DVA-C02 Security Practice Question
Which TWO actions are required to enable server-side encryption for an Amazon RDS instance? (Choose 2)
⚠ Common exam trap
DVA-C02 often tests the immutability of RDS encryption — candidates pick 'enable encryption after creation' because they assume it is a toggleable setting like in some other services, but RDS requires encryption at creation time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS KMS to manage the encryption key
Option D is correct because Amazon RDS encryption at rest is implemented using AWS Key Management Service (KMS) customer master keys (CMKs), so you must use AWS KMS to manage the encryption key that protects the DB instance's storage and snapshots. Option E is correct because RDS encryption at rest can only be enabled at the moment of DB instance creation (via the console, CLI --storage-encrypted, or API StorageEncrypted=true); you cannot turn it on afterward. Option A is wrong because an existing unencrypted RDS instance cannot simply have encryption enabled after creation—you must create a new encrypted instance from a snapshot. Option B is wrong because client-side encryption is an application-level concern and does not enable RDS server-side encryption at rest. Option C is wrong because placing the DB instance in a VPC is a networking configuration and has no bearing on enabling storage encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable encryption on the database after creation
Why it's wrong here
You cannot enable encryption on an existing unencrypted RDS DB instance; encryption at rest must be selected during the initial CreateDBInstance operation. If you attempt to modify an unencrypted instance to add encryption, the console and API have no such option. To apply encryption to an existing database, you must create a new encrypted snapshot, restore it as a new encrypted instance, and migrate your data.
- ✗
Use client-side encryption in the application
Why it's wrong here
Client-side encryption in the application encrypts data in the application layer before it is transmitted to the database, using keys managed by the application. This is fundamentally different from RDS server-side encryption, which encrypts the underlying storage volumes transparently using AWS KMS. Choosing client-side encryption does not enable or satisfy the RDS encryption at rest requirement, and you would still need to configure server-side encryption to meet compliance controls.
- ✗
Configure the DB instance to use a VPC
Why it's wrong here
Placing a DB instance in a VPC controls network-level isolation, subnets, route tables, and security groups, but it has no effect on data-at-rest encryption. An RDS instance can be launched inside a VPC while remaining completely unencrypted, because VPC configuration is orthogonal to storage encryption. To enable server-side encryption, you must use KMS and set the encryption flag at launch, not modify VPC settings.
- ✓
Use AWS KMS to manage the encryption key
Why this is correct
Amazon RDS server-side encryption is built on AWS KMS; you must select a customer master key (CMK) when enabling encryption at rest. The KMS key encrypts the database storage, automated snapshots, and read replicas through envelope encryption, and RDS uses the key to encrypt the data key that protects the volume. Without specifying a KMS key, the encryption option cannot be applied, making KMS key management an essential part of the required configuration.
- ✓
Specify encryption at rest when creating the DB instance
Why this is correct
You must explicitly enable encryption at rest when you create the DB instance, either by checking the encryption option in the console or by setting StorageEncrypted=true in the AWS CLI or API call. This setting is evaluated only at provisioning time; there is no post-creation modification path to turn it on. Therefore, specifying encryption at creation is a required action to achieve server-side encryption for the instance.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.