DBS-C01 Database Security Practice Question
A company is using Amazon Redshift and needs to comply with regulatory requirements that mandate encryption of all data at rest and control of the encryption keys. Which THREE steps should be taken? (Choose THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable automatic key rotation for the KMS key.
Enabling automatic key rotation for the KMS key ensures that encryption keys are rotated regularly, meeting key control requirements. Option B is correct because using a customer-managed KMS key allows the company to control the encryption keys themselves. Option E is correct because Amazon Redshift requires encryption to be enabled at cluster creation time, and using a KMS key accomplishes this. Option C is incorrect because AWS CloudHSM is not necessary for this requirement; KMS provides sufficient key management. Option D is incorrect because encryption cannot be enabled on an existing Redshift cluster; it must be enabled at creation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable automatic key rotation for the KMS key.
Why this is correct
Automatic rotation helps meet compliance requirements.
- ✓
Configure the cluster to use a customer-managed KMS key.
Why this is correct
Customer-managed keys give control over key policies.
- ✗
Use AWS CloudHSM to generate and manage encryption keys.
Why it's wrong here
CloudHSM is not required; KMS is sufficient.
- ✗
Enable encryption on the cluster after creation by modifying the cluster.
Why it's wrong here
You cannot enable encryption on an existing Redshift cluster.
- ✓
Create the cluster with encryption enabled using a KMS key.
Why this is correct
Encryption must be enabled at creation.
Go deeper
Related to this question
About these practice questions
One of 1,663 original DBS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DBS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DBS-C01 exam.