Question 213 of 1,663
DBS-C01 DocumentDB Parameter Groups Practice Question
A company is using Amazon DocumentDB (with MongoDB compatibility) for a content management system. The security team requires that all data be encrypted at rest and in transit. The DocumentDB cluster is already encrypted at rest using AWS KMS. To enforce encryption in transit, the security team wants to ensure that all client connections use TLS. The team has enabled the 'tls' parameter in the cluster parameter group. However, a developer reports that they can still connect to the cluster without specifying TLS options using the mongo shell. The developer is connecting from an EC2 instance in the same VPC. The security group for the DocumentDB cluster allows inbound traffic on port 27017 from the EC2 instance's security group. What is the most likely reason the developer can connect without TLS?
⚠ Common exam trap
Candidates often overlook that parameter group changes in DocumentDB require a cluster reboot to take effect, and that enabling the 'tls' parameter does not immediately force TLS on all connections.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The 'tls' parameter was not applied to the cluster because the parameter group was not associated with the cluster or the cluster was not rebooted.
In Amazon DocumentDB, enabling the 'tls' parameter in the cluster parameter group requires the parameter group to be associated with the cluster and the cluster to be rebooted for the change to take effect. If the parameter group was not properly associated or the cluster was not rebooted after modifying the parameter, TLS enforcement would not be active, allowing connections without TLS. Options A, B, and C are incorrect because DocumentDB supports TLS (via SSL), intra-VPC traffic does not bypass TLS, and older mongo shell versions can still use TLS if configured.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DocumentDB does not support TLS; it only supports SSL.
Why it's wrong here
DocumentDB supports TLS.
- ✗
The EC2 instance is in the same VPC, so TLS is not enforced for intra-VPC traffic.
Why it's wrong here
TLS enforcement applies regardless of network location.
- ✗
The developer is using an older version of the mongo shell that does not support TLS.
Why it's wrong here
If the server enforces TLS, the connection would fail, not succeed.
- ✓
The 'tls' parameter was not applied to the cluster because the parameter group was not associated with the cluster or the cluster was not rebooted.
Why this is correct
Parameter group changes require a reboot to take effect.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 20, 2026
This DBS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DBS-C01 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.