SAA-C03 Design Secure Architectures Practice Question
A healthcare analytics company runs an Amazon RDS for MySQL database in a private subnet. A compliance requirement mandates that all data at rest be encrypted with a key that the company can rotate, audit, and immediately revoke. The database is currently unencrypted. What is the MOST operationally efficient way to meet this requirement?
⚠ Common exam trap
The trap here is assuming you can simply modify an existing unencrypted RDS instance to turn on encryption, when RDS only allows changing the key of an already-encrypted instance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Take a snapshot of the DB instance, restore it with encryption enabled using a customer managed KMS key, and repoint the application to the new instance.
Encryption at rest for RDS must be enabled at creation. For an existing unencrypted instance, the supported path is to snapshot, restore with encryption using a customer managed KMS key, and repoint the application. This meets the need for customer-controlled rotation, audit trails, and revocability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable encryption on the existing DB instance by modifying it and specifying a customer managed AWS KMS key.
Why it's wrong here
You cannot enable encryption on an existing unencrypted RDS DB instance by modifying it. Encryption must be enabled at creation time; modifying only allows changing the KMS key for an already-encrypted instance. This approach would fail because the instance was created without encryption, so the modification cannot apply a key retroactively.
- ✓
Take a snapshot of the DB instance, restore it with encryption enabled using a customer managed KMS key, and repoint the application to the new instance.
Why this is correct
This is the standard supported method to encrypt an existing unencrypted RDS instance. You snapshot the instance, restore the snapshot with encryption enabled and a customer managed KMS key, then update the application connection string. It satisfies the requirement for customer-controlled key rotation, auditing, and revocation via KMS.
- ✗
Create an encrypted read replica from the unencrypted instance, promote it, and update the application endpoint.
Why it's wrong here
A read replica of an unencrypted instance cannot be encrypted. RDS only permits encrypting a replica if the source is already encrypted. Therefore, this method is invalid for an unencrypted primary. Even if it worked, promotion causes a brief outage and endpoint changes, which is less efficient than a snapshot restore.
- ✗
Enable encryption by restoring the automated backup to a new instance with the default AWS managed key aws/rds.
Why it's wrong here
Using the default AWS managed key aws/rds does not give the company control over rotation, auditing, or immediate revocation, which the compliance requirement demands. Also, restoring an automated backup is not the normal documented path for enabling encryption; snapshot restore is. The default key is managed by AWS and cannot be revoked by the customer.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.