Courseiva
Database SecuritymediumMultiple SelectObjective-mapped

DBS-C01 Database Security Practice Question

Which TWO actions should be taken to protect sensitive data in an Amazon RDS for Oracle DB instance? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use Oracle Transparent Data Encryption (TDE) for sensitive columns.

The correct answers are C and E. Option C, using Oracle Transparent Data Encryption (TDE), encrypts sensitive data at the column level within the database. Option E, enabling encryption at rest using AWS KMS, protects data stored on disk. Option A is incorrect because storing credentials in application configuration files is insecure. Option B is incorrect because disabling automated backups does not enhance security. Option D is incorrect because assigning a public IP increases exposure to attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Store database credentials in the application configuration file.

    Why it's wrong here

    Credentials should not be stored in code.

  • Disable automated backups to reduce storage costs.

    Why it's wrong here

    Disabling backups does not protect data.

  • Use Oracle Transparent Data Encryption (TDE) for sensitive columns.

    Why this is correct

    TDE provides column-level encryption.

  • Assign a public IP address to the DB instance for easier access.

    Why it's wrong here

    Public IP increases security risk.

  • Enable encryption at rest using AWS KMS.

    Why this is correct

    Encrypts data at rest.

About these practice questions

This DBS-C01 question is part of Courseiva's 1,663-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DBS-C01

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security administrator is setting up a new Amazon RDS for SQL Server database. The company requires that all data be encrypted at rest and in transit. Additionally, the database must be accessible only from a specific CIDR range. Which TWO actions should the administrator take? (Choose TWO.)

medium
  • A.Enable encryption at rest using AWS KMS.
  • B.Configure a security group that allows inbound traffic from the specific CIDR range.
  • C.Enable encryption in transit by modifying the RDS option group to include SSL.
  • D.Modify the DB parameter group to restrict network access.
  • E.Use AWS CloudHSM to manage encryption keys for the database.

Why A: Enabling encryption at rest using AWS KMS is a straightforward way to meet the encryption-at-rest requirement for RDS. Option B: Configuring a security group to allow inbound traffic from the specific CIDR range restricts network access to the database. Option C is incorrect because encryption in transit is handled by the database engine (e.g., SSL/TLS) and is not an RDS option group feature; you enable it on the client side or by modifying the DB parameter group. Option D is incorrect because DB parameter groups do not control network access; they manage database engine parameters. Option E is incorrect because AWS KMS is the default service for RDS encryption at rest; CloudHSM is an alternative for key management but not required.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DBS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DBS-C01 exam.