Courseiva
Security and Compliance →hardMultiple Select

Enable RDS Encryption at Rest with KMS

A DevOps team is designing a solution to encrypt data at rest for an Amazon RDS for MySQL database. Which TWO actions should the team take? (Choose TWO.)

Quick Answer

The correct answer is to enable encryption at rest when creating the RDS DB instance and use AWS KMS to manage the encryption key. This is because Amazon RDS encryption at rest uses AWS Key Management Service (KMS) to automatically encrypt the underlying storage, automated backups, read replicas, and snapshots using AES-256 encryption, and this setting must be specified at launch time since it cannot be added later to an unencrypted instance. On the AWS Certified DevOps Engineer Professional DOP-C02 exam, this concept tests your understanding of immutable infrastructure and security best practices, often appearing as a trap where candidates mistakenly think encryption can be enabled post-creation or confuse SSL/TLS (encryption in transit) with at-rest encryption. A common memory tip is “encrypt at birth or not at all” — remember that RDS encryption is a one-time decision at instance creation, and KMS is the key manager, not S3 or SSL.

⚠ Common exam trap

The trap is assuming RDS encryption can be toggled on after creation like a parameter change; in reality it is set only at creation, and candidates must also distinguish at-rest encryption (KMS) from in-transit encryption (SSL/TLS).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS KMS to create a customer managed key and assign it to the RDS instance

Option D is correct because Amazon RDS encryption at rest must be enabled at the moment the DB instance is created — you select 'Enable encryption' in the create-database workflow, and RDS then encrypts the underlying storage, automated backups, read replicas, and snapshots with the chosen KMS key. Option C is correct because RDS encryption at rest is implemented through AWS KMS, so the team should create a customer managed key (CMK) in KMS and assign it to the DB instance during creation to control key rotation, policies, and audit via CloudTrail. Option A is wrong because you cannot enable encryption on an existing unencrypted RDS instance by modifying it; you must restore from a snapshot into a new encrypted instance. Option B is wrong because SSL/TLS secures data in transit between clients and the DB, not data at rest on storage. Option E is wrong because RDS manages its own storage volumes and does not store database files in an S3 bucket that you can encrypt.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable encryption after creating the RDS instance by modifying the instance

    Why it's wrong here

    Encryption at rest can only be enabled when an RDS instance is created; modifying an existing unencrypted instance cannot turn it on. It is tempting because modifying instances is the normal route for many settings, but this particular attribute is immutable, so a snapshot-restore into a new encrypted instance is required.

  • ✗

    Enable SSL/TLS for the RDS instance

    Why it's wrong here

    SSL/TLS encrypts data in transit between clients and the RDS instance; it does not encrypt the underlying storage volumes, snapshots or backups. It is tempting because TLS is a genuine RDS encryption control, but it would be the correct choice when the requirement is protecting data moving over the network.

  • ✓

    Use AWS KMS to create a customer managed key and assign it to the RDS instance

    Why this is correct

    Assigning a customer managed key from AWS KMS to the RDS instance enables storage-level encryption of the underlying MySQL data volumes, satisfying the data-at-rest requirement. RDS integrates natively with KMS, so the DB instance, automated backups, read replicas and snapshots are all encrypted under that key.

  • ✓

    Enable encryption at rest when creating the RDS DB instance

    Why this is correct

    RDS encryption at rest must be enabled at instance creation; it cannot be applied retrospectively to an existing unencrypted instance. Enabling it during creation satisfies the stem's requirement to encrypt the MySQL database's underlying storage.

  • ✗

    Store the database files in an encrypted S3 bucket

    Why it's wrong here

    RDS stores and manages its own data on EBS volumes, not in S3, so placing database files in an encrypted bucket does not encrypt the database at rest. It is tempting because S3 encryption is a valid at-rest control, but it is the correct choice for objects stored in S3, not RDS-managed storage.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on DOP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company is using Amazon RDS for MySQL and needs to encrypt the database at rest. Which action should be taken to enable encryption?

easy
  • A.Create a read replica with encryption enabled
  • B.Use AWS Secrets Manager to encrypt the data
  • ✓ C.Enable encryption when creating the DB instance
  • D.Modify the existing DB instance and enable encryption

Why C: Amazon RDS encryption at rest can only be enabled at the time the DB instance is created — you cannot enable it on an existing unencrypted instance. The correct action is therefore to enable encryption during creation (via the console, CLI, or API using the 'StorageEncrypted' parameter). Once enabled, RDS uses AWS KMS to encrypt the underlying storage, automated backups, read replicas, and snapshots.

Variation 2. A company uses Amazon RDS for MySQL with Multi-AZ deployment. The security team requires that all data be encrypted at rest and that automated backups are also encrypted. Which configuration meets these requirements?

medium
  • A.Use an S3 bucket policy to enforce encryption for backup files.
  • ✓ B.Enable encryption for the RDS instance using AWS KMS.
  • C.Enable encryption on automated backups only after creating a snapshot.
  • D.Enable encryption on the underlying EBS volumes using KMS.

Why B: Enabling encryption on the RDS instance using AWS KMS at creation time encrypts the data, automated backups, read replicas, and snapshots. Option A is incorrect because an S3 bucket policy cannot enforce encryption for RDS automated backups; RDS encryption must be handled at the instance level. Option C is incorrect because enabling encryption on automated backups after creating a snapshot does not encrypt the live database or future automated backups. Option D is incorrect because encrypting the underlying EBS volumes separately does not automatically encrypt the RDS data, logs, or backups; RDS encryption must be enabled directly on the instance.

Variation 3. A DevOps engineer is tasked with encrypting data at rest for an Amazon RDS for MySQL database. Which TWO methods can achieve this?

medium
  • ✓ A.Enable encryption when creating the DB instance using a customer-managed KMS key.
  • ✓ B.Enable encryption when creating the DB instance using the AWS managed KMS key.
  • C.Use the default RDS encryption with a customer-managed key without KMS.
  • D.Enable encryption on an existing unencrypted DB instance by modifying the instance.
  • E.Use client-side encryption with the RDS SDK.

Why A: Option A is correct because when you create an RDS for MySQL DB instance you can enable storage encryption and choose a customer-managed AWS KMS key, which RDS uses to encrypt the underlying EBS storage, snapshots, and read replicas. Option B is also correct because RDS supports selecting the AWS managed KMS key (aws/rds) at creation time to encrypt the DB instance's storage, so encryption at rest is achieved without managing a custom key. Option C is wrong because RDS encryption always uses AWS KMS keys; there is no 'default RDS encryption with a customer-managed key without KMS.' Option D is wrong because you cannot enable encryption on an existing unencrypted RDS instance by modifying it; you must encrypt a snapshot and restore it to a new encrypted instance. Option E is wrong because client-side encryption with the RDS SDK is not a supported RDS at-rest encryption method for the database storage; RDS at-rest encryption is handled by KMS-backed storage encryption.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.