SCS-C02 Data Protection Practice Question
A company is designing a disaster recovery plan for its Amazon RDS for MySQL database. The database must be encrypted at rest. Which approach ensures that the database is encrypted and can be restored in another AWS Region?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a cross-Region read replica with encryption enabled
(Create a cross-Region read replica with encryption enabled) is correct because it continuously replicates data to another AWS Region and encryption at rest can be enabled, ensuring both disaster recovery and encryption. Option A is wrong because encryption cannot be enabled on an existing unencrypted DB instance; a new encrypted instance must be created. Option B is wrong because exporting to S3 and using cross-Region replication does not provide a real-time database replica and complicates recovery. Option C is wrong because while a manual snapshot can be copied to another Region with encryption, it does not provide continuous replication; it is a point-in-time backup, not a disaster recovery solution that minimizes data loss.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable encryption on the existing DB instance
Why it's wrong here
Enabling encryption on an existing unencrypted DB instance is not supported by Amazon RDS — encryption can only be applied when the instance is created. To encrypt an existing database you must restore it from a snapshot into a new encrypted instance or migrate data via DMS, which is an offline or ongoing migration project. This option neither provides cross-Region failover nor changes the fact that the original instance remains unencrypted, so it does not satisfy the DR requirement.
- ✗
Export the database to Amazon S3 and use S3 cross-Region replication
Why it's wrong here
Exporting the database to S3 and relying on S3 cross-Region replication creates an object-level backup, not an active database standby. S3 replication only copies files; you would still need to import that data into a new RDS instance in the recovery Region, which involves several manual steps and downtime. It also misses changes between exports unless you implement continuous logical replication separately, making its RPO/RTO far worse than a managed read replica.
- ✗
Create a manual snapshot and copy it to another Region with encryption
Why it's wrong here
A manual snapshot copied to another Region gives you a point-in-time backup in the DR Region, but a snapshot is inert — you must restore it to a new DB instance before applications can use it, and any data changes after the snapshot are lost. The recovery point objective equals the time since the last manual snapshot, and the recovery time objective includes manual restore and promotion steps. While this is an excellent backup strategy, it is not a continuous disaster-recovery solution.
- ✓
Create a cross-Region read replica with encryption enabled
Why this is correct
Creating a cross-Region read replica with encryption enabled gives you a continuously updated, readable copy of the primary database in another AWS Region. RDS automatically replicates changes from the primary using its asynchronous replication engine, and in a disaster you simply promote the replica to a standalone master with a few clicks, minimizing RTO. For encryption, the primary must be encrypted and you specify an AWS KMS key in the destination Region when creating the replica, so the DR copy is encrypted in transit and at rest.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.