SCS-C02 Infrastructure Security Practice Question
A company is designing a VPC with multiple subnets. The security team wants to ensure that traffic between the application tier and database tier is encrypted in transit. Which TWO actions should be taken?
⚠ Common exam trap
SCS-C02 often tests the misconception that network-level controls like security groups or VPC peering automatically provide encryption, when in fact encryption in transit requires explicit configuration at both the database and application layers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable encryption on the database connections using TLS/SSL
Option B is correct because enabling TLS/SSL on the database connections ensures that the data transmitted between the application tier and database tier is encrypted in transit, protecting it from interception or eavesdropping. Option D is correct because configuring the application to use an encrypted protocol (such as TLS/SSL) when connecting to the database is necessary to actually initiate and negotiate the encrypted session, complementing the database-side encryption. Option A is incorrect because an internet gateway only enables internet connectivity for a subnet and does not encrypt traffic between internal tiers. Option C is incorrect because security group rules restrict which ports and sources can communicate but do not provide encryption in transit. Option E is incorrect because VPC peering connects subnets or VPCs for routing purposes but does not encrypt the traffic between them.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Attach an internet gateway to the database subnet
Why it's wrong here
Attaching an internet gateway to the database subnet would give the database a route to the internet (and potentially make it reachable from the internet), but it does nothing to protect the data in transit between the application and the database. In fact, doing so would expose the database to the public internet unless tightly coupled with restrictive network ACLs and security groups, and even then it introduces a larger attack surface. Encryption of the database connections is a separate concern that an internet gateway cannot address.
- ✓
Enable encryption on the database connections using TLS/SSL
Why this is correct
Enabling TLS/SSL on the database connections encrypts the entire session between the application and the database, protecting the data from eavesdropping or tampering while it traverses the network. This is a direct, protocol-level mitigation for the lack of encryption between the application and the database, and it can be enforced at the database server (e.g., requiring SSL/TLS for all client connections) and supported by the client driver. It does not change network routing or access control, but it specifically ensures confidentiality and integrity of the data in transit.
- ✗
Use security group rules to restrict traffic to the database port
Why it's wrong here
Security group rules can limit which source IPs, security groups, or CIDRs are allowed to reach the database port, which is an important access-control measure to reduce exposure. However, security groups operate at the network layer and only filter packets based on allowed sources and destinations; they do not encrypt or otherwise protect the data payload. An attacker who can sniff traffic on the VPC or on a shared medium would still be able to read the unencrypted database traffic even if the security group rules are correctly configured.
- ✓
Configure the application to use an encrypted protocol when connecting to the database
Why this is correct
Configuring the application to use an encrypted protocol when connecting to the database means the application's database client is explicitly set to use TLS/SSL or another encryption method (e.g., SSH tunneling or IPSec) for its connection. This is a client-side enforcement that complements server-side requirements, ensuring that even if the server accepts unencrypted connections, the application will only establish an encrypted channel. It is a necessary step because merely enabling encryption on the database server does not guarantee the application will use it; the client must also be configured to negotiate and verify the encryption.
- ✗
Use VPC Peering to connect the subnets
Why it's wrong here
VPC peering connects two VPCs and allows private IP traffic to flow between them, but it is a routing mechanism, not an encryption mechanism. Even if the database subnets were in separate VPCs and peered with the application VPC, the traffic would still traverse the network unencrypted unless the application and database both use an encrypted protocol. Moreover, VPC peering does not apply to subnets within the same VPC, so it is conceptually irrelevant to the stated scenario of multiple subnets in a single VPC.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.