Courseiva
Database SecurityeasyMultiple ChoiceObjective-mapped

DBS-C01 Practice Question: Encrypting an existing unencrypted RDS instance

A company wants to encrypt an existing unencrypted Amazon RDS for PostgreSQL DB instance. What is the correct procedure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Take a snapshot of the instance, create an encrypted copy of the snapshot, and restore the encrypted snapshot to a new DB instance.

Encryption for an existing unencrypted Amazon RDS for PostgreSQL DB instance cannot be enabled directly. The correct procedure is to take a snapshot of the instance, create an encrypted copy of that snapshot, and then restore the encrypted snapshot to a new DB instance. Option A accurately describes this process. Option B is incorrect because restoring a snapshot does not allow enabling encryption during the restore; encryption must be applied at the time of snapshot copy. Option C is incorrect because you cannot modify a running DB instance to enable encryption. Option D is incorrect because creating a read replica does not encrypt the primary instance; encryption must be set up before replica creation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Take a snapshot of the instance, create an encrypted copy of the snapshot, and restore the encrypted snapshot to a new DB instance.

    Why this is correct

    This is the standard procedure to migrate to an encrypted instance.

  • Take a snapshot of the instance and restore it with encryption enabled.

    Why it's wrong here

    Restoring from a snapshot does not encrypt it unless the snapshot itself is encrypted.

  • Modify the DB instance and enable encryption in the RDS console.

    Why it's wrong here

    Encryption cannot be enabled on an existing instance.

  • Create a read replica of the instance and enable encryption on the replica.

    Why it's wrong here

    Read replicas only inherit encryption from the primary.

About these practice questions

Courseiva writes every DBS-C01 question from scratch — 1,663 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DBS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DBS-C01 exam.