Courseiva
Security →mediumMultiple Choice

DVA-C02 Security Practice Question

A company wants to encrypt data in transit between an on-premises application and an Amazon RDS instance. Which of the following should be implemented?

⚠ Common exam trap

DVA-C02 often tests the distinction between encryption in transit and encryption at rest, so the trap is selecting a network-level control like VPN or a storage-level control like encryption at rest instead of the application-level SSL/TLS connection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use SSL/TLS for the database connection

Encrypting data in transit between an on-premises application and Amazon RDS requires enabling SSL/TLS on the database connection. RDS supports SSL/TLS for all supported engines, and the client must be configured to use the RDS certificate authority to establish an encrypted channel. This directly protects data as it travels over the network from the application to the database endpoint.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use an AWS Site-to-Site VPN connection

    Why it's wrong here

    Using an AWS Site-to-Site VPN connection establishes an encrypted tunnel at the network layer between your on-premises network and the AWS Virtual Private Cloud (VPC). While this secures the network path, it does not inherently provide end-to-end application-layer encryption for the specific database connection itself. The data within the VPN tunnel still needs an additional layer of encryption, such as SSL/TLS, to secure the direct communication between the application and the RDS instance.

  • ✓

    Use SSL/TLS for the database connection

    Why this is correct

    SSL/TLS (Secure Sockets Layer/Transport Layer Security) is the industry standard protocol for encrypting data in transit directly between a client application and a database server. It establishes a secure, encrypted channel, ensuring confidentiality, integrity, and authentication of the data exchanged. For an RDS instance, configuring the database client to use SSL/TLS guarantees that all data transmitted between the on-premises application and the RDS database is encrypted throughout its journey, fulfilling the requirement for data encryption in transit.

  • ✗

    Place the RDS instance in a private subnet and use a bastion host

    Why it's wrong here

    Placing an RDS instance in a private subnet restricts its direct exposure to the internet, enhancing network security by limiting inbound access. A bastion host provides a controlled, secure jump box for administrators to access resources within that private subnet. While these measures are crucial for network segmentation and access control, they do not inherently encrypt the actual data payload traveling between the client application and the RDS instance once a connection is established; they manage *who* can connect, not *how* the data is encrypted during transit.

  • ✗

    Enable encryption at rest on the RDS instance

    Why it's wrong here

    Enabling encryption at rest on an RDS instance protects the data stored on the database's underlying storage volumes, backups, snapshots, and read replicas. This is a critical security measure for safeguarding data when it is persistent on disk, preventing unauthorized access if the storage media were compromised. However, encryption at rest does not address the security of data actively moving over the network connection between a client application and the database server; it protects data that is stationary, not data in transit.

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.