Courseiva
Database SecurityeasyMultiple ChoiceObjective-mapped

DBS-C01 IAM policies Practice Question

A company wants to ensure that only specific IAM users can perform certain operations on an Amazon RDS DB instance, such as creating snapshots or modifying the instance. Which AWS feature should be used to define these permissions?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

IAM policies

IAM policies are used to grant or deny permissions to AWS resources, including Amazon RDS DB instances. By attaching an IAM policy to a user, group, or role, you can control which actions (e.g., CreateDBSnapshot, ModifyDBInstance) are allowed. Options A, C, and D are incorrect: VPC security groups control network traffic, DB parameter groups manage database engine settings, and DB subnet groups define which subnets the DB instance can use—none of these define permissions for specific operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • VPC security groups

    Why it's wrong here

    Security groups control network traffic to the DB instance, not IAM permissions.

  • IAM policies

    Why this is correct

    IAM policies define permissions for AWS actions on resources like RDS.

  • DB parameter groups

    Why it's wrong here

    Parameter groups manage database engine configuration parameters.

  • DB subnet groups

    Why it's wrong here

    Subnet groups define which subnets the DB instance can be created in.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This DBS-C01 question is part of Courseiva's 1,663-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DBS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DBS-C01 exam.