SCS-C02 Data Protection Practice Question
A company is migrating on-premises databases to Amazon RDS for MySQL. The security team requires that data be encrypted at rest and in transit. Which combination of steps should the team take to meet these requirements?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable encryption at rest on the RDS instance and set the rds.force_ssl parameter to 1 in the DB parameter group.
Enabling encryption at rest on the RDS instance (which can be done during creation or via a snapshot copy with encryption enabled) and requiring SSL for connections (by setting the rds.force_ssl parameter to 1 in the DB parameter group) ensures data is encrypted both at rest and in transit. Option A is incorrect because an RDS proxy with TLS termination does not enforce encryption for direct connections to the database, and encryption at rest alone does not cover in-transit. Option C is incorrect because using a client-side encryption library is not a standard RDS feature and would require application changes; it does not provide at-rest encryption managed by RDS. Option D is incorrect because configuring the security group to allow only HTTPS traffic is for HTTP-based services, not for MySQL connections; MySQL uses a different protocol, and HTTPS does not apply to database connections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use an RDS proxy with TLS termination and enable encryption at rest.
Why it's wrong here
While RDS Proxy can terminate TLS from clients, it does not enforce SSL on connections between the proxy and the RDS database engine, nor does it prevent direct non-TLS connections to the instance. Enabling encryption at rest only protects the storage layer; without rds.force_ssl=1, traffic can still traverse the network in cleartext. Therefore, this option fails to guarantee in-transit encryption for all database connections.
- ✓
Enable encryption at rest on the RDS instance and set the rds.force_ssl parameter to 1 in the DB parameter group.
Why this is correct
Enabling encryption at rest on the RDS instance protects data files and automated backups using AWS KMS-managed keys, addressing the at-rest requirement. Setting rds.force_ssl=1 in the DB parameter group configures the MySQL/PostgreSQL engine to accept only TLS/SSL-encrypted connections, forcing all clients to negotiate an encrypted transport. Applying this parameter group requires a reboot, and after that every connection—including from read replicas—must use SSL, thereby satisfying both at-rest and in-transit encryption.
- ✗
Enable encryption at rest on the RDS instance and use a client-side encryption library.
Why it's wrong here
Client-side encryption libraries encrypt specific column or field values before sending them to RDS, but they do not encrypt the database connection itself; data in transit remains vulnerable to sniffing. This approach also adds application-level complexity and does not enforce a policy that all database clients use encryption. The requirement to 'force' encryption for the database is not met because the RDS engine is configured to accept plaintext connections.
- ✗
Enable encryption at rest and configure the security group to allow only HTTPS traffic.
Why it's wrong here
Security groups are stateful network firewalls that control traffic by IP addresses and ports, not encryption. HTTPS is an application-layer protocol for web traffic over port 443, whereas MySQL and PostgreSQL use their own wire protocols over ports 3306 or 5432, optionally protected by TLS. Restricting the security group to HTTPS would block legitimate database traffic and does nothing to encrypt connections, so this option is both functionally incorrect and irrelevant to in-transit encryption.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.