DOP-C02 Security and Compliance Practice Question
A company uses Amazon RDS for MySQL with Multi-AZ deployment. The security team requires that all data be encrypted at rest and that automated backups are also encrypted. Which configuration meets these requirements?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable encryption for the RDS instance using AWS KMS.
Enabling encryption on the RDS instance using AWS KMS at creation time encrypts the data, automated backups, read replicas, and snapshots. Option A is incorrect because an S3 bucket policy cannot enforce encryption for RDS automated backups; RDS encryption must be handled at the instance level. Option C is incorrect because enabling encryption on automated backups after creating a snapshot does not encrypt the live database or future automated backups. Option D is incorrect because encrypting the underlying EBS volumes separately does not automatically encrypt the RDS data, logs, or backups; RDS encryption must be enabled directly on the instance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use an S3 bucket policy to enforce encryption for backup files.
Why it's wrong here
RDS backups and snapshots are stored in AWS-managed S3 buckets that are not accessible to the customer's account, so no S3 bucket policy can be attached to them. Moreover, the encryption state of automated backups and snapshots is inherited from the RDS instance encryption setting, not controlled independently via S3. Therefore, even if you configured an S3 policy, it could not secure the live database or its backup data as required.
- ✓
Enable encryption for the RDS instance using AWS KMS.
Why this is correct
Enabling RDS encryption with AWS KMS is the correct method because it transparently encrypts the DB instance's data at rest, its automated backups, and its snapshots using the same customer master key. For a Multi-AZ deployment, you should enable encryption either at instance creation or by restoring an encrypted snapshot, since encryption cannot be added to an existing unencrypted instance without a snapshot restore. This ensures compliance and data protection across all storage layers without requiring direct access to underlying storage.
- ✗
Enable encryption on automated backups only after creating a snapshot.
Why it's wrong here
The process of encrypting an existing unencrypted RDS instance requires creating a manual snapshot, copying that snapshot with the 'Enable encryption' option using a KMS key, and then restoring from the encrypted snapshot—this yields a new encrypted instance. Simply 'enabling encryption on automated backups' is not a supported RDS operation; encryption is a property of the instance and applies uniformly to the primary database, backups, and snapshots. Thus, this approach cannot encrypt the current live instance's ongoing automated backups, and it does not address the original unencrypted database even if a snapshot is taken.
- ✗
Enable encryption on the underlying EBS volumes using KMS.
Why it's wrong here
Although RDS for MySQL uses Amazon EBS volumes for storage underneath, those volumes are fully abstracted by the RDS service and are not presented to customers as separate EBS resources that can have KMS encryption toggled independently. If you try to encrypt the 'underlying EBS volumes' via EC2 APIs or the EBS console, you cannot target an RDS instance because RDS manages its own storage lifecycle. The only supported control plane operation is to enable RDS encryption itself, which automatically encrypts the underlying EBS storage, so this option is both impractical and incorrect.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company is using Amazon RDS for MySQL and needs to encrypt the database at rest. Which action should be taken to enable encryption?
easy- A.Create a read replica with encryption enabled
- B.Use AWS Secrets Manager to encrypt the data
- ✓ C.Enable encryption when creating the DB instance
- D.Modify the existing DB instance and enable encryption
Why C: Amazon RDS encryption at rest can only be enabled at the time the DB instance is created — you cannot enable it on an existing unencrypted instance. The correct action is therefore to enable encryption during creation (via the console, CLI, or API using the 'StorageEncrypted' parameter). Once enabled, RDS uses AWS KMS to encrypt the underlying storage, automated backups, read replicas, and snapshots.
Variation 2. A DevOps team is designing a solution to encrypt data at rest for an Amazon RDS for MySQL database. Which TWO actions should the team take? (Choose TWO.)
hard- A.Enable encryption after creating the RDS instance by modifying the instance
- B.Enable SSL/TLS for the RDS instance
- ✓ C.Use AWS KMS to create a customer managed key and assign it to the RDS instance
- ✓ D.Enable encryption at rest when creating the RDS DB instance
- E.Store the database files in an encrypted S3 bucket
Why C: Option D is correct because Amazon RDS encryption at rest must be enabled at the moment the DB instance is created — you select 'Enable encryption' in the create-database workflow, and RDS then encrypts the underlying storage, automated backups, read replicas, and snapshots with the chosen KMS key. Option C is correct because RDS encryption at rest is implemented through AWS KMS, so the team should create a customer managed key (CMK) in KMS and assign it to the DB instance during creation to control key rotation, policies, and audit via CloudTrail. Option A is wrong because you cannot enable encryption on an existing unencrypted RDS instance by modifying it; you must restore from a snapshot into a new encrypted instance. Option B is wrong because SSL/TLS secures data in transit between clients and the DB, not data at rest on storage. Option E is wrong because RDS manages its own storage volumes and does not store database files in an S3 bucket that you can encrypt.
Variation 3. A DevOps engineer is tasked with encrypting data at rest for an Amazon RDS for MySQL database. Which TWO methods can achieve this?
medium- ✓ A.Enable encryption when creating the DB instance using a customer-managed KMS key.
- ✓ B.Enable encryption when creating the DB instance using the AWS managed KMS key.
- C.Use the default RDS encryption with a customer-managed key without KMS.
- D.Enable encryption on an existing unencrypted DB instance by modifying the instance.
- E.Use client-side encryption with the RDS SDK.
Why A: Option A is correct because when you create an RDS for MySQL DB instance you can enable storage encryption and choose a customer-managed AWS KMS key, which RDS uses to encrypt the underlying EBS storage, snapshots, and read replicas. Option B is also correct because RDS supports selecting the AWS managed KMS key (aws/rds) at creation time to encrypt the DB instance's storage, so encryption at rest is achieved without managing a custom key. Option C is wrong because RDS encryption always uses AWS KMS keys; there is no 'default RDS encryption with a customer-managed key without KMS.' Option D is wrong because you cannot enable encryption on an existing unencrypted RDS instance by modifying it; you must encrypt a snapshot and restore it to a new encrypted instance. Option E is wrong because client-side encryption with the RDS SDK is not a supported RDS at-rest encryption method for the database storage; RDS at-rest encryption is handled by KMS-backed storage encryption.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.