A data engineer is configuring an AWS Glue job that reads from an Amazon RDS for MySQL database and writes to Amazon S3. The security team requires that the data be encrypted in transit between AWS Glue and Amazon RDS. Which action should the engineer take to meet this requirement?
For JDBC connections to RDS for MySQL, encryption in transit is enabled by setting sslMode=REQUIRED in the JDBC URL and providing the RDS CA certificate for validation. This ensures that the connection between AWS Glue and RDS is encrypted using SSL/TLS. This is the standard method to enforce encryption in transit for Glue JDBC connections.
Why this answer
To encrypt data in transit between AWS Glue and Amazon RDS for MySQL, the JDBC connection must be configured to use SSL. Setting sslMode=REQUIRED in the JDBC URL and providing the RDS root certificate ensures that the connection is encrypted and the server certificate is validated. This is the correct approach for meeting the encryption in transit requirement.
Exam trap
The trap here is confusing encryption at rest with encryption in transit, or assuming that IAM policies can enforce SSL for database connections.