DOP-C02 Security and Compliance Practice Question
Which TWO are best practices for securing an Amazon RDS database? (Choose 2)
⚠ Common exam trap
DOP-C02 often tests the misconception that public accessibility or single-AZ simplifies management — candidates pick convenience options that violate the shared responsibility model's security and availability best practices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Launch the RDS instance in a private subnet.
Option C is correct because launching the RDS instance in a private subnet removes it from the public internet, so only resources inside the VPC (or connected via VPN/Direct Connect or a bastion) can reach the database endpoint, which is a core network-isolation best practice. Option D is correct because enabling encryption at rest with AWS KMS protects stored data, automated backups, read replicas, and snapshots, satisfying compliance and data-protection requirements. Option A is wrong because public accessibility exposes the database to internet-based attacks and is not recommended; management should be done via private networking or a bastion. Option B is wrong because a Single-AZ deployment creates a single point of failure and does not improve security; Multi-AZ is preferred for availability. Option E is wrong because granting direct IAM user access to the database bypasses proper database authentication and least-privilege controls; IAM should be used for AWS API access, not direct DB logins.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable public accessibility for easy management.
Why it's wrong here
Enabling public accessibility assigns a public IP to the RDS instance and allows inbound traffic from the internet through the security group, dramatically increasing the attack surface for brute force and SQL injection attempts. Management should instead be performed from within the VPC using a bastion host or via an AWS VPN/Direct Connect, ensuring the database never receives unsolicited internet traffic. This violates the principle of least privilege because it exposes the database port to potentially untrusted networks.
- ✗
Use a single Availability Zone to reduce complexity.
Why it's wrong here
Choosing a single Availability Zone has no security benefit; it merely avoids the cost of a standby replica. In fact, it introduces availability risks where a data center failure could cause loss of access to the database, which is a separate concern from confidentiality or integrity. Security best practices for RDS focus on network isolation, encryption, and access control, not on reducing AZ count, so this option distracts from proper hardening.
- ✓
Launch the RDS instance in a private subnet.
Why this is correct
Launching the RDS instance in a private subnet that has no route to an internet gateway prevents any direct inbound connection from the public internet, including attempts to exploit database vulnerabilities. Only resources inside the VPC, such as application servers in private subnets or a bastion host, can reach the database, and those connections can be further restricted by security groups and NACLs. This is a core network security control that reduces the attack surface and is a mandatory requirement for many compliance frameworks.
- ✓
Enable encryption at rest using AWS KMS.
Why this is correct
Enabling encryption at rest for an RDS instance uses the AWS Key Management Service (KMS) to encrypt the underlying storage, automated backups, read replicas, and snapshots using envelope encryption. Even if an attacker gains physical access to the storage media or acquires a snapshot outside the VPC, the data remains unreadable without the KMS key. This does not protect data in transit or from SQL injection, but it is an essential defense-in-depth layer for data confidentiality.
- ✗
Grant direct IAM user access to the database.
Why it's wrong here
Applying direct IAM user rights to an RDS database is conceptually invalid because IAM users are AWS control‑plane identities; they do not authenticate to the database engine itself. RDS supports IAM database authentication, but that still creates a database user authenticated through an authentication token — it does not grant IAM users direct table access. Entangling IAM permissions with database privileges creates a broad, unmanageable permission surface, whereas the correct pattern is to use database users, groups, and roles with least privilege.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company has an Amazon RDS for MySQL database that stores sensitive data. The security team requires encryption at rest and in transit. Which combination of options meets these requirements?
easy- A.Use AWS Certificate Manager to issue a certificate for the RDS instance
- B.Place the RDS instance in a private subnet and use VPC peering
- ✓ C.Enable encryption at rest on the RDS instance and enforce SSL connections
- D.Use AWS KMS to encrypt the database before inserting data and decrypt on read
Why C: Enabling encryption at rest on the RDS instance (via KMS) and enforcing SSL/TLS connections satisfies both requirements: encryption at rest protects data on disk, and SSL enforcement encrypts data in transit between the client and the database. RDS supports encryption at rest through KMS keys and SSL enforcement via parameter group settings (e.g., require_secure_transport for MySQL).
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.