A company wants to encrypt data in transit between an on-premises application and an Amazon RDS instance. Which of the following should be implemented?
SSL/TLS (Secure Sockets Layer/Transport Layer Security) is the industry standard protocol for encrypting data in transit directly between a client application and a database server. It establishes a secure, encrypted channel, ensuring confidentiality, integrity, and authentication of the data exchanged. For an RDS instance, configuring the database client to use SSL/TLS guarantees that all data transmitted between the on-premises application and the RDS database is encrypted throughout its journey, fulfilling the requirement for data encryption in transit.
Why this answer
Encrypting data in transit between an on-premises application and Amazon RDS requires enabling SSL/TLS on the database connection. RDS supports SSL/TLS for all supported engines, and the client must be configured to use the RDS certificate authority to establish an encrypted channel. This directly protects data as it travels over the network from the application to the database endpoint.
Exam trap
DVA-C02 often tests the distinction between encryption in transit and encryption at rest, so the trap is selecting a network-level control like VPN or a storage-level control like encryption at rest instead of the application-level SSL/TLS connection.
How to eliminate wrong answers
Option A is wrong because a Site-to-Site VPN encrypts traffic at the network layer between the on-premises network and the VPC, but it does not encrypt the database connection itself; if the VPN terminates before the RDS instance, the final leg could still be unencrypted. Option C is wrong because a private subnet and bastion host improve network access control but do not encrypt data in transit. Option D is wrong because encryption at rest protects stored data on disk, not data moving over the network.