A company uses Amazon RDS for MySQL to store financial data. A compliance requirement mandates that all database connections must be encrypted. Which configuration step is necessary?
This is correct. To enforce encrypted connections for RDS MySQL, you must modify the DB parameter group to require SSL/TLS by setting parameters such as 'require_secure_transport' to 1. While the exact parameter name may vary, the intent is to enforce encryption in transit.
Why this answer
For Amazon RDS for MySQL, the parameter require_secure_transport controls whether the DB instance accepts only SSL/TLS-encrypted connections. Setting it to 1 enforces encryption for all client connections, satisfying the compliance mandate. This is the direct, database-level control for connection encryption, distinct from storage encryption or network isolation.
Exam trap
DEA-C01 often tests the confusion between encryption at rest (storage encryption) and encryption in transit (require_secure_transport), leading candidates to pick the storage encryption option for a connection-encryption requirement.
How to eliminate wrong answers
Option B is wrong because placing the DB instance in a private subnet restricts network reachability but does not encrypt connections — clients in the same VPC can still connect without TLS. Option C is wrong because enabling encryption at creation time encrypts data at rest (storage), not data in transit between clients and the database. Option D is wrong because security group rules filter source IPs and ports but do not enforce TLS on the connection itself.