DOP-C02 Security and Compliance Practice Question
A DevOps engineer is tasked with encrypting data at rest for an Amazon RDS for MySQL database. Which TWO methods can achieve this?
⚠ Common exam trap
The trap is thinking that encryption can be enabled on an existing unencrypted RDS instance by modifying it, or that client-side encryption is a valid method for RDS at-rest encryption. Candidates might also confuse AWS managed keys with customer-managed keys, but both are valid for encryption. The key is to remember that encryption must be enabled at creation time, and you can choose either key type.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable encryption when creating the DB instance using a customer-managed KMS key.
Option A is correct because when you create an RDS for MySQL DB instance you can enable storage encryption and choose a customer-managed AWS KMS key, which RDS uses to encrypt the underlying EBS storage, snapshots, and read replicas. Option B is also correct because RDS supports selecting the AWS managed KMS key (aws/rds) at creation time to encrypt the DB instance's storage, so encryption at rest is achieved without managing a custom key. Option C is wrong because RDS encryption always uses AWS KMS keys; there is no 'default RDS encryption with a customer-managed key without KMS.' Option D is wrong because you cannot enable encryption on an existing unencrypted RDS instance by modifying it; you must encrypt a snapshot and restore it to a new encrypted instance. Option E is wrong because client-side encryption with the RDS SDK is not a supported RDS at-rest encryption method for the database storage; RDS at-rest encryption is handled by KMS-backed storage encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable encryption when creating the DB instance using a customer-managed KMS key.
Why this is correct
Selecting encryption at DB instance creation with a customer-managed KMS key encrypts the underlying storage, snapshots and read replicas. This satisfies the data-at-rest constraint while giving the organisation control over key rotation and revocation, which an AWS managed key does not provide.
- ✓
Enable encryption when creating the DB instance using the AWS managed KMS key.
Why this is correct
Enabling encryption at DB instance creation with the AWS managed KMS key (aws/rds) encrypts storage, snapshots and replicas at rest. This satisfies the encryption requirement without the customer managing key policies, though key rotation and access control remain with AWS.
- ✗
Use the default RDS encryption with a customer-managed key without KMS.
Why it's wrong here
RDS encryption at rest requires AWS KMS keys; there is no keyless customer-managed option, so this method cannot be configured. It tempts because customer-managed keys do give control over rotation and access policy, which is the right choice when compliance demands key ownership rather than an AWS-managed key.
- ✗
Enable encryption on an existing unencrypted DB instance by modifying the instance.
Why it's wrong here
Modifying an existing unencrypted RDS instance cannot enable storage encryption; encryption must be set at creation, so the instance must be recreated from a snapshot. It is tempting because RDS modification supports many other settings, and that route would be correct for changing instance class or storage size, not encryption state.
- ✗
Use client-side encryption with the RDS SDK.
Why it's wrong here
Client-side encryption with the RDS SDK protects data before it reaches the database but leaves the underlying RDS storage unencrypted, so it does not satisfy encryption at rest for the instance. It is tempting because it secures sensitive fields end to end, and it would be correct for application-level protection of specific columns rather than storage encryption.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.