Courseiva
Database SecuritymediumMultiple SelectObjective-mapped

DBS-C01 Database Security Practice Question

A company is designing a security strategy for Amazon RDS for SQL Server. Which TWO actions should be taken to encrypt data at rest? (Choose TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable Transparent Data Encryption (TDE) on the SQL Server database.

For Amazon RDS for SQL Server, encryption at rest can be achieved using two methods: enabling RDS encryption at rest with AWS KMS (option E) or enabling Transparent Data Encryption (TDE) natively within SQL Server (option B). Option A is incorrect because EBS encryption is automatically handled by RDS when you enable encryption at rest via KMS, but you cannot enable EBS encryption directly on the underlying volumes. Option C is incorrect because AWS CloudHSM can be used for key management but is not required for RDS encryption at rest. Option D is incorrect because SSL/TLS encrypts data in transit, not at rest.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable Amazon EBS encryption on the underlying volumes.

    Why it's wrong here

    Incorrect. While RDS uses EBS volumes, enabling RDS encryption at rest (Option E) automatically encrypts the underlying EBS volumes. You do not need to separately enable EBS encryption.

  • Enable Transparent Data Encryption (TDE) on the SQL Server database.

    Why this is correct

    Correct. Transparent Data Encryption (TDE) is a SQL Server feature that encrypts data at rest within the database files.

  • Use AWS CloudHSM to store encryption keys.

    Why it's wrong here

    Incorrect. AWS CloudHSM is not required for RDS encryption at rest; AWS KMS is used to manage encryption keys.

  • Enable SSL/TLS for connections.

    Why it's wrong here

    Incorrect. SSL/TLS encrypts data in transit between clients and the database, not data at rest.

  • Enable RDS encryption at rest using AWS KMS.

    Why this is correct

    Correct. Enabling RDS encryption at rest uses AWS KMS to encrypt the underlying storage, automated backups, and snapshots.

About these practice questions

One of 1,663 original DBS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DBS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DBS-C01 exam.