Courseiva
Database SecurityhardMultiple ChoiceObjective-mapped

DBS-C01 Database Security Practice Question

A company needs to comply with PCI DSS requirements for an Amazon RDS for Oracle DB instance. The requirements include encryption of sensitive data at rest and in transit, and automated key rotation. Which combination of services and configurations should be used? (Select THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable encryption at rest on the RDS instance using AWS KMS.

Options B, C, and D are correct. Option B: Enable encryption at rest on the RDS instance using AWS KMS. Option C: Use AWS Secrets Manager to automatically rotate database credentials. Option D: Enable SSL/TLS for connections to the database. Option A is incorrect because AWS CloudHSM is not required for key rotation; KMS can handle key rotation automatically. Option E is incorrect because VPC Flow Logs are for network traffic monitoring, not encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use AWS CloudHSM to generate and store encryption keys.

    Why it's wrong here

    KMS provides automatic key rotation; CloudHSM is optional and not required.

  • Enable encryption at rest on the RDS instance using AWS KMS.

    Why this is correct

    Encryption at rest is required for PCI DSS.

  • Use AWS Secrets Manager to automatically rotate database credentials.

    Why this is correct

    Credential rotation is often required for compliance.

  • Enable SSL/TLS for connections to the database.

    Why this is correct

    Encryption in transit is required.

  • Enable VPC Flow Logs to audit database connections.

    Why it's wrong here

    Flow logs are for monitoring, not encryption.

About these practice questions

Courseiva writes every DBS-C01 question from scratch — 1,663 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DBS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DBS-C01 exam.