DBS-C01 Amazon RDS Encryption Practice Question
A company is launching a new application that requires an Amazon RDS for PostgreSQL database. The database will store highly sensitive data, and the security team mandates that all data at rest must be encrypted. The company also requires that the encryption keys be managed by the security team using AWS CloudHSM. What is the MOST efficient way to meet these requirements?
⚠ Common exam trap
Candidates may assume TDE applies to all RDS engines, but TDE is only supported for Oracle and SQL Server, not PostgreSQL or MySQL.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS KMS with a customer-managed key (CMK) for RDS encryption.
Amazon RDS for PostgreSQL does not support Transparent Data Encryption (TDE). TDE is only available for Oracle and SQL Server. The most efficient way to meet the requirements is to use RDS encryption with a customer-managed key (CMK) in AWS KMS, which encrypts the underlying storage and automated backups. The security team can manage the CMK via CloudHSM by using a KMS custom key store, thus satisfying the key management requirement. Option A is incorrect because EBS encryption is not directly applicable to RDS instances; RDS encryption uses KMS. Option B is incorrect because TDE is not supported for PostgreSQL. Option D is incorrect because client-side encryption introduces application changes and does not ensure encryption at rest within the database.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable EBS encryption on the RDS instance's underlying volumes using a KMS key.
Why it's wrong here
EBS encryption is not available for RDS instances; RDS encryption uses KMS, not EBS.
- ✗
Enable Transparent Data Encryption (TDE) using a CloudHSM key in the RDS instance.
Why it's wrong here
TDE is not supported for Amazon RDS for PostgreSQL; it is only available for Oracle and SQL Server.
- ✓
Use AWS KMS with a customer-managed key (CMK) for RDS encryption.
Why this is correct
RDS encryption with a customer-managed KMS key encrypts data at rest and can be backed by CloudHSM via custom key store.
- ✗
Implement client-side encryption in the application before writing data to the database.
Why it's wrong here
Client-side encryption requires application changes and does not encrypt data at rest within the database itself.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DBS-C01 question is part of Courseiva's 1,663-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DBS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DBS-C01 exam.