SCS-C02 Data Protection Practice Question
A company is designing a data encryption solution for its Amazon RDS for PostgreSQL database. The database must be encrypted at rest. What is the simplest way to achieve this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable encryption when creating the RDS instance using a KMS key.
RDS supports encryption at rest for new databases using AWS KMS. Option B is incorrect because there is no separate encryption layer; RDS uses KMS. Option C is incorrect because application-level encryption is not the simplest. Option D is incorrect because RDS does not support CloudHSM for encryption at rest.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable encryption when creating the RDS instance using a KMS key.
Why this is correct
Native RDS encryption at rest is a one-way, create-time configuration: you specify a customer-managed AWS KMS key (or the default aws/rds key) when launching the DB instance, and RDS uses envelope encryption to encrypt the instance's storage, automated backups, snapshots, and read replicas. Because the encryption decision is baked into the underlying storage during provisioning, it cannot be retroactively applied to an already-running instance. This is the simplest and most operationally transparent way to meet an at-rest encryption requirement for Amazon RDS.
- ✗
Enable AWS KMS encryption on the RDS instance after creation.
Why it's wrong here
There is no console toggle, CLI command, or SDK operation that enables AWS KMS encryption for an existing, unencrypted RDS instance. To migrate you have to stop writes, take a snapshot, create an encrypted copy of that snapshot, and restore a brand-new encrypted instance — a manual process. The option incorrectly implies encryption can be flipped on in place post-creation, which is why it is wrong.
- ✗
Use application-level encryption before inserting data into the database.
Why it's wrong here
Application-level encryption means you encrypt column values (e.g., using AWS Encryption SDK or KMS Encrypt) in your application before writing to the DB, which does protect data at rest but at a high cost: every read/write path must be modified, fields lose the ability to be indexed or searched natively, and key rotation/compliance becomes a separate engineering effort. It is a valid mitigation but not the expected, simplest answer for encrypting an entire RDS instance, especially when native encryption at launch achieves the same goal with zero application changes.
- ✗
Use AWS CloudHSM to encrypt the EBS volumes attached to the RDS instance.
Why it's wrong here
Amazon RDS does not expose the attached EBS volumes to you, so you cannot attach a CloudHSM to them; RDS handles volume creation and mounting transparently, and encryption at rest is integrated exclusively with AWS KMS, not CloudHSM. CloudHSM is relevant when you want to manage your own keys for database Transparent Data Encryption (TDE) or SSL/TLS offload, but it has no role in encrypting RDS storage. Thus, using CloudHSM to encrypt RDS EBS volumes is technically impossible.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.