Courseiva
Database SecuritymediumMultiple SelectObjective-mapped

DBS-C01 Database Security Practice Question

A company is using Amazon RDS for MySQL and needs to comply with PCI DSS requirements. Which TWO actions should the company take to secure the database? (Choose TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable encryption at rest using AWS KMS.

Options A and C are correct. Enabling encryption at rest using AWS KMS protects data on disk, which is a PCI DSS requirement. Enabling audit logging helps track database activities for compliance. Options B and D are incorrect: writing audit logs directly to an S3 bucket is not supported; RDS audit logs are sent to CloudWatch Logs. Enabling public accessibility would violate security requirements. Option E is incorrect because changing the default port is not a PCI DSS requirement and may complicate management without adding meaningful security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable encryption at rest using AWS KMS.

    Why this is correct

    Encryption at rest is required for data protection.

  • Configure the database to write audit logs directly to an S3 bucket.

    Why it's wrong here

    RDS does not write audit logs directly to S3.

  • Enable audit logging to track database activities.

    Why this is correct

    Audit logs are required for compliance.

  • Enable public accessibility on the RDS instance to allow access from anywhere.

    Why it's wrong here

    Public accessibility increases exposure, not recommended for PCI DSS.

  • Change the default database port to a non-standard port.

    Why it's wrong here

    Security through obscurity is not a PCI DSS requirement.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,663 original DBS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DBS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DBS-C01 exam.