DBS-C01 Database Security Practice Question
A company is migrating an on-premises Oracle database to Amazon RDS for Oracle. The security team requires that all data be encrypted at rest using a key stored in AWS CloudHSM. What must be done to meet this requirement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Oracle Transparent Data Encryption (TDE) with CloudHSM as the key store.
Use Oracle Transparent Data Encryption (TDE) with CloudHSM as the key store. RDS for Oracle supports TDE, which allows encryption at rest using keys stored in CloudHSM. Option A is incorrect because RDS encryption at rest uses AWS KMS, and while KMS can use a CloudHSM key as a custom key store, the question specifies the key must be stored in CloudHSM directly, which is achieved via TDE integration. Option B is incorrect because RDS does not support custom file system encryption; encryption at rest is managed at the database or instance level. Option C is incorrect because SSL/TLS provides encryption in transit, not at rest.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable RDS encryption at rest using a KMS key backed by CloudHSM.
Why it's wrong here
KMS custom key stores can use CloudHSM, but RDS encryption uses KMS, not CloudHSM directly.
- ✗
Create an encrypted file system on the RDS instance using CloudHSM.
Why it's wrong here
RDS does not allow file system access.
- ✗
Configure SSL/TLS for the database connection.
Why it's wrong here
SSL is for in-transit, not at rest.
- ✓
Use Oracle Transparent Data Encryption (TDE) with CloudHSM as the key store.
Why this is correct
RDS Oracle supports TDE with CloudHSM.
Go deeper
Related to this question
About these practice questions
This DBS-C01 question is part of Courseiva's 1,663-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DBS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DBS-C01 exam.