team requires that all connections to the cluster from outside the VPC use SSL, and that the cluster's audit logs capture connection and user activity. The engineer has already enabled audit logging to Amazon S3. Which additional configuration should the engineer apply to meet the SSL requirement?
The require_ssl parameter in a Redshift parameter group enforces SSL for all connections to the cluster. When set to true, clients that do not use SSL are rejected. This is the standard cluster-level setting for meeting encryption-in-transit requirements, and it applies to connections from outside the VPC as well as inside, ensuring consistent enforcement.
Why this answer
The require_ssl parameter in the Redshift parameter group is the correct way to enforce SSL for all connections to the cluster. When set to true, any client that attempts to connect without SSL is rejected. This directly meets the security team's requirement for encrypted connections from outside the VPC and works alongside audit logging, which the engineer has already enabled.
Exam trap
The trap here is confusing IAM policies and VPC endpoints with database-level SSL enforcement, when Redshift uses a cluster parameter for this purpose.