Courseiva
Data Protection →easyMultiple Choice

SCS-C02 Data Protection Practice Question

A company is designing a disaster recovery plan for its Amazon RDS for MySQL database. The database must be encrypted at rest. Which approach ensures that the database is encrypted and can be restored in another AWS Region?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a cross-Region read replica with encryption enabled

(Create a cross-Region read replica with encryption enabled) is correct because it continuously replicates data to another AWS Region and encryption at rest can be enabled, ensuring both disaster recovery and encryption. Option A is wrong because encryption cannot be enabled on an existing unencrypted DB instance; a new encrypted instance must be created. Option B is wrong because exporting to S3 and using cross-Region replication does not provide a real-time database replica and complicates recovery. Option C is wrong because while a manual snapshot can be copied to another Region with encryption, it does not provide continuous replication; it is a point-in-time backup, not a disaster recovery solution that minimizes data loss.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable encryption on the existing DB instance

    Why it's wrong here

    Enabling encryption on an existing unencrypted DB instance is not supported by Amazon RDS — encryption can only be applied when the instance is created. To encrypt an existing database you must restore it from a snapshot into a new encrypted instance or migrate data via DMS, which is an offline or ongoing migration project. This option neither provides cross-Region failover nor changes the fact that the original instance remains unencrypted, so it does not satisfy the DR requirement.

  • ✗

    Export the database to Amazon S3 and use S3 cross-Region replication

    Why it's wrong here

    Exporting the database to S3 and relying on S3 cross-Region replication creates an object-level backup, not an active database standby. S3 replication only copies files; you would still need to import that data into a new RDS instance in the recovery Region, which involves several manual steps and downtime. It also misses changes between exports unless you implement continuous logical replication separately, making its RPO/RTO far worse than a managed read replica.

  • ✗

    Create a manual snapshot and copy it to another Region with encryption

    Why it's wrong here

    A manual snapshot copied to another Region gives you a point-in-time backup in the DR Region, but a snapshot is inert — you must restore it to a new DB instance before applications can use it, and any data changes after the snapshot are lost. The recovery point objective equals the time since the last manual snapshot, and the recovery time objective includes manual restore and promotion steps. While this is an excellent backup strategy, it is not a continuous disaster-recovery solution.

  • ✓

    Create a cross-Region read replica with encryption enabled

    Why this is correct

    Creating a cross-Region read replica with encryption enabled gives you a continuously updated, readable copy of the primary database in another AWS Region. RDS automatically replicates changes from the primary using its asynchronous replication engine, and in a disaster you simply promote the replica to a standalone master with a few clicks, minimizing RTO. For encryption, the primary must be encrypted and you specify an AWS KMS key in the destination Region when creating the replica, so the DR copy is encrypted in transit and at rest.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.