Courseiva
Database SecurityhardMultiple ChoiceObjective-mapped

DBS-C01 Database Security Practice Question

A company is migrating its on-premises Oracle database to Amazon RDS for Oracle. The database contains sensitive data that must be encrypted at rest and in transit. The security team also requires that the encryption keys be rotated every year. The DBA has enabled encryption at rest using a customer-managed KMS key and SSL/TLS for in-transit encryption. What additional step is needed to meet the key rotation requirement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable automatic KMS key rotation for the customer-managed key.

Enable automatic KMS key rotation for the customer-managed key. AWS KMS supports automatic annual rotation of customer-managed keys, which meets the key rotation requirement without manual intervention. Option A is incorrect because manually creating a new key and updating the RDS instance each year is an unnecessary manual process when automatic rotation is available. Option B is incorrect because RDS option groups do not control encryption key rotation; they are used for managing additional database features. Option C is incorrect because CloudHSM is not integrated with RDS for key management; KMS is the service used for RDS encryption at rest.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Manually create a new KMS key every year and update the RDS instance to use the new key.

    Why it's wrong here

    Manual rotation is possible but not automatic; also requires updating the instance.

  • Configure the RDS option group to rotate the encryption key.

    Why it's wrong here

    Option group does not handle key rotation.

  • Use an AWS CloudHSM key and configure automatic rotation.

    Why it's wrong here

    CloudHSM does not integrate with RDS encryption.

  • Enable automatic KMS key rotation for the customer-managed key.

    Why this is correct

    KMS can rotate the key automatically every year.

About these practice questions

This DBS-C01 question is part of Courseiva's 1,663-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DBS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DBS-C01 exam.