Courseiva
Workload-Specific Database DesignmediumMultiple ChoiceObjective-mapped

DBS-C01 Workload-Specific Database Design Practice Question

Network Topology
aws cloudformation describe-stacksstack-name MyStackquery "Stacks[0].Outputs"Refer to the exhibit.```"OutputKey": "RDSEndpoint","OutputValue": "mydb.c9abcdefghi.us-east-1.rds.amazonaws.com","Description": "RDS endpoint"},"OutputKey": "DBName","OutputValue": "MyDB","Description": "Database name""OutputKey": "MasterUsername","OutputValue": "admin","Description": "Master username"

Refer to the exhibit. A CloudFormation stack was deployed to create an RDS instance. The application team reports they cannot connect to the database using the endpoint provided. The security group allows inbound traffic on port 3306 from the application's security group. What is the most likely cause?

⚠ Common exam trap

The trap here is that candidates focus on network connectivity issues (security groups, endpoints) and overlook the fact that authentication credentials are not automatically provided in stack outputs, leading them to choose options like B or D instead of recognizing the password mismatch as the root cause.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The database password is not provided in the stack outputs; the team may be using the wrong password

The CloudFormation stack outputs typically do not include the database password for security reasons. The application team may be using an incorrect password, which would cause authentication failures even if the network connectivity and security group rules are properly configured. Without the correct password, the RDS instance will reject the connection attempt at the MySQL/MariaDB protocol level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The RDS instance is in a Multi-AZ deployment and the endpoint is for the standby

    Why it's wrong here

    Multi-AZ uses the same endpoint; failover is transparent.

  • The security group inbound rule is missing the port 3306

    Why it's wrong here

    The stem says the security group allows inbound on 3306.

  • The database password is not provided in the stack outputs; the team may be using the wrong password

    Why this is correct

    The password is not output; they likely need to retrieve it from Secrets Manager.

  • The RDS endpoint is incorrect; it should include the port number

    Why it's wrong here

    The endpoint alone is sufficient; the client can use default port.

About these practice questions

This DBS-C01 question is part of Courseiva's 1,663-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DBS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DBS-C01 exam.